04-03-2018 06:30 AM - edited 03-12-2019 05:09 AM
Hi Team ,
I have an ASA 5585 running in multi context mode.
I already have an IPSEC VPN running on system with source as 10.0.0.0/8.
Now I have to create one more VPN with source as 10.2.0.0/16 network.
The problem is that 10.2.00.00 is also being used at new peer. So they want me to NAT the 10.2.0.0 ip behind 10.250.x.x ip.
But my concern is that 10.250.0.0 also falls in 10.0.0.0 and therefore the traffic would go from existing VPN.
I tried to add a deny statement for 10.250.x.x IP above the permit statement in interesting traffic for existing VPN.
But My VPN is not coming up. Not even initiating.
sh crypto isa sa shows only existing VPN
04-03-2018 07:08 AM
Deny statement in crypto acl works, so it should be something else.
Can you post a packet-tracer with details ?
04-03-2018 07:16 AM
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide