Since there are not many scenarios when the HUB is behind NAT, I've created an article that describes situations when two spokes are behind NAT and only one has a static NAT.
Most of the hub-and-spoke ipsec VPN environments have the HUB configured with a public IP address, but sometimes the HUB is behind static NAT (all packets to a public IP address on the NAT device are forwarded to the Ipsec HUB SRX device and all packets from this box are source nated to the same public IP that never changes).
This is the same as having two spokes behind NAT and one of them having static NAT and a tunnel between the two is necessary. Below articles describes this situation and provides solution to make the static NAT spoke (or HUB) establish ipsec phase 1 with other spoke behind NAT.
http://forum.ivorde.ro/juniper-srx-spoke-to-spoke-ipsec-vpn-when-both-spokes-are-behind-nat-t15671.html
Since there are not many scenarios when the HUB is behind NAT, I've created an article that describes situations when two spokes are behind NAT and only one has a static NAT.
Most of the hub-and-spoke ipsec VPN environments have the HUB configured with a public IP address, but sometimes the HUB is behind static NAT (all packets to a public IP address on the NAT device are forwarded to the Ipsec HUB SRX device and all packets from this box are source nated to the same public IP that never changes).
This is the same as having two spokes behind NAT and one of them having static NAT and a tunnel between the two is necessary. Below articles describes this situation and provides solution to make the static NAT spoke (or HUB) establish ipsec phase 1 with other spoke behind NAT.
[url]http://forum.ivorde.ro/juniper-srx-spoke-to-spoke-ipsec-vpn-when-both-spokes-are-behind-nat-t15671.html[/url]