Symptom
When configuring vpn load-balancing with cluster encryption the ASA will create a default ikev1 policy and also a default ipsec transform set, the same is currently pushing 3des as encryption and md5 as hash. Usually uses ikev1 policy sequence number 65533 or higher, e.g.:
crypto ikev1 policy 65534
authentication pre-share
encryption 3des
hash md5
group 14
lifetime 86400
Conditions
vpn load-balancing with cluster encryption configuration