JuniperSRX VR
Main applications: dual-exit gateway, alternative policy routing; MPL × × ×; equal to Cisco's vrf, to achieve network isolation of routes
The global routing table and the virtual routing table can also fill each other
First, configuration: (zones:DMZ--Inside2)
1) create a virtual router and put it into the interface
Edit routing-instances [DMZ-Inside2]
Set instance-type virtual-router
Set interface ge-0/0/4.0
Set interface ge-0/0/3.0
2) Test the connectivity of directly connected networks DMZ,Inside2
Run ping routing-instances [DMZ-Iside2] 10.1.2.1 / / for direct ping, the global routing table is found.
Run ping routing-instances [DMZ-Iside2] 192.168.1.1
3) create an inter-Zone policy: Security Policis (release traffic DMZ--Inside2)
Edit security policies from-zone DMZ to-zone Inside2
Edit policy [Permit-ICMP]
Set match source-address any
Set match destination-address any
Set match application junos-ping
Set then permit
Edit policy [Permit-Telnet]
Set match source-address any
Set match destination-address any
Set match application junos-telnet
Set then permit
# show security policies
Edit security policies from-zone DMZ to-zone Inside2
# rename policy [Permit-ICMP] to [Permit-ICMP-And-Telnet]
5) ping 1.1.1.1 and ping 1.1.1.1 on PC in DMZ area to check connectivity and whether it is running VR (Routing-Instance).
Ping 1.1.1.1
4) View command
Run show route / / View global routing table and virtual routing table
Second, configuration (Inside1 router starts lo:1.1.1.1;Inside2 router starts lo:1.1.1.1)
Globally configure static route to Inside1
Set routing-options static route 1.1.1.1/32 nex-hop 10.1.1.1
# show routing-options
Virtual router configured with static route to Inside2
Edit routing-instance [DMZ-Iside2] routing-options
Set static route 1.1.1.1/32 next-hop 10.1.2.1
# show routing-instance
# run show route / / View global routing table and virtual routing table