JuniperSRX Filter-Based Forwarding
Is policy routing.
1) create routing-instance (SP1,SP2), and instance-type is fowarding
Edit routing-instance [SP1] instance-type forwading
Set routing-options static route 0/0 nex-hop 202.100.1.1
Edit routing-instance [SP2] instance-type forwading
Set routing-options static route 0/0 nex-hop 202.100.2.1
2) create a firewall filter
Edit friewall filter [Inside1] term [1]
Set from source-address 10.1.1.0/24
Set then routing-instance SP1
Set term [Default-Permit-All] then accept
Set firewall filter [Inside1] term [1] from source-address 10.1.1.0/24
Set firewall filter [Inside1] term [1] from source-port xxxx
Set firewall filter [Inside1] term [1] destination-address x.x.x.x/x
Set firewall filter [Inside1] term [1] destination-port xxxx
Set firewall filter [Inside1] term [1] then routing-instance SP1
Set firewall filter [Inside1] term [Default-Permit] then accept
Edit firewall filter [Inside2] term [2]
Set from source-address
Set then routing-instance SP2
Set term [Default-Permit-All] then accept
3) call filter via API
Set interface ge-0/0/2.0 family inet filter input Inside1
Set interfaes ge-0/0/3.0 family inet filter input Inside2
4) merge routing tables
Run show route / / check the global routing table. There are no routes in the routing-instance defined earlier.
Show routing-instances
Edit routing-options
Set interface-routes rib-group inet [Policy-Routing]
Edit rib-groups [Policy-Routing]
Set import-rib [inet.0 SP1.inet.0 SP2.inet.0]
Run show route / / View the merged routing table
5) create an inter-Zone policy: Security Policis (release traffic Inside1- > Outside;Inside2- > Outside)
Set security policies from-zone Inside1 to-zone Outside policy Default-Permit-All
Set match source-address any
Set match destination-address any
Set match application any
Set then permit
Set security policies from-zone Inside2 to-zone Outside policy Default-Permit-All
Set match sourc-address any
Set match destination-address any
Set match application-address any
Set then permit
# show security policies
# run show security flow session