Hello Martin,
Ensure all SA's are exact match between peer's.
Also on the pix initiate a "clear ipsec sa" and "clear isakmp sa" to force tunnel renegociate.
You should replace the netmask in then following command:
isakmp key ******** address x.x.x.x netmask 255.255.255.0
with 255.255.255.255
Then check if no-xauth and no-config-mode parameters are required.
Mike