Hi,
Thanks for your advice, it has solved my problem and you has won a star.
I didn't have to open UDP 500 and IP 50. I think perhaps I'm using traversal-nat.
After I've read your message, I've found a thread about ACL with VPN started on September 29th (multiple access lists per VPN). It was very clear.
I've already enabled the antispoofing feature on all interfaces.
Do you have any advice or warn?
Thanks,
danr19