09-25-2020 02:28 AM
i have to same model firewalls i configure site to site IPsec vpn its working fine both sides LAN network accessible everything working fine. i want to all my branch internet traffic going to HO Firewall Gateway branch isp did not use for internet traffic means my branch user internet traffic going out HO Firewall.is it possible is yes please help.
09-25-2020 02:48 AM
Hi @Salman.Baig
You need to amend your crypto map ACL that defines interesting traffic to include the networks 0.0.0.0/0.0.0.0.
On the HO ASA you will need to include the command same-security-traffic permit intra-interface and create a NAT rule to NAT the Branch traffic behind the HO office ASA outside interface.
HTH
09-25-2020 04:16 AM
Branch router point all traffic towards Tunnel interface towards HO
on HO maksure you allow the ACL and NAT available for this subnet to use internet.
Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community: