We've been struggling to get 3 SA520W's to make an IPSec Site-to-Site tunnel. After searching the web, we finally found a post about the Racoon firewall and this issue suggesting turning off Perfect Forward Secrecy. After turning off PFS on the SA ...