Hi Suraj,
tks for your repply and time.
The solution provided by you, make sense if the ingress traffic interface and the egress traffic interface belong to inet.0 (default routing table).
But, this scenario is like that:
* I have one security zone, example, SRX-ZONE;
* Traffic source (172.16.16.0/24) arrive in the interface reth0.10;
* The egress interface is reth0.20;
* Interface reth0.10 and interface reth0.20 belong to a custom virtual instance type virtual-router.
* The static route applied in the custom virtual instance to reach the network 10.0.0.0/8 point to 10.43.7.3;
* But when the traffic source is the 172.16.16.0/24 the next hop to reach the network 10.0.0.0/8 should be 10.43.7.4;
Summary: i need a FBF to be applied in a custom virtual instance, not to be applied in the inet.0.
Note: i tried your configuration, but didn´t woked because no there "rib-group inet <rib-name>" option in the "routing-instance custom-instance routing-options" stanza.
Do you know some another solution?
Tks for attention.
João Victor