In an Always On VPN configuration, the secure GlobalProtect connection is always on. Traffic that matches specific filters (such as port and IP address) configured on the GlobalProtect gateway is always routed through the VPN tunnel.

SRX Series,vSRX. Understanding Route-Based IPsec VPNs, Example: Configuring a Route-Based VPN, Understanding CoS Support on st0 Interfaces The problrm was that I was enterning the command in the configuration mode while I should write it after the globle mode. The problem now that tunnel is ok (up) but there is no ping between the internal LANs ( networks behind the VPN server and Remote VPN router). Regards

Our example setup is between two branches of a small company, We now move to the Site 2 router to complete the VPN configuration. The settings for Router 2 are identical, with the only difference being the peer IP Addresses and access lists: R2(config)# crypto isakmp policy 1. Configure Site to Site IPSec VPN Tunnel in Cisco IOS Router Oct 08, 2015