Your company has installed a new transparent proxy server that it wants all employee traffic to traverse before taking the default route to the Internet. The proxy server is within two DMZ zones from the SRX Series device, which means your SRX device must now have two default routes:
one to the proxy DMZ and one to the Internet from the proxy DMZ.
What can you do to get the traffic to flow to the transparent proxy DMZ, and then from the proxy DMZ to the Internet, regardless of the destination or port?
Configure two static default floating routes: one from the employee zone to the ingress proxy DMZ and a second from the egress proxy DMZ to the Internet.
Configure two separate routing instances: one instance for the employee zone to the ingress proxy DMZ and the second for the egress proxy DMZ to the Internet.
Configure security policies that will route all traffic to the ingress proxy DMZ then traffic will follow the default route to the Internet from the egress proxy DMZ.
Configure a rib-group to handle the two default routes between the ingress and egress zones of the new proxy.