<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Multisite VPN routing issue in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/multisite-vpn-routing-issue/m-p/1135135#M1005205</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;This ended up being a twofold issue.  First, the interesting traffic needed to be defined on the ASA's as acomisky suggested, tyvm :).  Second, the 2810 router managed by the ASP had their ACL's configured incorrectly, and were not permitting traffic to the 10.0.0.0/16 subnet.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks all for your help.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Tue, 12 Aug 2008 18:25:50 GMT</pubDate>
    <dc:creator>zharin</dc:creator>
    <dc:date>2008-08-12T18:25:50Z</dc:date>
    <item>
      <title>Multisite VPN routing issue</title>
      <link>https://community.cisco.com/t5/network-security/multisite-vpn-routing-issue/m-p/1135128#M1005193</link>
      <description>&lt;P&gt;I have a client with several sites and have an interesting routing issue.  At Site B, the subnet is 10.0.0.0/16, with an ASA 5505.  Site A is 192.168.0.0/16, with an ASA5510, as well as a 2810 series router (managed by someone else).  There is one vpn tunnel between the two ASA's that is working just fine, site A to site B communication is working perfectly.  There is a second VPN at Site A from the 2810 router to a service provider (we'll call their site SiteC).  I've been able to hairpin the 5510 at site A so it redirects traffic for SiteC to the 2810.  However, at Site B, I can't seem to get the 5505 to take traffic destined for SiteC to get pushed through the VPN tunnel to Site A, and then on to the 2810.  &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;So, from Site A, I can ping anything on Site B, and anything on Site C.  From Site B, I can ping anything on SiteA, including the inside interface of the 2810 router.  I cannot ping from Site B to Site C, and vice versa.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I really hope that makes sense to you guys.  Ideas?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt; &lt;/P&gt;&lt;P&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 21 Feb 2020 10:57:20 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/multisite-vpn-routing-issue/m-p/1135128#M1005193</guid>
      <dc:creator>zharin</dc:creator>
      <dc:date>2020-02-21T10:57:20Z</dc:date>
    </item>
    <item>
      <title>Re: Multisite VPN routing issue</title>
      <link>https://community.cisco.com/t5/network-security/multisite-vpn-routing-issue/m-p/1135129#M1005194</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Does your ISP know how to get to 10.0.0.0/16?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Farrukh&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 07 Aug 2008 07:01:44 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/multisite-vpn-routing-issue/m-p/1135129#M1005194</guid>
      <dc:creator>Farrukh Haroon</dc:creator>
      <dc:date>2008-08-07T07:01:44Z</dc:date>
    </item>
    <item>
      <title>Re: Multisite VPN routing issue</title>
      <link>https://community.cisco.com/t5/network-security/multisite-vpn-routing-issue/m-p/1135130#M1005196</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Please forgive me if I am being dense, but I don't understand the relevance of whether the ISP knows how to route to my private subnet.  The ASA's should be doing the routing through the VPN tunnel, not the ISP.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 07 Aug 2008 11:25:20 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/multisite-vpn-routing-issue/m-p/1135130#M1005196</guid>
      <dc:creator>zharin</dc:creator>
      <dc:date>2008-08-07T11:25:20Z</dc:date>
    </item>
    <item>
      <title>Re: Multisite VPN routing issue</title>
      <link>https://community.cisco.com/t5/network-security/multisite-vpn-routing-issue/m-p/1135131#M1005198</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;On Site 'B', when you ping Site 'C', what do you see in the encrypted/decrypt?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;show crypto ipsec sa&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;How many VPN peer's do you have at Site "B"?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You need to tell more detail about your setup. Is the ASA5510 the hub or the 2810? Spokes are SiteBASA,SiteC Isp Device AND?&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Farrukh&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 07 Aug 2008 12:32:44 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/multisite-vpn-routing-issue/m-p/1135131#M1005198</guid>
