We've got SRX at our main office and SSG5's at remote locations that we site-to-site VPN in. We use route based VPN's. The route that we define is:
route x.x.x.x next-hop st0.0 passive
Since st0.0 only appears to be up when a VPN is active, we put the passive keyword on to keep the route in the routing table so we could export it via BGP. The problem is that when we initiate traffic from the main office to the VPN site, the traffic is discarded by the passive command and it doesn't bring up the tunnel.
So if we take out the passive command, the route isn't there for us to export via BGP and if it's there, the traffic destined for the network is dicsarded. How do we need to set this up so traffic initiated from the host site to the VPN site brings up the tunnel?