<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic ASA VPN Routing Overlap in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/asa-vpn-routing-overlap/m-p/4145375#M1073536</link>
    <description>&lt;P&gt;Hi&lt;/P&gt;&lt;P&gt;I am setting up a site to site VPN topology and think I may run into a problem. This will be deployed on up-to-date code on ASAv50's.&lt;/P&gt;&lt;P&gt;A Pair of A/S ASA's will have an IPSec VPN to Vendor Site 1 and another to Vendor Site 2. The issue that I have is that a single VIP will be reachable by both VPN's on the same ASA, so I will essentially have 2 VPN's that will have the same source and same destination traffic by way of the interesting traffic. They will terminate on different end points but the traffic profiles will be the same.&lt;/P&gt;&lt;P&gt;Will the box even let me set this up (I don't have the environment yet otherwise I would test) and if so, how do I choose between the tunnels. Is there such a thing as primary and secondary tunnels for a given set of traffic or am I trying something impossible?&lt;/P&gt;&lt;P&gt;Thanks in advance&lt;/P&gt;</description>
    <pubDate>Wed, 02 Sep 2020 20:16:24 GMT</pubDate>
    <dc:creator>anthonykahwati</dc:creator>
    <dc:date>2020-09-02T20:16:24Z</dc:date>
    <item>
      <title>ASA VPN Routing Overlap</title>
      <link>https://community.cisco.com/t5/network-security/asa-vpn-routing-overlap/m-p/4145375#M1073536</link>
      <description>&lt;P&gt;Hi&lt;/P&gt;&lt;P&gt;I am setting up a site to site VPN topology and think I may run into a problem. This will be deployed on up-to-date code on ASAv50's.&lt;/P&gt;&lt;P&gt;A Pair of A/S ASA's will have an IPSec VPN to Vendor Site 1 and another to Vendor Site 2. The issue that I have is that a single VIP will be reachable by both VPN's on the same ASA, so I will essentially have 2 VPN's that will have the same source and same destination traffic by way of the interesting traffic. They will terminate on different end points but the traffic profiles will be the same.&lt;/P&gt;&lt;P&gt;Will the box even let me set this up (I don't have the environment yet otherwise I would test) and if so, how do I choose between the tunnels. Is there such a thing as primary and secondary tunnels for a given set of traffic or am I trying something impossible?&lt;/P&gt;&lt;P&gt;Thanks in advance&lt;/P&gt;</description>
      <pubDate>Wed, 02 Sep 2020 20:16:24 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-vpn-routing-overlap/m-p/4145375#M1073536</guid>
      <dc:creator>anthonykahwati</dc:creator>
      <dc:date>2020-09-02T20:16:24Z</dc:date>
    </item>
    <item>
      <title>Re: ASA VPN Routing Overlap</title>
      <link>https://community.cisco.com/t5/network-security/asa-vpn-routing-overlap/m-p/4145735#M1073554</link>
      <description>&lt;P&gt;in this scenario you would need to NAT the subnet of one of the remote sites to a different IP or subnet.&amp;nbsp; For example.&amp;nbsp; If Site1 and Site 2 only need to connect to the VIP and the VIP does not need to connect to Site 1 or Site 2, then you could NAT the Site 2 subnet to a single IP and only allow that IP over that specific VPN.&amp;nbsp;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Optionally you would need to do a redesign and allocate another subnet to one of the sites.&lt;/P&gt;</description>
      <pubDate>Fri, 04 Sep 2020 12:27:46 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-vpn-routing-overlap/m-p/4145735#M1073554</guid>
      <dc:creator>Marius Gunnerud</dc:creator>
      <dc:date>2020-09-04T12:27:46Z</dc:date>
    </item>
  </channel>
</rss>

