We have SSG320 in our Data Center and SSG 5GT in one of our remote sites. We have 3 VPN's coming out of 5GT, two of them are going to NS 204 Devices. One of them is going to SSG320. One VPN going to one of the NS204 is working perfect. Second VPN using tunnel.2 going to second NS204 is not very stable it goes up and down for some reason intermittently But the third VPN via tunnel.5 to SSG320 is not coming up at all. I get SA up but Link shows down and I can't pass any traffic between the two sites. When I delete the VPN to SSG320 and recreate it, on both ends, it comes back up for like 60 seconds or so but it goes down again and I don't see any error messages either.
It sounds like you are using VPN monitoring. What happens if you disable VPN monitoring on both peers? Does your tunnel remain stable? If so and you are able to pass traffic through the tunnel, then likely VPN monitoring is failing for some reason. You should confirm your VPN monitoring settings are correct and that the VPN monitoring target is pingable by the peer. If the tunnel is up but no traffic is passing, then confirm if ESP traffic is passing between the two peers. You may need to connect a sniffer on the untrust sides of both peers to determine if the ESP packet is leaving the firewall and that the ESP packet is being received at the other side. If you do not see that then you may have a device on the network that is blocking ESP traffic.