Without seeing the rest of your configuration I can't say for sure, but most likely this is caused by a missing policy for the return traffic.
Where you define "pair-policy Remote-END" you must have a policy named Remote-END to define the VPN traffic in the opposite direction.
For example:
from-zone trust to-zone untrust {
policy Permit-Trust-Untrust-VPN {
match {
source-address 192.168.10.0/24;
destination-address 192.168.11.1/32;
application any;
}
then {
permit {
tunnel {
ipsec-vpn Remote-VPN;
pair-policy Permit-Untrust-Trust-VPN;
}
}
}
}
}
from-zone untrust to-zone trust {
policy Permit-Untrust-Trust-VPN {
match {
source-address 192.168.11.1/32;
destination-address 192.168.10.0/24;
application any;
}
then {
permit {
tunnel {
ipsec-vpn Remote-VPN;
pair-policy Permit-Trust-Untrust-VPN;
}
}
}
}
}