cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
937
Views
2
Helpful
16
Replies

CIsco ASA Configurations Guide 5508

Hamidsattarrana
Level 1
Level 1

Hello Guys,

We have Cisco ASA 5508 on the leaseweb cloud. We have almost 17 site-to-site VPN instances. I have attached the screenshot for security reasons I have hidden the pubic IP address. The Local Network in attached screenshot is same subnet 10.12.192.0/24 with no NAT. It is named as LAN_Access.

The issue is that I try to make 2 more VPN tunnels with same LAN_Access (10.12.192.0/24) but during configuration there is a warning. "The protected traffic overlaps with that of the connection profile to "XX.XX.XX.XX" where XX is public IP of another remote ipsec peer. It is also using the same LAN_Access as local network. (10.12.192.0/24). Also the warning say This can cause traffic initiated from the local network which is intended to go through "YY.YY.YY.YY" New public IP address of ipsec remote peer to go through XX.XX.XX.XX instead.

XX.XX.XX.XX VPN profile is at the top. And the new YY.YY.YY.YY is at the bottom.

I don't understand what it means, Why it is happening maybe it's because there is the same LAN_Access (10.12.192.0/24) for all of the VPN profiles?

Also what is the priority number means in Edit IPsec site-to-site connection profile>>> Advanced>>>Crypto Map Entry>>>Priority?

The priority of XX.XX.XX.XX is 2 and the priority of YY.YY.YY.YY is 17

Please advise on this what should I do what the issue? 

ASA inside Network: 10.12.192.0/24

ASA Outside Network: 176.9.102.214

The default gateway is: 176.9.102.215

Thanks in advance.

Overlapping Error.pngSite-to-Site.png

 

16 Replies 16

@Hamidsattarrana well "Remote side local Network: 10.0.0.0/8" is going to conflict with any remote network in 10.0.0.0 address space, you should change this 10.0.0.0/8 to be more specific so it does not overlap with the other remote networks used for the other VPNs.

Hamidsattarrana
Level 1
Level 1

How can I view the configuration of 1 ipsec instance in cli?