Hi
You can use Sydney vpn to allow communication between Austria and Perth.
There's the nat solution but you'll need to add a subnet in your crypto acl to allow a nat 1:1.
The best solution, as you'll need to modify something, would be:
- on vpn between Austria and Sydney, add Perth subnets as destination for Austria and as source for Sydney.
- on vpn between Sydney and Perth, add Austria subnets as source for Sydney and as destination on Perth
- on Sydney, allow traffic to come in and go out the same interface (same-security-traffic permit intra-interface)
- on Sydney, configure your exempt nat by telling no nat between Austria and Perth.
That's it. It should work that way if you don't want to create a 3rd L2L between Austria and Perth.
Is that clear?
Thanks
Francesco
PS: Please don't forget to rate and select as validated answer if this answered your question