250 remote sites use ezvpn to connect back to ASA 5520. Tunnels show active but do not pass any IP traffic. The only way to resolve issue is to "clear crypto ipsec sa". Has happened twice in the last 3 days. Logs show messages of denying traffic for ...