In this situation, we have a IPsec VPN tunnel with IKE & IPsec security associations full and active, both peers can ping each other via normal traffic but no traffic is flowing through the established VPN tunnel.
In the VPN statistics we're able to see the ping attempts inside the VPN and "encrypted packets" but they're not reaching the peer, so no response is given and they time out.
For this situation, there was no NAT device after the SRX.
In the configuration for IPsec, we see the "not-nat-traversal" command set.
Removing this command fixed the issue matching these symptoms.