cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
359
Views
0
Helpful
1
Replies

ASA VPN Routing

kyle.ashcraft
Level 1
Level 1

Good Afternoon, Hoping I could get some clarification on something related to Cisco ASA tunnels that a bit confusing. I have provided a general high level diagram to hopefully help illustrate my point. My main focus would be from the East Coast perspective but works either directions. My East Coast firewall has an IPSEC tunnel built to the west coast and has "interesting traffic" filters applied on the tunnels for the respective networks. Where I am a little confused is the routing portion of this config. On the East Coast router my route table states in order to reach 4.4.4.1/32 use next-hop 3.3.3.2 which is used to build the VPN tunnel between the two site, makes sense. The route I'm confused about is it then states to reach 2.2.2.0/24 use next-hop 4.4.4.2. Traffic does work today between the sites but I'm not understanding how. From a routing perspective my Firewall doesn't have a route for the 4.4.4.2 gateway and that IP is on the perimeter router not the firewall so I don't understand how this works. The route does state use the "outside" interface so even though I don't have a gateway that I know how to route to if I send the data to the perimeter router regardless then he will know how to reach it. Hope I explained my confusion well enough and any information that can be provided would be appreciated. Thanks!

1 Reply 1

Jon Marshall
Hall of Fame
Hall of Fame

 

The diagram may help :) 

 

If 2.2.2.0/24 is the remote subnet via IPSEC then all you have to do is make sure the traffic is routed to the interface where you have applied your IPSEC crypto map so if the outside interface is where the crypto map is applied then that route would work although often with internet setups the default route points that way anyway. 

 

Like I say though, diagram would help as the above is all guesswork at the moment. 

 

Jon

Review Cisco Networking products for a $25 gift card