V4.0 supports single IPSec SA approach, no matter how many tunnel list one is pushing, and there are no public-to-public SAs anymore, so telnet to the outside won't work, also you need to add the "management-access inside" on the pix (requires V6.3.1 or later) and "telnet inside " to be able to telnet inside netowork