Configuring Juniper Networks NetScreen and SSG Firewalls

The following Frequently Asked Questions, answered by the authors of this book, are designed to both measure your understanding of the concepts presented in this chapter and to assist you with real-life implementation of these concepts. To have your questions about this chapter answered by the author, browse to www.syngress.com/solutions and click on the Ask the Author form.
Q: When would I want to use source-based routing (SBIR) over destination-based routing?
A: Destination-based routing is definitely the most widely implemented form or routing. Many administrators feel it is a more logical choice than routing based upon the source/interface because you are trying to forward traffic based upon where it is going, not on where it came from. But this isn t always the case, and so Juniper has provided support for source-based and source interface based routing should you need to make routing decisions with these methods.
Q: When should I use a dynamic routing protocol instead of just using static routing?
A: Networks that are very small have a limited number of networks, and have only single paths between networks that are good candidates for static routing. For example, if you have a central site with three branch offices forming a hub-and-spoke configuration, it would make sense to just point each branch to the central site statically, which could route the traffic to the appropriate branch. In such a network, where there is no redundancy, you don t have to worry about being able to fail...