cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
308
Views
0
Helpful
1
Replies

3 site vpn traffic

cb80
Level 1
Level 1

Hi all 

 

just needing some assistance if possible

 

 I’ve 3 asa 5505 conning via site to site vpn 

 

device A is connected to device B via IPSec vpn 

device C is connected to device B via IPSec vpn 

 

both network   A and network C can talk to network B ok 

 

However network A can’t communicate with network C. I did some packet tracing and it indicated crpytomaps needed to be updated which I have. However. Still the same. Anyone able to point me in the right direction of advise of some commands I can try. 

thanks for any assistance

1 Reply 1

The two most often forgotten configs in this scenario are:

  • NAT exemption for traffic A->C and C->A with interfaces (outside, outside)
  • same-security-traffic permit intra-interface