<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Remote access and site to site on the same ASA in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/remote-access-and-site-to-site-on-the-same-asa/m-p/1191787#M954676</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;The ACLs appear to be working fine.  I am passing IP traffic for all of the configured subnets with the exception of the remote access subnet.  I have both ends of the tunnel configured with the RA subnet in the crypto map.  I am not using reverse route injection.  Actually I am not at all familiar with it.  Do you think this is where I should start looking?  &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Mon, 27 Apr 2009 18:14:18 GMT</pubDate>
    <dc:creator>jhankin</dc:creator>
    <dc:date>2009-04-27T18:14:18Z</dc:date>
    <item>
      <title>Remote access and site to site on the same ASA</title>
      <link>https://community.cisco.com/t5/network-security/remote-access-and-site-to-site-on-the-same-asa/m-p/1191785#M954664</link>
      <description>&lt;P&gt;I am using an ASA 5510 for both remote access and site to site VPN.  Is there a way for the remote access clients to access the remote sites via the site to site tunnels?  I have included the IP address range of the remote access clients in the crypto maps for the site to site tunnels but their traffic appears to be blocked.  I suppose I could set up a second ASA to handle just the remote access users but I would prefer to avoid the expense if possible.  &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks  &lt;/P&gt;&lt;P&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 21 Feb 2020 11:25:42 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/remote-access-and-site-to-site-on-the-same-asa/m-p/1191785#M954664</guid>
      <dc:creator>jhankin</dc:creator>
      <dc:date>2020-02-21T11:25:42Z</dc:date>
    </item>
    <item>
      <title>Re: Remote access and site to site on the same ASA</title>
      <link>https://community.cisco.com/t5/network-security/remote-access-and-site-to-site-on-the-same-asa/m-p/1191786#M954672</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Are the acl configure correctly and are you permitting the traffic on the remote end?  You wont need that second ASA, I have this setup in my network now. Are you using RRI for the site to site?  Reverse route injection.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 27 Apr 2009 18:00:02 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/remote-access-and-site-to-site-on-the-same-asa/m-p/1191786#M954672</guid>
      <dc:creator>DialerString_2</dc:creator>
      <dc:date>2009-04-27T18:00:02Z</dc:date>
    </item>
    <item>
      <title>Re: Remote access and site to site on the same ASA</title>
      <link>https://community.cisco.com/t5/network-security/remote-access-and-site-to-site-on-the-same-asa/m-p/1191787#M954676</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;The ACLs appear to be working fine.  I am passing IP traffic for all of the configured subnets with the exception of the remote access subnet.  I have both ends of the tunnel configured with the RA subnet in the crypto map.  I am not using reverse route injection.  Actually I am not at all familiar with it.  Do you think this is where I should start looking?  &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 27 Apr 2009 18:14:18 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/remote-access-and-site-to-site-on-the-same-asa/m-p/1191787#M954676</guid>
      <dc:creator>jhankin</dc:creator>
      <dc:date>2009-04-27T18:14:18Z</dc:date>
    </item>
    <item>
      <title>Re: Remote access and site to site on the same ASA</title>
      <link>https://community.cisco.com/t5/network-security/remote-access-and-site-to-site-on-the-same-asa/m-p/1191788#M954678</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;RRI only injects a static route in the ASA routing table and removes it when the tunnel is down. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Can you provide a show run access-list, show run nat, sh run crypto and a sh run tunnel?  &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Can you paste the acl from the other side? &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 27 Apr 2009 18:22:02 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/remote-access-and-site-to-site-on-the-same-asa/m-p/1191788#M954678</guid>
      <dc:creator>DialerString_2</dc:creator>
      <dc:date>2009-04-27T18:22:02Z</dc:date>
    </item>
    <item>
      <title>Re: Remote access and site to site on the same ASA</title>
      <link>https://community.cisco.com/t5/network-security/remote-access-and-site-to-site-on-the-same-asa/m-p/1191789#M954681</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I have attached the output of the show commands as a text file.  &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt; &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 27 Apr 2009 19:16:17 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/remote-access-and-site-to-site-on-the-same-asa/m-p/1191789#M954681</guid>
      <dc:creator>jhankin</dc:creator>
      <dc:date>2009-04-27T19:16:17Z</dc:date>
    </item>
    <item>
      <title>Re: Remote access and site to site on the same ASA</title>
      <link>https://community.cisco.com/t5/network-security/remote-access-and-site-to-site-on-the-same-asa/m-p/1191790#M954684</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Where is your pool of addresses for: &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;address-pool RemoteAccPool&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 28 Apr 2009 17:43:16 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/remote-access-and-site-to-site-on-the-same-asa/m-p/1191790#M954684</guid>
      <dc:creator>DialerString_2</dc:creator>
      <dc:date>2009-04-28T17:43:16Z</dc:date>
    </item>
    <item>
      <title>Re: Remote access and site to site on the same ASA</title>
      <link>https://community.cisco.com/t5/network-security/remote-access-and-site-to-site-on-the-same-asa/m-p/1191791#M954687</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Your dynamic-map sequence number should always be higher than the static crypto maps.  &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You may want to start them at 6000 you can have up to 65535, and the number is optional&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 28 Apr 2009 17:51:56 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/remote-access-and-site-to-site-on-the-same-asa/m-p/1191791#M954687</guid>
      <dc:creator>DialerString_2</dc:creator>
      <dc:date>2009-04-28T17:51:56Z</dc:date>
    </item>
    <item>
      <title>Re: Remote access and site to site on the same ASA</title>
      <link>https://community.cisco.com/t5/network-security/remote-access-and-site-to-site-on-the-same-asa/m-p/1191792#M954691</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;The pool of addresses for remote access is 172.25.25.1 to 172.25.25.254.  This is the address pool referred to by RemoteAccPool.  I have confirmed that this range of addresses is in the ACLs on both ends of the tunnel.  This is were I first started looking when the traffic would not pass once the tunnel was established.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks     &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 28 Apr 2009 19:04:18 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/remote-access-and-site-to-site-on-the-same-asa/m-p/1191792#M954691</guid>
      <dc:creator>jhankin</dc:creator>
      <dc:date>2009-04-28T19:04:18Z</dc:date>
    </item>
  </channel>
</rss>

