<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic multiple L2L VPN's issue in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/multiple-l2l-vpn-s-issue/m-p/1668139#M536206</link>
    <description>&lt;P&gt;Dear all,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I will be honest and admit that I've gained my knowledge of ASA-5520 through trial &amp;amp; error and practical experience and I have no previous proper education on the matter, and I configure the ASA mereley using the ASDM (I have little knowledge of the ASA IOS commands), enough, let's get to the question..&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;We have an ASA-5520 with 2 DMZ interfaces, 1 inside, 1 outside&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;On the Inside:&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; head office network and voice (CUCM) infrastructure&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;On the DMZ:&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; FTP, gateway servers etc&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;On DMZ2:&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Branch offices that are connected to our head office via L2L VPN, using a single ISP's WAN (we call it data subscription, meaning&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; that the branch offices are accessing all network resources through the ASA )&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;On the Outside:&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Public IP address connected to the ISP internet subscription, where we have also configured L2L VPN with other branch offices (that&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; use other IPS's)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;What I'm trying to accomplish is establish connectivity between one branch from the DMZ2 zone to another branch from the Outside zone, this implies:&lt;/P&gt;&lt;P&gt;1. connecting the Voice VLAN of both branches&lt;/P&gt;&lt;P&gt;2. connecting the Data VLAN of both branches&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I was able to establish this with one Outside branch (site A) to another DMZ2 branch (site B), however I'm not able to establish the same between site A and another DMZ2 site (site C). I went through the configuration of all devices over and over again, and I still can not find what I missed to not be able to replicate my success with A to B&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I know my explanation is a nightmare, however I'm only asking if there's a checklist that I should follow, or any hint on troubleshooting the issue.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks a lot&lt;/P&gt;</description>
    <pubDate>Mon, 11 Mar 2019 20:57:57 GMT</pubDate>
    <dc:creator>Saladin211</dc:creator>
    <dc:date>2019-03-11T20:57:57Z</dc:date>
    <item>
      <title>multiple L2L VPN's issue</title>
      <link>https://community.cisco.com/t5/network-security/multiple-l2l-vpn-s-issue/m-p/1668139#M536206</link>
      <description>&lt;P&gt;Dear all,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I will be honest and admit that I've gained my knowledge of ASA-5520 through trial &amp;amp; error and practical experience and I have no previous proper education on the matter, and I configure the ASA mereley using the ASDM (I have little knowledge of the ASA IOS commands), enough, let's get to the question..&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;We have an ASA-5520 with 2 DMZ interfaces, 1 inside, 1 outside&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;On the Inside:&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; head office network and voice (CUCM) infrastructure&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;On the DMZ:&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; FTP, gateway servers etc&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;On DMZ2:&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Branch offices that are connected to our head office via L2L VPN, using a single ISP's WAN (we call it data subscription, meaning&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; that the branch offices are accessing all network resources through the ASA )&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;On the Outside:&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Public IP address connected to the ISP internet subscription, where we have also configured L2L VPN with other branch offices (that&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; use other IPS's)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;What I'm trying to accomplish is establish connectivity between one branch from the DMZ2 zone to another branch from the Outside zone, this implies:&lt;/P&gt;&lt;P&gt;1. connecting the Voice VLAN of both branches&lt;/P&gt;&lt;P&gt;2. connecting the Data VLAN of both branches&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I was able to establish this with one Outside branch (site A) to another DMZ2 branch (site B), however I'm not able to establish the same between site A and another DMZ2 site (site C). I went through the configuration of all devices over and over again, and I still can not find what I missed to not be able to replicate my success with A to B&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I know my explanation is a nightmare, however I'm only asking if there's a checklist that I should follow, or any hint on troubleshooting the issue.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks a lot&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 20:57:57 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/multiple-l2l-vpn-s-issue/m-p/1668139#M536206</guid>
      <dc:creator>Saladin211</dc:creator>
      <dc:date>2019-03-11T20:57:57Z</dc:date>
    </item>
    <item>
      <title>Re: multiple L2L VPN's issue</title>
      <link>https://community.cisco.com/t5/network-security/multiple-l2l-vpn-s-issue/m-p/1668140#M536207</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;This sounds like it could be either a nat issue/a same interface traffic/or generic routing problem&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Sent from Cisco Technical Support iPad App&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 13 Jul 2011 11:10:23 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/multiple-l2l-vpn-s-issue/m-p/1668140#M536207</guid>
      <dc:creator>andrew.prince</dc:creator>
      <dc:date>2011-07-13T11:10:23Z</dc:date>
    </item>
  </channel>
</rss>

