I was thinking about it but GPRS feature set seems to be unvailable on branch SRX345. My current policy allow any sctp traffic (there is junos-sctp-any pre-defined in JUNOS)
Policy: Diameter, action-type: permit, State: enabled, Index: 57, Scope Policy: 0 Policy Type: Configured Sequence number: 1 From zone: trust, To zone: r-hss Source addresses: any-ipv4(global): 0.0.0.0/0 any-ipv6(global): ::/0 Destination addresses: HSS(global): 192.168.120.2/32 Application: junos-sctp-any IP protocol: 132, ALG: 0, Inactivity timeout: 0 Source port range: [0-0] Destination port range: [0-0] Per policy TCP Options: SYN check: No, SEQ check: No Session log: at-create
I have similar policy applied in both directions: trust->r-hss and r-hss -> trust