Heads Up :
The post you are writing will appear in a public forum. Please ensure all content is appropriate for public consumption. Review the employee guidelines for the community here.
Each VPN tunnel has its own crypto map that must be activated. The specified "interesting" traffic should be enough to bring up the tunnel so there shouldnt be a need to ping across the tunnel.
I wouldnt use access-lists to block traffic but instead I would use policy nat.access-list WEB permit ip x.x.x.x x.x.x.x any nat (inside) 1 access-list WEBglobal (outside) 1 interfaceYou will have to play with your subneting to get it right ..... I s...