Mr penguin your correct in what you say below however policy based does not use tunnel interfaces so it must be proxy id
in route based it uses the st0 interfaces so you are correct but this question does not say what you are using either route or policy based.
https://www.juniper.net/documentation/us/en/software/junos/vpn-ipsec/topics/topic-map/security-ipsec-vpn-configuration-overview.html#d135e2559
The next-hop gateways are the IP addresses for the st0 interfaces of all remote spoke peers. The next hop should be associated with the correct IPsec VPN name.
A voting comment increases the vote count for the chosen answer by one.
Upvoting a comment with a selected answer will also increase the vote count towards that answer by one.
So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.
westh4m1234
8 months, 2 weeks agowesth4m1234
8 months, 2 weeks agopenguin02007
1 year, 1 month agoachon
1 year, 7 months ago