cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
10272
Views
20
Helpful
32
Replies

Add new subnets to site to site VPN tunnel are already created.

virtuali1151
Level 1
Level 1

Hello,

 

I am using a Cisco ASA 5545, ASDM 7.6, I have a site to site VPN tunnel created and now I would like to route additional traffic over that VPN tunnel.  Can you please advise how I would do this via ASDM or CLI.

 

So the current remote network is 10.210.0.0/16, I would like to route the following remote ranges over the same VPN tunnel.

 

Address space (10.208.0.0/13):


10.210.0.0/16
10.211.0.0/16
10.212.0.0/16
10.213.0.0/16
10.214.0.0/16

32 Replies 32

I take it no NAT exemption is done if no NATTING is being done for any of the local source subnets for the IPSEC tunnel correct?

@CiscoPurpleBelt If you do not have NAT configured at all then you would not need a NAT exemption rule. You would need a NAT exemption if you have a dynamic NAT in your configuration (i.e. for internet access), that could potentially NAT outbound traffic. The NAT exemption rule would need to be placed above the dynamic NAT rule in order to be effective.

 

HTH

In reference to IPSEC VPN, I have the following, the DM objects are being natted to itself correct? I can replace the DM objects with a object-group containing both those objects correct? Why does X.X.X.30_new appear twice?
nat (inside,outside) source static DM_INLINE_NETWORK_1 DM_INLINE_NETWORK_1 destination static X.X.X.30_object X.X.X.30_object

Getting Started

Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community: