There is a reason why Cisco asks to make the Crypto ACL's to be specific on regards to traffic definition, your setup will simply will not match, on your 515 you had the advantage of defining specific source and destination of your crypto acls on your ASA 7.0(8) you are not causing this security association never to match. Go ahead and try to change the ASA 7.0(8) crypto acls to look as how the pix 515 is and try again or make both the 7.0(7) and 7.0(8) specific.