Routing

last person joined: 5 days ago 

Ask questions and share experiences about ACX Series, CTP Series, MX Series, PTX Series, SSR Series, JRR Series, and all things routing, including portfolios and protocols.
  • 1.  Default routes question

    Posted 03-11-2013 03:21
      |   view attached

    Hi,

     

    We have two ADSL links attached to our Juniper SSG5 and I'm looking at using Policy Based Routing to push all traffic for a specific website out of one ADSL link and all other external traffic out of the other (see attached picture).  I think I've got my head around setting up the PBR but I have a question about how to setup the default routes.  Currently both ADSL connections are attached to the firewall and they have identical metrics and preferences; if I don't want any traffic apart from that which is destined for www.website.com to go out of 1.1.1.1 how should I setup the default routes?  Would it be as simple as changing the metric to 2 for 1.1.1.1 and leaving the metric as 1 for 2.2.2.2?

     

    Edit - I've been having a think about this, should I just remove the default route for 1.1.1.1 and let the PBR do the work instead?  Please forgive my ignorance but I'm relatively new to JunOS.

     

    Thanks for any help,

     

    Ben.



  • 2.  RE: Default routes question
    Best Answer

    Posted 03-11-2013 09:32

    Not sure why you would need PBR for this? (As long as I am reading it correctly of course). If you just had a static route on the Juniper for the web site you want out of Ethernet0/1 and your default out the other interface then that would cover it all. PBR is mainly used for source IP based routing, so if you only wanted traffic from a certain IP on your LAN to go out one DSL circuit then PBR would be needed.

     

    Regards,

     

    Mike



  • 3.  RE: Default routes question

    Posted 03-12-2013 03:52

    Hi Mike,

     

    Thanks for the reply, I think you're absolutely right.  The reason I started down the PBR idea was that I was going to use source IP but between the LAN and the Juniper firewall we have a Proxy server which NATs the internal IPs so I change it to destination and as you rightly say it will be much simpler to just use a static route.

     

    Thanks again, I think you've saved me a lot of time!

     

    Cheers,

     

    Ben.