      <dc:creator>Farrukh Haroon</dc:creator>
      <dc:date>2008-08-07T12:32:44Z</dc:date>
    </item>
    <item>
      <title>Re: Multisite VPN routing issue</title>
      <link>https://community.cisco.com/t5/network-security/multisite-vpn-routing-issue/m-p/1135132#M1005200</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I'll check the encrypt/decrypt next time I'm onsite.  The ASA5510 is the primary router at Site A.  The 2810 belongs to another company hosting a timeclock app, and is only used for the vpn connection to said company.  Site B's only VPN peer is to Site A.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Other spokes are not in place yet.  Once we figure out how to make Site B talk to Site C, we'll be adding another 30 or so spokes at remote locations, with VPN connections back to Site A so the remote sites can communicate to Site C.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 07 Aug 2008 13:50:49 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/multisite-vpn-routing-issue/m-p/1135132#M1005200</guid>
      <dc:creator>zharin</dc:creator>
      <dc:date>2008-08-07T13:50:49Z</dc:date>
    </item>
    <item>
      <title>Re: Multisite VPN routing issue</title>
      <link>https://community.cisco.com/t5/network-security/multisite-vpn-routing-issue/m-p/1135133#M1005202</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Encrypt/Decrypt doesn't change.  The 5505 doesn't appear to be directing the packets through the VPN tunnel.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 12 Aug 2008 12:20:06 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/multisite-vpn-routing-issue/m-p/1135133#M1005202</guid>
      <dc:creator>zharin</dc:creator>
      <dc:date>2008-08-12T12:20:06Z</dc:date>
    </item>
    <item>
      <title>Re: Multisite VPN routing issue</title>
      <link>https://community.cisco.com/t5/network-security/multisite-vpn-routing-issue/m-p/1135134#M1005204</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;You need to add the interesting traffic to both ASA's at site A and B. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;What is the network you are trying to reach on the other end of the vpn on the 2810? You need to add this network to the vpn between the ASA's. Let's say it's a.b.c.d/24.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Site B&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;access-list inside_nat0_outbound extended permit ip 10.0.0.0 255.255.0.0 a.b.c.d 255.255.255.0 &lt;/P&gt;&lt;P&gt;access-list outside_cryptomap extended permit ip 10.0.0.0 255.255.0.0 a.b.c.d 255.255.255.0 &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Site A&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;access-list Outside_1_cryptomap extended permit ip a.b.c.d 255.255.255.0 10.0.0.0 255.255.0.0&lt;/P&gt;&lt;P&gt;access-list inside_nat0_outbound extended permit ip a.b.c.d 255.255.255.0 10.0.0.0 255.255.0.0(assuming 2810 is inside asa)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Also need to know where the 2810 is in relation to Site A 5510.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Assuming the 2810 is inside the ASA it would require the following route.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;ip route 10.0.0.0 255.255.0.0 192.168.0.1&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Lastly, you would need to add the 10.0.0.0 network to the vpn traffic for the tunnel between 2810 and site c. Hope that helps.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 12 Aug 2008 13:51:11 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/multisite-vpn-routing-issue/m-p/1135134#M1005204</guid>
      <dc:creator>acomiskey</dc:creator>
      <dc:date>2008-08-12T13:51:11Z</dc:date>
    </item>
    <item>
      <title>Re: Multisite VPN routing issue</title>
      <link>https://community.cisco.com/t5/network-security/multisite-vpn-routing-issue/m-p/1135135#M1005205</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;This ended up being a twofold issue.  First, the interesting traffic needed to be defined on the ASA's as acomisky suggested, tyvm :).  Second, the 2810 router managed by the ASP had their ACL's configured incorrectly, and were not permitting traffic to the 10.0.0.0/16 subnet.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks all for your help.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 12 Aug 2008 18:25:50 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/multisite-vpn-routing-issue/m-p/1135135#M1005205</guid>
      <dc:creator>zharin</dc:creator>
      <dc:date>2008-08-12T18:25:50Z</dc:date>
    </item>
  </channel>
</rss>

