I've got a problem connecting a Cisco router to a BM3.8 server.

First, some config info:

------ Cisco -------

crypto isakmp policy 1
encr 3des
authentication pre-share
crypto isakmp key <key> address <bm public ip>
crypto ipsec transform-set vpn-pvm esp-3des esp-sha-hmac
crypto map static-map local-address Dialer1
crypto map static-map 1 ipsec-isakmp
set peer <bm public ip>
set security-association lifetime seconds 600
set transform-set vpn-pvm
set pfs group2
match address 111

interface Dialer1
ip address negotiated
ip nat outside
encapsulation ppp
dialer pool 1
dialer-group 1
no cdp enable
ppp authentication chap pap callin
ppp chap hostname <host>
ppp chap password <pass>
ppp pap sent-username <user> password <pass>
ppp ipcp dns request
ppp ipcp wins request
crypto map static-map
hold-queue 224 in

access-list 101 deny ip
access-list 101 permit ip any
access-list 111 permit ip
dialer-list 1 protocol ip permit

---- BorderManager ----

VPN Slave Member
- Server Address = <public ip cisco>'
- Tunneladres =
- Non-Bordermanager VPN
- PSS = <key>
- Protected network

3th Party Trafic Rules
- Gateway Address = <public ip cisco>
- 3th Party Server PNL =
- NBM Server PNL =
- Action = Encrypt
- Key Life Time By Time = 10 min
- Encryption = 3DES
- Authent = HMAC-SHA1

It starts connecting and the PSS are exchanged,
but in de Audit log & the BM server 1 get:
Failed to create IKE SA - Received message in the wrong state. Dest IP =
<public ip cisco>

Anyone nows where to look for solving this problem.

Best regards,