We have a requirement to create two VPN Tunnels
Local Subnet : 18.104.22.168/16 : Remote Subnet (DC): 22.214.171.124/8
Local Subnet : 126.96.36.199/16 : Remote Subnet : 188.8.131.52/16
DC has about 50 sites in that subnet range, If I create these two Tunnels as is, then the traffic meant for Site B may go through Site A's VPN Tunnel.
The only way I know how to achieve this is create individual subnets (49) and add them to Tunnel for Site A, but it's a pain.
Is there any other way to achive it without having to create 49 subnets?
You could complicate your configuration using NAT to over come this overlapping networks (that's also a pain)
Alternatively use a VTI instead of a crypto map with 2 static routes to the correct tunnel. The /16 would match the correct Site B tunnel and the /8 Site A tunnel.
There is nothing special about a VTI in your scenario, it's just your /16 is a more specific route so will be routed to the correct tunnel interface.