Hi,
Yes, you can configure authentication without Radius, i.e by Local Authentication, which I see you have already done below by creating the profile "user-auth-profile". So you may not require the Radius configuration below, but you need to apply the User-Profile to the "firewall-authentication"; for example
[edit access]
user@srx-1# show
firewall-authentication {
web-authentication {
default-profile user-auth-proflie
Sorry, I'm not sure about the Cos for Dynamic VPN.
Hope this helps a bit.