Here's what I've usually found the problem with
Phase: (Don't Care what phase)
Type: VPN
Subtype: encrypt
Result: DROP
The problem is usually this. Either you have something in your encryption domain that doesn't belong there or you have something i...