This problem may happen when dynamic crypto map comes up before static crypto map in the sequence, the tunnel fails to come up in such cases.
In order to resolve this issue, assign a higher sequence number to the dynamic crypto map.
For example : crypto map newmap 65525 ipsec-isakmp dynamic cisco
Following link may help you
http://www.cisco.com/en/US/products/ps6120/products_configuration_example09186a00805733df.shtml