Hi,
Using show crypto isakmp sa you can find out which side started the tunnel (src). Or during maintenance window, generate interesting traffic and debug crypto engine/isakmp/ipsec.
Since the tunnel is established with no traffic, I'd suspect a routing issue on the remote side. For example, the router connected to the Netscreen should have a static route for the PIX's side LAN.
HTH,
Mustafa