I made it work with 2 changes: 1. On SonicWALL VPN policy editor I checked the checkbox "Advanced/Enable IKE Mode Configuration" and them set a IP pool. 2. In the ipsec.conf I _removed_ the line Paul suggested: "leftmodecfgclient=yes"