There are many reasons for this to happen. One such reason is if you have a dynamic IP address on your router, then this could result in a failed connection. Since the IP address keeps changing, the VPN Tunnel might have problems reconnecting next time. Sometimes it might connect, but next time you want to connect and the IP address on the router has changed, then the connection cannot be setup to the remote server.This is due to lifetime expiry.
1. One solution for this is to keep a fixed IP address.
2. The other is to use "isakmp" keepalives. Turn on the isakmp keepalives on both the router and the PIX.
On the router the command is "crypto isakmp keepalive 30 5".
And on the PIX it is "isakmp keepalive 30 5"
where 30 is the time interval in seconds. Hence these keepalives are sent every 30 seconds. It can be a value between 10 to 3600 seconds. 5 is the retry interval in seconds.
With this the problem should be solved.Hope this is useful.