What problem does it solve? Configuring an SRX as a secure MPLS L3VPN PE or CPE is error-prone: forwarding modes, VRF context, policy matching, and NAT must all align across Junos releases, and a wrong stanza silently breaks tenant isolation or stateful inspection. This Skill pins the agent to verified Junos 24.2R1+/25.4R1 syntax and a structured verification workflow. ## Core Features & Use Cases - Forwarding-mode design: Configure family mpls packet-based while keeping inet/inet6 flow-based, with platform and release support notes per SRX model. - VRF-aware policy and NAT: Build L3VPN VRF-group policy matching (24.2 style) or VRF-to-zone mapping (25.4R1+), plus VRF-aware source/static NAT and AppID verification. - Troubleshooting matrix and verification workflow: Symptom-to-cause tables, operational show commands, packet capture guidance, and PowerMode/RFP performance cautions. - Use Case: An engineer must deploy an SRX4600 as a secure PE with two overlapping customer VRFs; the Skill produces the VRF, MP-BGP, zone, policy, and NAT configuration plus a step-by-step verification checklist. ## Quick Start Use the srx-mpls-in-flow skill to design and verify an SRX MPLS L3VPN flow-mode deployment for my PE router with two customer VRFs.