I have an old SRX650 with route based vpn running to several remote srx. This has worked fine for years. I just tried updating the 650 to junos 12.1X44 D35.5 - after which two of the vpn tunnels would not come up. These two, unlike the others, have a static nat in effect at the remote end. Has Juniper changed the way ipsec vpn works through a NAT recently?