Depending on your version, you might want to change the following line:
set security ike gateway dyn-vpn-local-gw xauth access-profile dyn-vpn-access-profile
With the following
set security ike gateway dyn-vpn-local-gw aaa access-profile dyn-vpn-access-profile
Ref: https://forums.juniper.net/t5/SRX-Services-Gateway/SRX-IPsec-client-VPN/td-p/320612