Are they running the latest firmware? I found a recent posting at Cisco forums relating to 520W's having the same error and a new firmware supposedly fixed many VPN problems. Also, have you tried rebooting/clearing the SA's? The settings you have look pretty basic and should work fine, I don't see anything out of the ordinary.
I also found a suggestion relating to a Cisco -> Netgear setup where they used a dynamic DNS name and that solved the problem oddly enough.