Hello, there could be many reasons for this.
What device on the "other" side are you trying todo a route-based VPN to?
If's a Juniper SRX you should be fine with the standard proposals.
If it's a Juniper SSG box some tuning is in order.
If it's a Checkpoint box some tuning is for sure going to be needed.
IKE phase 1 propoals not matching
preshared keys not matching
PFS settings, AES128 or AES256 or DH group 2 or group 5 etc etc.
One thing I always configure is this: establish-tunnels immediately
It's under this: edit security ipsec vpn NONAME
This the box always tries to negotiate to brind the tunnel up with regular intervals.
As the former poster said attach your configuration so we can help you better.
Regards
-John