Thanks for your reply, but I'm not asking about VRF-Lite.
I want to know if Juniper has an equivalent of a Front-Door VRF.
This is where a specific VRF (or routing-instance) is used as the underlay, and another VRF is the overlay.
For example, VRF-1 is the underlay, and has a default route over the internet. This VRF is used for building the tunnel, and establishing the IPSec SA's.
VRF-2 (of the global VRF) is the overlay. The tunnel interface is in this VRF. This VRF has a default route that pushes traffic over the tunnel.
Does Juniper have this?