12-12-2009 01:47 AM
Hi,
I have the attached network topology:
A VPN is setup between the Branch RTR and DC Tier1 ASA. Branch WAE is registered with the natted IP of the core CM on Y.Y.Y.a. Branch users access the servers on their natted IPs Y.Y.Y.Y/16. At the Branch wccp redirection is setup at the Branch router while at the DC L2 redirection is configured on the Core SW.
I got the follwoing results from the tests I perfomed:
As a summary it seems it is something related to a NAT issue where the Branch WAE is seeing the initiated sessions as X.X.X.X/16 - Y.Y.Y.Y/16 while the core sees them as Z.Z.Z.Z/16 - X.X.X.X/16.
Considering that I cannot perform identity nat or terminate the VPN on Tier2 ASA, is there any solution to make the waas work with the servers natted to the Y.Y.Y.Y/16 range?
Regards,
Jad
12-14-2009 12:39 PM
Hi Jad,
Thanks for your post. For the results you describe in the first bullet ("VPN at the DC terminated on Tier1 ASA"), can you please post the relevant output from the command sh stat conn on each WAE?
Thanks,
Zach
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide