<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Routing problem behind ASA VPN (lan2lan) ASA connection? in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/routing-problem-behind-asa-vpn-lan2lan-asa-connection/m-p/3856078#M27271</link>
    <description>&lt;P&gt;Hi all,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have an ASA L2L ASA connection (including VPN Dial-In on both ASAs) up and running. Additionally Internet connection works fine.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;LAN 1----- ASA1 --------IPSec-VPN-L2L----- ASA2 ----- LAN 2.&lt;/P&gt;&lt;P&gt;All works fine.&lt;/P&gt;&lt;P&gt;Now I added a cisco 2960-x switch with an SVI Interface an 2 vlan to LAN 1.&lt;/P&gt;&lt;P&gt;VLAN 10-----SVI ------LAN1(VLAN1) ------ASA1-----IPSecVPN-----ASA2-----LAN2.&lt;/P&gt;&lt;P&gt;VLAN20------!&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;From VLAN 10, 20, 1 I can ping the Internet, but from VLAN 10,20 I can't reach LAN2 behind ASA2.&lt;/P&gt;&lt;P&gt;On ASA1 I extended my crypto-map ACL additionally to LAN1 with VLAN10,10 (Subnets) to allow it through the VPN Tunnel. Additionally I added to inside routes on ASA1 facing to the vlan10,20)&lt;/P&gt;&lt;P&gt;route inside 10.0.10.0 and 10.20.0 to VLAN1 interface Swicht-SVI-ASA1 transfer subnet. I think routing between switch and asa1 works because Internet access is ok. It seems to me that the source traffic doesn't enter the VPN-tunnel. Interesting. Ping from an host in vlan1-ASA1 through the VPN tunnel to LAN2 works?&lt;/P&gt;&lt;P&gt;Any ideas?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;many thx&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Peter&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Tue, 14 May 2019 15:35:54 GMT</pubDate>
    <dc:creator>1pdemharter</dc:creator>
    <dc:date>2019-05-14T15:35:54Z</dc:date>
    <item>
      <title>Routing problem behind ASA VPN (lan2lan) ASA connection?</title>
      <link>https://community.cisco.com/t5/network-security/routing-problem-behind-asa-vpn-lan2lan-asa-connection/m-p/3856078#M27271</link>
      <description>&lt;P&gt;Hi all,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have an ASA L2L ASA connection (including VPN Dial-In on both ASAs) up and running. Additionally Internet connection works fine.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;LAN 1----- ASA1 --------IPSec-VPN-L2L----- ASA2 ----- LAN 2.&lt;/P&gt;&lt;P&gt;All works fine.&lt;/P&gt;&lt;P&gt;Now I added a cisco 2960-x switch with an SVI Interface an 2 vlan to LAN 1.&lt;/P&gt;&lt;P&gt;VLAN 10-----SVI ------LAN1(VLAN1) ------ASA1-----IPSecVPN-----ASA2-----LAN2.&lt;/P&gt;&lt;P&gt;VLAN20------!&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;From VLAN 10, 20, 1 I can ping the Internet, but from VLAN 10,20 I can't reach LAN2 behind ASA2.&lt;/P&gt;&lt;P&gt;On ASA1 I extended my crypto-map ACL additionally to LAN1 with VLAN10,10 (Subnets) to allow it through the VPN Tunnel. Additionally I added to inside routes on ASA1 facing to the vlan10,20)&lt;/P&gt;&lt;P&gt;route inside 10.0.10.0 and 10.20.0 to VLAN1 interface Swicht-SVI-ASA1 transfer subnet. I think routing between switch and asa1 works because Internet access is ok. It seems to me that the source traffic doesn't enter the VPN-tunnel. Interesting. Ping from an host in vlan1-ASA1 through the VPN tunnel to LAN2 works?&lt;/P&gt;&lt;P&gt;Any ideas?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;many thx&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Peter&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 14 May 2019 15:35:54 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/routing-problem-behind-asa-vpn-lan2lan-asa-connection/m-p/3856078#M27271</guid>
      <dc:creator>1pdemharter</dc:creator>
      <dc:date>2019-05-14T15:35:54Z</dc:date>
    </item>
    <item>
      <title>Re: Routing problem behind ASA VPN (lan2lan) ASA connection?</title>
      <link>https://community.cisco.com/t5/network-security/routing-problem-behind-asa-vpn-lan2lan-asa-connection/m-p/3856096#M27272</link>
      <description>&lt;P&gt;Hi there,&lt;/P&gt;
&lt;P&gt;Have you added VLANs 10 and 20 to the NAT exemption rule on ASA1?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Can you share the running confg of ASA1 so we can confirm?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;cheers,&lt;/P&gt;
&lt;P&gt;Seb.&lt;/P&gt;</description>
      <pubDate>Tue, 14 May 2019 15:56:33 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/routing-problem-behind-asa-vpn-lan2lan-asa-connection/m-p/3856096#M27272</guid>
      <dc:creator>Seb Rupik</dc:creator>
      <dc:date>2019-05-14T15:56:33Z</dc:date>
    </item>
    <item>
      <title>Re: Routing problem behind ASA VPN (lan2lan) ASA connection?</title>
      <link>https://community.cisco.com/t5/network-security/routing-problem-behind-asa-vpn-lan2lan-asa-connection/m-p/3856162#M27275</link>
      <description>&lt;P&gt;Hello&amp;nbsp;&lt;SPAN&gt;Peter,&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;When you want new IP ranges or subnets to be a part of existing VPN setup, you have to update these new ranges/subnets into all relevant configuration parts at both ends (object groups, crypto-map ACL, interface ACL, NAT, routing and so on...).&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;If it still does not work, please attach your configuration at both ends (in .txt files)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I hope it helps.&lt;/P&gt;</description>
      <pubDate>Tue, 14 May 2019 17:00:26 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/routing-problem-behind-asa-vpn-lan2lan-asa-connection/m-p/3856162#M27275</guid>
      <dc:creator>Netlabbuilder</dc:creator>
      <dc:date>2019-05-14T17:00:26Z</dc:date>
    </item>
    <item>
      <title>Re: Routing problem behind ASA VPN (lan2lan) ASA connection?</title>
      <link>https://community.cisco.com/t5/network-security/routing-problem-behind-asa-vpn-lan2lan-asa-connection/m-p/3856543#M27278</link>
      <description>&lt;P&gt;Many thx! I will check it&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Peter&lt;/P&gt;</description>
      <pubDate>Wed, 15 May 2019 08:03:34 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/routing-problem-behind-asa-vpn-lan2lan-asa-connection/m-p/3856543#M27278</guid>
      <dc:creator>1pdemharter</dc:creator>
      <dc:date>2019-05-15T08:03:34Z</dc:date>
    </item>
    <item>
      <title>Re: Routing problem behind ASA VPN (lan2lan) ASA connection?</title>
      <link>https://community.cisco.com/t5/network-security/routing-problem-behind-asa-vpn-lan2lan-asa-connection/m-p/3856546#M27279</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;many thx! I will check it.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Peter&lt;/P&gt;</description>
      <pubDate>Wed, 15 May 2019 08:04:18 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/routing-problem-behind-asa-vpn-lan2lan-asa-connection/m-p/3856546#M27279</guid>
      <dc:creator>1pdemharter</dc:creator>
      <dc:date>2019-05-15T08:04:18Z</dc:date>
    </item>
  </channel>
</rss>

