SRX Services Gateway
SRX Services Gateway

Route leaking and discard routes

‎06-26-2015 03:01 AM

Hi

 

I wan't to isolate a customer setup with some overlapping IP's in a virtual router on a SRX3600, and it seem as I have two options, either connect the VR with a logical tunnel, or leak routes between the two instances.

 

I have both options working, but to keep policy writing as simple as possible, I would prefeer to just leak routes, so that I can write policies directly to the zones inside the VR.

 

Most of the routing in my SRX happens in inet.0, where I have a default route.

 

So my initial thought was to just leak the default route from inet.0 into the VR, expecting the SRX to the look for more specifics in inet.0, but this didn't happen, instead all traffic from the VR was just send directly to the next hop of the default route.

 

I can live with this, but.. The SRX is also originating some prefixes, from some static discard routes, when I leak these routes into the VR, traffic from the VR to these prefixes are just dropped inside the VR.

 

Is there any way around this behaviour?

 

/Ralf

3 REPLIES 3
SRX Services Gateway
Solution
Accepted by topic author solido
‎08-26-2015 01:27 AM

Re: Route leaking and discard routes

‎06-26-2015 03:10 AM

Hello ,

 

1) So my initial thought was to just leak the default route from inet.0 into the VR, expecting the SRX to the look for more specifics in inet.0, but this didn't happen, instead all traffic from the VR was just send directly to the next hop of the default route.

 

>  Instead of leaking the default route from inet to VR , make sure you also leak specific routes for those subnet prefixes also to VR using policy option and match route terms like " default , static , direct " etc . This will help you to take specifi routes from INET instead of just taking default route .

 

2)I can live with this, but.. The SRX is also originating some prefixes, from some static discard routes, when I leak these routes into the VR, traffic from the VR to these prefixes are just dropped inside the VR.

 

Is there any way around this behaviour?

 

> So here also create policy options to discard rejected routes from  inet to VR using   "except " option . Or put then action as discard / reject  .

 

 

 


Thanks,
Sam

Please Mark My Solution Accepted if it Helped, Kudos are Appreciated too .....
SRX Services Gateway

Re: Route leaking and discard routes

‎06-26-2015 03:53 AM

> So here also create policy options to discard rejected routes from  inet to VR using   "except " option . Or put then action as discard / reject  .

 

I had actually tested that, but but I couldn't make it work, thinking that traffic would just go out the default route, hence my post. Upon checking things again, i found that I forgot to add my new zones the the nat rules that enables me to reach natte'd hosts from the inside.

 

Thanks

 

SRX Services Gateway

Re: Route leaking and discard routes

‎06-28-2015 09:58 PM

Hello ,

 

Thanks for the update . Glad that the issue was resolved .


Thanks,
Sam

Please Mark My Solution Accepted if it Helped, Kudos are Appreciated too .....