If that is the case, then maybe you could explain why the following does not work:
I have created an Active/Active that works, no problem, when the two SRX1500s are connected back to back, but when I try and connect them through the core (MX240) I cannot ping out..... (That may be an SRX issue)... let me explain what I have completed and the actual issue:
On the SRX (HA Works):
set zones security-zone trust interfaces reth1.0
set interfaces reth1 unit 0 family inet address 192.168.1.1/24
set interfaces reth1 unit 0 family iso - (For IS-IS)
set interfaces lo0 unit 0 family iso address 49.0001.1921.6800.1001.00 - (IS-IS NET Address)
set protocols isis interface reth1.0
set protocols isis interface lo0.0 passive
On the other end (MX240)
set interfaces ge-1/5/0 unit 0 family inet address 192.168.1.2/24
(IS-IS is configured corerctly as it work everywhere in the core)
So, if I try and ping from the MX240 to the reth1 address it fails.
If I ping from the SRX to the MX240 it states: No route to host - There should be no need as they are directly connected.
Route table on the MX240 shows that the route to the 192.168.1.1 address is through the correct interface, but when I completer a :
show route 192.168.1.2 from the SRX, it shows lot's of routes as disabled or removed (can't remember which)..... so, it seems there is an issue on the SRX (The Zones states an "any, any, any, permit" rule from trust to trust)
Anyone know please?