SRX Services Gateway
SRX Services Gateway

What will my source-address from this device be?

‎03-04-2019 09:41 AM

Hi All,

 

I've got a device with two routing-instances configured. RI A has my ISP circuit installed. RI B has my trusted traffic interfaces configured. RI B also has my loopback interface which I use for management of the device. RI A has a loopback interface which i use for internet traffic destined for my device. I have the default-address-selection configuration applied. 

 

My question is this. I have no interface in the default routing-instance, when traffic from the device, in this case (IDP signature updates from the device destined for services.netscreen.com) where will the traffic originate from? Will the traffic originate from the loopback in RI A or RI B?

 

Happy to provide more information if there is not sufficient info. 

 

The issue I am trying to solve is to do some sort of source based forwarding due to some issues with ECMP that I can't figure out. I need traffic from this device to take a specific ISP of mine rather than be load balanced. 

Thanks

4 REPLIES 4
SRX Services Gateway

Re: What will my source-address from this device be?

‎03-04-2019 10:40 AM

This KB may help you. Please check : https://kb.juniper.net/InfoCenter/index?page=content&id=KB32386&pmv=print&actp=RSS&searchid=&type=cu...

 

Thanks,
Nellikka
JNCIE x3 (SEC #321; SP #2839; ENT #790)
Please Mark My Solution Accepted if it Helped, Kudos are Appreciated too!!!
SRX Services Gateway

Re: What will my source-address from this device be?

‎03-04-2019 12:03 PM

Thanks for the link Nellikka. However, I don't want to have any footprint in the default routing-instance. The document you've linked to requires the loopback in the default routing-instance. 

 

SRX Services Gateway

Re: What will my source-address from this device be?

‎03-04-2019 09:53 PM

Hello,

 

As mentioned in the KB by design the IDP signature updates are meant to be sourced from the default routing instance only.

 

You can use the command "set security idp security-package source-address" if you wish to use a different interface other than the fxp in the default routing-instance. However I uderstand this does not solve your requirement to have no footprint in inet.0

 

Regards,

 

Vikas

SRX Services Gateway

Re: What will my source-address from this device be?

‎03-04-2019 11:56 PM

Hello,

 

After 17.3 you can move the fxp from the default routing-instance to junos_management.

https://www.juniper.net/documentation/en_US/junos/topics/task/configuration/mgmt_junos-routing-insta...

That can solve your problem.

Balázs