Re: Dynamic VPN Issue - No Default Gateway Assigned
IP address with /32 subnet mask is an expected behavior. There is no point in assigning /24 subnet mask for a point to point tunnel interface. There is no need to assign ip address on st0.9 interface in this case and you can simply remove the configured /24 address. From the official documention: "When an IP address is assigned from an external RADIUS server or a local address pool, an IP address with a 32-bit mask is passed to the NCP Exclusive Remote Access Client. After the tunnel is established, auto route insertion (ARI) automatically inserts a static route to the remote client’s IP address so that traffic from behind the SRX Series device can be sent into the VPN tunnel to the client’s IP address" (https://www.juniper.net/documentation/en_US/junos/topics/topic-map/security-remote-access-vpns-with-...)
Instead of configuring a default route(0/0), NCP installs two /1 networks in the clients routing table, which are equivalent to default route. Because best route is calculated based on longest prefix match (/1 > /0) traffic will match NCP routes and will go via tunnel. So everything is working as expected. Are you facing any issue other than this default gateway not displaying?