Problem Description:

ASA 5510 is the central site FW, multiple IPSEC tunnels present to ASA5505 remotes.
One of the remote is acting funny; the ipsec tunnel can be initiated from a ping inside cmd on the
ASA5510,

but the 5505 cannot initiate the tunnel.
Once the tunnel is up, traffic is 2-way.

After checking all the crypto map and no nat acls, and a reboot,
I was left diffing (comparing) a working 5505 config with one that was not working.
There were no differences other than the ip addresses.

Both tunnel setups were identical on the central site ASA5510 as well.

ping inside cmd on the remote ASA5505 would not only fail to bring up the tunnel but an SA was
not established either.

This told me that ISAKMP was failing (key exchange).

A debug :
debug crypto ipsec

said something to the effect that the 5510 was not able to properly determine the identity of the
incoming SA request from the 5505.

The below config on the 5510:

tunnel-group a.b.c.d ipsec-attributes
isakmp peer ip a.b.c.d no-xauth

fixed the problem !!!

Basically xauth was enabled for this incoming SA request on the 5510 but its supposed to be OFF by default,
and even after entering the above command it did not show up in “sh run” on the 5510.

What shows up is :

tunnel-group a.b.c.d general-attributes