Hello Diego.. Did you have outbound access-groups applied? I'm working on a similar problem that was fixed when I added an element for 'gre' in the ACL applied to the interface. I'm now trying to determine if this behavior is by design or a bug......