This article offers a solution to resolve the error.
Traffic from Cisco LAN hosts fails when sent through the IPsec VPN toward the SSR LAN network. Reverse traffic from the SSR toward the Cisco LAN is also blocked.
End-to-end traffic flow impacted:
Cisco LAN Host → Cisco VPN → Internet → SSR VPN → SSR LAN Host
This is mostly because required traffic steering and application policies are not configured on both the SSR and Cisco devices for the respective local and remote LAN subnets. As a result, VPN traffic between the two networks is not correctly permitted or classified.
Need to ensure appropriate application/traffic steering policies are created and allowed on both the SSR and Cisco gateways for the required LAN networks.
Required Policies
a) Cisco LAN → SSR LAN
b) SSR LAN → Cisco LAN
Both directions must be explicitly permitted for full bidirectional VPN connectivity.If you face any further issues, please contact JUNIPER JTAC Support for assistance.