Hi
1) Basically yes, for the case when you connect VRs with "next-table" route lookup, or with
RIB groups. But note that if you are using lt (or physical) interface to connect VRs, then
reverse route lookup is done in each of them. If you are not doing NAT then the reverse route
to source is needed in both VRs (just imagine those VRs are separate boxes - you will
need route to the source in each router).
2) If connecting VRs with physical loop or lt interface, SRX creates 2 sessions for any
session going into one router and exiting the other one. E.g.
Session ID: 57866, Policy name: intrazone-Juniper-SV/4, Timeout: 3394, Valid
In: 172.20.107.10/56290 --> 172.20.207.10/23;tcp, If: vlan.107, Pkts: 27, Bytes: 1568
Out: 172.20.207.10/23 --> 172.20.107.10/56290;tcp, If: lt-0/0/0.1, Pkts: 21, Bytes: 1543
Session ID: 57867, Policy name: intrazone-ACME-SV/5, Timeout: 3394, Valid
In: 172.20.107.10/56290 --> 172.20.207.10/23;tcp, If: lt-0/0/0.2, Pkts: 27, Bytes: 1568
Out: 172.20.207.10/23 --> 172.20.107.10/56290;tcp, If: vlan.207, Pkts: 21, Bytes: 1543
Here, vlan.107 is the actual incoming interface while vlan.207 is the outgoing one.