This article describes the issue of being unable to build a VPN tunnel, when the SRX/J-Series device is the IKE responder in a dynamic endpoint configuration (which also includes Dynamic-VPN).
Any VPN, in which the SRX/J-Series device is the responder in a dynamic endpoint environment and the external-interface is in a non-default routing-instance, will not successfully negotiate for an IPSec VPN tunnel. This is as per design. There are currently no plans to address this limitation. For any dynamic endpoint environment, the external-interface must be part of the default inet.0 routing instance. Any dynamic endpoint configuration, in which the external interface is in a custom routing instance, will fail in the IPSec VPN negotiation. It is recommended to re-configure the VPN, so that the external-interface is in the default inet.0 routing-instance. Scenarios in which dynamic endpoints are involved: