Despite the fact that I have the following setting:
crypto isakmp nat-traversal 10
All tunnels are bi-directional.
Our l2l tunnels keep dropping due to inactivity. On one client, the tunnel drops and doesn't come back up unless you remove the remote IP range from their object group and re-add it. This issue is secondary, however.
What I really want to know is how to keep tunnels from timing out due to inactivity.