Hi,
Only when you initiate an end to end ping will the traffic pass through a policy based VPN. This is because the VPN encryption domain is formed by what is specified in the policy. So both the objects as well as the direction are equally important. Even if you specify a source in the ping the source-zone is still going to "Junos-host". And in your setup we do not have a policy which allows VPN traffic from-zone "junos-host".
I hope this explains your issue.
Regards,
Anand