Ryan,
I think the key is to have a transport-mode SA available. All of the SAs that come standard on the Cisco VPN server are tunnel-mode.
The specifics of what I got working for phase 2: ESP/SHA/HMAC-160 + AES-128. However, I suspect that 3DES will work fine if you have a tunnel-mode version.
Now my problem is that I can't authenticate - even if I create a local user with an all-numeric password, and set the group authentication mode to Internal, I still get an authentication failure. To be able to get into production with this I need to get SDI authentication working but when that wasn't working I thought I'd try with Internal, and that also doesn't work 😟