Hello Tom,
As soon as you get the problem please add the following command on the ASA:
more system:running-config | begin tunnel
Then check the pre-shared key to confirm is the right you are applying into the client,
Regards,
Julio
Julio Carvajal
Senior Network Security and Core Specialist
CCIE #42930, 2xCCNP, JNCIP-SEC