If you using multiple IPSec profiles, you may run into multiple issues.

Changing tunnel protection without rebooting: Follow sequence


interface tunnel 20
shut
exit
!
interface tunnel 20
no tunnel protection ipsec profile DMVPN_IPS shared
exit
!
interface tunnel 20
no shut
!
end

Showing ISAKMP SA


show crypto isakmp sa

Clearing ISAKMP


clear crypto isakmp 1004

Confirming changes:


show dmvpn detail