(2013-09-25)
Problem
A VPN you've been fighting with for a while is finally shown as up, but the route you have tied to the tunnel interface it uses still shows as down.
Solution
Turn of VPN Monitor on the phase-2, which you probably clicked in random desperation during the diagnostic process. VPN Monitor requires that the far end be a Netscreen (or possibly a Juniper JunOS-based device), and if it isn't, the VPN Monitor never gets the feedback it wants to mark the link as up.