<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Hi Ben, in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/asa-routing-with-s2s-vpn/m-p/3034624#M134445</link>
    <description>&lt;P&gt;Hi Ben,&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;You are right the Routing on the ASA specifically with VPN normally takes the default gateway and the default gateway should be pointing to the next hop (ISP) but by configuring the nat exemption on the ASA you are going to make sure the traffic is not nat to the public ip and goes through the tunnel by matching the interesting traffic.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Hope this info helps!!&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Rate if helps you!!&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;-JP-&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Fri, 30 Jun 2017 00:05:15 GMT</pubDate>
    <dc:creator>JP Miranda Z</dc:creator>
    <dc:date>2017-06-30T00:05:15Z</dc:date>
    <item>
      <title>ASA routing with S2S VPN</title>
      <link>https://community.cisco.com/t5/network-security/asa-routing-with-s2s-vpn/m-p/3034623#M134444</link>
      <description>&lt;P&gt;I'm still fairly new to the ASA world. I'm trying to wrap my head around how the ASA handles routing. Specifically I'm looking at routing when there is also a site-to-site VPN. In the VPN configuration process we define "interesting traffic" and the peer IP, among other things. That traffic does not get NATed. The rest of the traffic is NATed to the outside interface's IP. So, for the VPN, how is the traffic routed? Is there any additional routes that need to be added or does the VPN configuration take care of that? As far as a default route (0.0.0.0 0.0.0.0 &amp;lt;IP&amp;gt;), I feel like that needs to point to the ISP IP. Ultimately I need to make sure VPN traffic goes to the remote peer and that everything else goes to the internet.&lt;/P&gt;</description>
      <pubDate>Tue, 12 Mar 2019 09:38:36 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-routing-with-s2s-vpn/m-p/3034623#M134444</guid>
      <dc:creator>Ben F</dc:creator>
      <dc:date>2019-03-12T09:38:36Z</dc:date>
    </item>
    <item>
      <title>Hi Ben,</title>
      <link>https://community.cisco.com/t5/network-security/asa-routing-with-s2s-vpn/m-p/3034624#M134445</link>
      <description>&lt;P&gt;Hi Ben,&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;You are right the Routing on the ASA specifically with VPN normally takes the default gateway and the default gateway should be pointing to the next hop (ISP) but by configuring the nat exemption on the ASA you are going to make sure the traffic is not nat to the public ip and goes through the tunnel by matching the interesting traffic.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Hope this info helps!!&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Rate if helps you!!&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;-JP-&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 30 Jun 2017 00:05:15 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-routing-with-s2s-vpn/m-p/3034624#M134445</guid>
      <dc:creator>JP Miranda Z</dc:creator>
      <dc:date>2017-06-30T00:05:15Z</dc:date>
    </item>
    <item>
      <title>Thanks for confirming! It</title>
      <link>https://community.cisco.com/t5/network-security/asa-routing-with-s2s-vpn/m-p/3034625#M134446</link>
      <description>&lt;P&gt;Thanks for confirming! It made sense, but when it comes to customer downtime I like to be sure if I am doing something new that I do it correctly.&lt;/P&gt;</description>
      <pubDate>Fri, 30 Jun 2017 12:34:23 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-routing-with-s2s-vpn/m-p/3034625#M134446</guid>
      <dc:creator>Ben F</dc:creator>
      <dc:date>2017-06-30T12:34:23Z</dc:date>
    </item>
  </channel>
</rss>

