FWIW:
When updating the IPSec Policy, under the ISAKMP (IKE) Settings, the IPSec Tunnel will fail if the "Authentication Algorithm" is to SHA2 512bit if a tunnel is setup between two different versions of ASG (e.g. v7.304 & v6.314). If the algorithm is downgraded to SHA2 256bit, the tunnel will establish itself.