cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
768
Views
0
Helpful
1
Replies

ASA to ASA VPN IPSEC

muflixcek
Level 1
Level 1

Hello, i tried to do this example https://learningnetwork.cisco.com/docs/DOC-8696 but im not able to solve it. im using GNS3 and here is my topology

in Attached Files are my 2 ASA configs

routes seems ok to me

ASA1

ASA2

other commands

sh crypto isakmp sa detail

There are no IKEv1 SAs

There are no IKEv2 SAs

sh crypto ipsec sa

There are no ipsec sas

in clouds i have two windows 7 running in vmware, they can ping their routers but not anything else

what do you think ? :-) please help

1 Reply 1

Herbert Baerten
Cisco Employee
Cisco Employee

For starters, if ASA1 and ASA2 are directly connected to each other then they should be in the same subnet, i.e. ASA2 should be e.g. 10.0.0.2.

Otherwise, you need a router between them to route between the 10.0.0.0 and the 20.0.0.0 subnets.

hth

Herbert