This error message occurs when phase 1 attributes do not match on both ends of the VPN tunnel.
To resolve this issue, make sure the hash algorithm and the rest of the Internet Security Association and Key Management Protocol (ISAKMP) parameters are the same on both sides of the VPN tunnel.
This issue is related to Cisco bug ID CSCdu34352: ISAKMP SA negotiation not successful.
Note: The ISAKMP (0:2): Notify has no hash. Rejected message may be displayed in the debug log.
ISAKMP (0:2): Notify has no hash. Rejected
For more information, refer to the ISAKMP Policy Mismatch; Tunnel Initiated From CE1 section of Sample Problem Scenarios.