This article explains an issue where the Juniper Secure Connect (JSC) clients cannot access any of the remote protected resources.
JSC is configured to be hosted on a loopback interface. Users can connect to JSC but cannot access any remote protected resources.
If the JSC or any ipsec VPN is hosted on a loopback interface, it is a must that the loopback interface and the ingress physical interface (interface receiving the traffic from JSC clients) are assigned to the same security zone. If these 2 interfaces belong to 2 different security zones, interested tunnel traffic will be dropped on SRX and the remote users will not be able to access the remote protected resources sitting behind SRX.