@evt wrote:
When you attach an address-book to a zone, does that mean addresses in that address-book will be completely unreachable if the SRX sees them sourced from another zone? For instance, I have a set of addresses that are portable on my network, for purposes of email server redundancy. Should my email server go down, they are (manually) ported to another part of the network and configured on a warm-standby mail server there.
As it is now, I've configured these addresses in an address-book that is attached to my internal mail zone. Do I need to delete them from that address-book and put them in the 'global' address-book?
What version of Junos are you running? I think it was 11.2 (or 11.1) that introduced a new "architecture" for address-books. In previous version you had a separate address-book for each zone (like in ScreenOS). Which in your case means you would have to create adress-book entries for your standby mailservers in each zone that it operates in.
The new version now allow you to separate the address-books from the zones, so you can basically have a "global" address-book that's valid for all zones. Here you would only need to create your mailservers once and you could use them in all zones.
The release notes of 11.2 or 11.1 (whichever version introduced this, sorry but I don't remember) have a pretty detailed explanation.
While we are at it, said version also introduced a global zone (those familiar with ScreenOS will like this).