<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic How can we implement 2 tunnels (same source firewall, different destination firewall) with same source and destination subnet. in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/how-can-we-implement-2-tunnels-same-source-firewall-different/m-p/4014816#M23079</link>
    <description>&lt;P&gt;I have come across a conflict situation. And given the limitation that we cannot apply an NAT to remote environment.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Tunnel 1&lt;/P&gt;&lt;P&gt;Local Firewall IP : x.x.x.x&lt;/P&gt;&lt;P&gt;Peer Firewall IP : y.y.y.y&lt;/P&gt;&lt;P&gt;Local Subnet : 10.252.100.0/24&lt;/P&gt;&lt;P&gt;Remote Subnet : 192.168.100.0/24&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Tunnel 2&lt;/P&gt;&lt;P&gt;Local Firewall IP : x.x.x.x&lt;/P&gt;&lt;P&gt;Peer Firewall IP : z.z.z.z&lt;/P&gt;&lt;P&gt;Local Subnet : 10.252.100.0/24&lt;/P&gt;&lt;P&gt;Remote Subnet : 192.168.100.0/24&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Please advise how can this be solved using ASA5515 firewalls.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Mon, 20 Jan 2020 18:26:29 GMT</pubDate>
    <dc:creator>ahin.shaw</dc:creator>
    <dc:date>2020-01-20T18:26:29Z</dc:date>
    <item>
      <title>How can we implement 2 tunnels (same source firewall, different destination firewall) with same source and destination subnet.</title>
      <link>https://community.cisco.com/t5/network-security/how-can-we-implement-2-tunnels-same-source-firewall-different/m-p/4014816#M23079</link>
      <description>&lt;P&gt;I have come across a conflict situation. And given the limitation that we cannot apply an NAT to remote environment.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Tunnel 1&lt;/P&gt;&lt;P&gt;Local Firewall IP : x.x.x.x&lt;/P&gt;&lt;P&gt;Peer Firewall IP : y.y.y.y&lt;/P&gt;&lt;P&gt;Local Subnet : 10.252.100.0/24&lt;/P&gt;&lt;P&gt;Remote Subnet : 192.168.100.0/24&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Tunnel 2&lt;/P&gt;&lt;P&gt;Local Firewall IP : x.x.x.x&lt;/P&gt;&lt;P&gt;Peer Firewall IP : z.z.z.z&lt;/P&gt;&lt;P&gt;Local Subnet : 10.252.100.0/24&lt;/P&gt;&lt;P&gt;Remote Subnet : 192.168.100.0/24&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Please advise how can this be solved using ASA5515 firewalls.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 20 Jan 2020 18:26:29 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/how-can-we-implement-2-tunnels-same-source-firewall-different/m-p/4014816#M23079</guid>
      <dc:creator>ahin.shaw</dc:creator>
      <dc:date>2020-01-20T18:26:29Z</dc:date>
    </item>
    <item>
      <title>Re: How can we implement 2 tunnels (same source firewall, different destination firewall) with same source and destination subnet.</title>
      <link>https://community.cisco.com/t5/network-security/how-can-we-implement-2-tunnels-same-source-firewall-different/m-p/4014849#M23080</link>
      <description>&lt;P&gt;You have to NAT somewhere to mitigate the Same subnet in the environment.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;what device remote end ?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 20 Jan 2020 19:42:42 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/how-can-we-implement-2-tunnels-same-source-firewall-different/m-p/4014849#M23080</guid>
      <dc:creator>balaji.bandi</dc:creator>
      <dc:date>2020-01-20T19:42:42Z</dc:date>
    </item>
    <item>
      <title>Re: How can we implement 2 tunnels (same source firewall, different destination firewall) with same source and destination subnet.</title>
      <link>https://community.cisco.com/t5/network-security/how-can-we-implement-2-tunnels-same-source-firewall-different/m-p/4015321#M23081</link>
      <description>&lt;P&gt;Palo Alto&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I am okay with doing NAT at our end (Cisco ASA). We cannot do NAT at remote ends.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thank You.&lt;/P&gt;</description>
      <pubDate>Tue, 21 Jan 2020 14:01:47 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/how-can-we-implement-2-tunnels-same-source-firewall-different/m-p/4015321#M23081</guid>
      <dc:creator>ahin.shaw</dc:creator>
      <dc:date>2020-01-21T14:01:47Z</dc:date>
    </item>
    <item>
      <title>Re: How can we implement 2 tunnels (same source firewall, different destination firewall) with same source and destination subnet.</title>
      <link>https://community.cisco.com/t5/network-security/how-can-we-implement-2-tunnels-same-source-firewall-different/m-p/4015407#M23082</link>
      <description>&lt;P&gt;yes you can mitigate with differege IP address one of the site to NAT at your end.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;make sure they allow your New IP address far end ACL.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 21 Jan 2020 15:21:27 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/how-can-we-implement-2-tunnels-same-source-firewall-different/m-p/4015407#M23082</guid>
      <dc:creator>balaji.bandi</dc:creator>
      <dc:date>2020-01-21T15:21:27Z</dc:date>
    </item>
    <item>
      <title>Re: How can we implement 2 tunnels (same source firewall, different destination firewall) with same source and destination subnet.</title>
      <link>https://community.cisco.com/t5/network-security/how-can-we-implement-2-tunnels-same-source-firewall-different/m-p/4015667#M23083</link>
      <description>&lt;P&gt;The solution is brief that I realized after Balaji's comment and looking at the packet flow of Cisco ASA.&lt;/P&gt;&lt;P&gt;&lt;A href="https://www.cisco.com/c/en/us/support/docs/security/asa-5500-x-series-next-generation-firewalls/113396-asa-packet-flow-00.html" target="_blank"&gt;https://www.cisco.com/c/en/us/support/docs/security/asa-5500-x-series-next-generation-firewalls/113396-asa-packet-flow-00.html&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;ASA performs XLATE functionality which can act as Pseudo address for destination, similarly i have to NAT my source to different address. So following this when a route for tunnel is established it knows the forward (Pseudo Address) and reverse path (NATed Source).&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I don't have environment to test but definitely feel it will working knowing ASA creates policy based tunnel.&amp;nbsp;&lt;/P&gt;&lt;P&gt;Original thought was identifying solution for such cases using PA, Checkpoint, ASA and Fortigate.&lt;/P&gt;</description>
      <pubDate>Tue, 21 Jan 2020 21:02:06 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/how-can-we-implement-2-tunnels-same-source-firewall-different/m-p/4015667#M23083</guid>
      <dc:creator>ahin.shaw</dc:creator>
      <dc:date>2020-01-21T21:02:06Z</dc:date>
    </item>
  </channel>
</rss>

