Heads Up :
The post you are writing will appear in a public forum. Please ensure all content is appropriate for public consumption. Review the employee guidelines for the community here.
You will need to use "tunnel-group" command instead of what you are using for the pre-shared key:
tunnel-group 172.30.2.1 type ipsec-l2ltunnel-group 172.30.2.1 ipsec-attributes ikev1 pre-shared-key cisco12345
172.30.2.1 is the peer IP address
Looks like a bug with ISE version 2.4. I am running with same issue on version 2.4:
https://bst.cloudapps.cisco.com/bugsearch/bug/CSCvj14636/?rfs=iqvred
Workaround: reload the PAN and then application reset-passwd ise command will work.