I beleive its missing a route-lookup and a no-proxy-arp option at the end of the nat statement. My question is, as this site is live and can't afford any downtime, will me adding the command route-lookup and no-proxy-arp at the end of the NAT cause any temporary outage?
Curious have you tired connecting to the FW via its tunnel addressing?
Can you post the config of the asa?
Please rate and mark as an accepted solution if you have found any of the information provided useful. This then could assist others on these forums to find a valuable answer and broadens the community’s global network.