Hello,
Can you verify that the Encryption algorithm, Authentication, and DH group are the same in both phases and tunnel devices? Also, can you verify that the Pre-shared key is the same? It is possible that it can not be authenticated by one of these settings.
After validating the settings you can apply the command via ssh /etc/init.d/ipsec restart to restart the tunnel negotiation.