cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
957
Views
0
Helpful
2
Replies

ASA 5520 IPSEC vpn overlap

r.arzouni
Level 1
Level 1

Hi There,

We have multiple vpn tunnels coming to our cisco asa 5520 , the problem is that when we create another tunnel with the same network as another network on the firewall , it does not know how to route the traffic to which interface or sub interface.

How can we over come this , can you please help.

Thanks

R

2 Replies 2

andrew.prince
Level 10
Level 10

Search the forums for nat over IPSec, this question has been asked and answered many times

Sent from Cisco Technical Support iPad App

Patrick0711
Level 3
Level 3

Policy NAT on both ends of the tunnel or use public IP addresses on both ends. 

If your remote VPN subnet is the same as a local network on the firewall, the traffic will never get forwarded since a directly connected network route takes precedence over the default route.