Phase succeeds but Phase fails. The management tunnel exists but can't negotiate data protection.
Proxy ID mismatch: Phase includes which networks to protect. If Site A says protect but Site B says , negotiation fails.
Transform set mismatch: ESP encryption or hash algorithms differ.
PFS disagreement: One side expects PFS, the other doesn't.
Verify that interesting traffic definitions match exactly on both peers.