I have 3 sites with SRX routers one is at Main site IP10.0.1.0 with 2 remote sites that I am trying to get communtion between. Site RA IP 10.0.2.0 and Site RB 10.0.3.0 can communicate with Main site without problems Site RA has VPN to Main Site RB does not. How do I setup SRX to communicate between the 2 remote sites by going to Main site?
In the scenario you explained, where the remote sites can communicate already with the main site, I think you need to following:
A route for the internal subnets of Site RB with a next-hop of the Main Site. (I cant tell to what address because I dont know the complete topology nor the configuration on the devices).
A route for the internal subnets of Site RA with a next-hop of the Main Site.
A security-policy allowing traffic from/to the internal subnets of the remote sites. I cant tell the from-zone and to-zone to be configured on the security policy because again I dont know the topology nor your configuration.
If you would like to share some more information I will advise to provide:
Sound like you just need all three sites to be able to communicate with each other.
If that is the case, the simplest solution is to just create two move site-to-site vpn tunnels.
One from RB to main
One from RA to RB
These will be the same setup as your current tunnel just joining up all the remaining links.
Figured out the problem. I had to setup traffic selectors at main site.
Thanks for suggestions.