ASA5512 ASA Version 9.2(2)4 interface GigabitEthernet0/0 channel-group 1 mode active no nameif no security-level no ip address interface GigabitEthernet0/1 channel-group 1 mode active no nameif no security-level no ip address interface GigabitEthernet0/2 no nameif security-level 100 no ip address interface GigabitEthernet0/2.6 vlan 6 nameif CUST-TEST-VPN security-level 90 ip address 172.22.100.30 255.255.255.252 interface Port-channel1 lacp max-bundle 8 nameif BGP2_UPLINK security-level 0 no ip address interface Port-channel1.5 vlan 15 nameif Internet security-level 0 ip address object network VPN-Test-LAN subnet 10.1.0.0 255.255.255.0 object network VPN-Test-VRF subnet 10.2.0.0 255.255.255.0 object network VPN-Test-Interface subnet 172.22.100.28 255.255.255.252 object-group network DM_INLINE_NETWORK_2 network-object object VPN-Test-Interface network-object object VPN-Test-VRF access-list Internet_access_in extended deny ip any any log access-list Test-VPN_cryptomap extended permit ip object-group DM_INLINE_NETWORK_1 10.1.0.0 255.255.255.0 log access-list CUST-TEST-VPN_access_in extended permit ip any any log icmp permit any Internet icmp permit 10.1.0.0 255.255.255.0 Internet icmp permit any CUST-TEST-VPN nat (CUST-TEST-VPN,Internet) source static DM_INLINE_NETWORK_2 DM_INLINE_NETWORK_2 destination static VPN-Test-LAN VPN-Test-LAN route-lookup access-group Internet_access_in in interface Internet access-group CUST-TEST-VPN_access_in in interface CUST-TEST-VPN route Internet 0.0.0.0 0.0.0.0 1 route CUST-TEST-VPN 10.2.0.0 255.255.255.0 172.22.100.29 1 crypto ipsec ikev1 transform-set ESP-AES-256-SHA esp-aes-256 esp-sha-hmac crypto ipsec ikev1 transform-set ESP-AES-256-SHA-TRANS esp-aes-256 esp-sha-hmac crypto ipsec ikev1 transform-set ESP-AES-256-SHA-TRANS mode transport crypto ipsec security-association pmtu-aging infinite crypto map Internet_map3 1 match address Test-VPN_cryptomap crypto map Internet_map3 1 set peer crypto map Internet_map3 1 set ikev1 transform-set ESP-AES-256-SHA crypto map Internet_map3 1 set reverse-route crypto map Internet_map3 interface Internet crypto ca trustpool policy crypto ikev1 enable Internet crypto ikev1 policy 30 authentication pre-share encryption aes-256 hash sha group 2 lifetime 86400 group-policy GP-Inframon internal group-policy GP-Inframon attributes vpn-filter value Test-VPN_cryptomap vpn-tunnel-protocol ikev1 tunnel-group type ipsec-l2l tunnel-group general-attributes default-group-policy GP-Inframon tunnel-group ipsec-attributes ikev1 pre-shared-key *****