Tenants
CSO uses the tenant element to logically separate one customer from another. An OpCo administrator
creates one tenant to represent each customer for which they will provide network services.
Using RBAC and other means such as virtual routing and forwarding (VRF) instances within the network,
CSO keeps all tenant and OpCo objects walled within their own space. This ultimately includes the traffic
that traverses the customer networks. No individual tenant, its administrators, operators, or customers
can see or interact with the objects of another tenant or customer. Tenants can be named in whatever
way makes most sense to the SP or OpCo administrator.
Points of Presence (POPs)
A POP is a physical location, usually at the provider network edge, that acts as a demarcation or interchange
point between two or more networks. POPs are used in SD-WAN deployments as a way to locate network
access and network services closer to the users who need them. Different network services and different
connection types can be offered at each POP, depending on need and availability.
In CSO, a POP is typically where tenant traffic breaks out of the tenant overlay network into the provider
underlay network or Internet. The SP or OpCo administrator is responsible for creating the POP and adding
PE routers and provider hub devices to that POP. Once a provider hub device is added, the device becomes
available to be selected for use within a tenant network. POPs can be named in whatever way makes the
most sense to the SP or OpCo administrator.
Provider Hub
The SP or OpCo administrator adds the provider hub to the POP. The provider hub can have either or
both of the following roles:
•OAM - An OAM hub is situated logically between the CPEs and the CSO installation. Its role is to receive
OAM traffic from CSO and forward it to the destination CPE devices within secure tunnels. In the other
direction, the OAM hub receives OAM traffic from CPE devices within secure tunnels and forwards it
to CSO. This role only exists in a CSO on-premises deployment. In CSOaaS, this role is part of the provided
service.
•DATA - For tenant traffic staying within the tenant network, the data hub acts as a transit hub for
site-to-site traffic. For tenant traffic destined for the provider network, the data hub acts as a demarcation
point between the overlay tenant network and the underlay provider network. The provider data hub
is optional for tenants that have their own enterprise data hubs. If a tenant has an enterprise data hub
as well as an assigned provider data hub, the assigned provider data hub acts as a backup.
20