On Cisco IOS, these commands help diagnose VPN issues:
show crypto isakmp sa Displays Phase 1 status
show crypto ipsec sa Shows Phase 2 SAs and packet counters
debug crypto isakmp Verbose negotiation output
clear crypto isakmp Reset Phase 1 (then Phase 2 rebuilds)
Look for increasing encrypt/decrypt counters. Zero counters mean traffic isn't entering the tunnel.