Hi,
I don't see a nat0 ACL on the PIX running 8.x
Can you check the following:
PIX 8.x
access-list nonat permit ip 172.16.1.0 255.255.255.0 10.1.11.0 255.255.255.0
nat (inside) 0 access-list nonat
PIX 7.x
access-list nonat permit ip 10.1.11.0 255.255.255.0 172.16.1.0 255.255.255.0
nat (inside) 0 access-list nonat
The ACL applied to the crypto map should define the same traffic as the above ACL.
Also.. add the command ''management-access inside'' and try to PING between inside addresses.
ie.
From PIX 8.x
ping inside 10.1.11.1
Check the establishmet of phase 1:
sh cry isa sa
Check the establishment of phase 2:
sh cry ips sa
Federico.