01-17-2024 11:17 AM
Hello Guys,
We have Cisco ASA 5508 on the leaseweb cloud. We have almost 17 site-to-site VPN instances. I have attached the screenshot for security reasons I have hidden the pubic IP address. The Local Network in attached screenshot is same subnet 10.12.192.0/24 with no NAT. It is named as LAN_Access.
The issue is that I try to make 2 more VPN tunnels with same LAN_Access (10.12.192.0/24) but during configuration there is a warning. "The protected traffic overlaps with that of the connection profile to "XX.XX.XX.XX" where XX is public IP of another remote ipsec peer. It is also using the same LAN_Access as local network. (10.12.192.0/24). Also the warning say This can cause traffic initiated from the local network which is intended to go through "YY.YY.YY.YY" New public IP address of ipsec remote peer to go through XX.XX.XX.XX instead.
XX.XX.XX.XX VPN profile is at the top. And the new YY.YY.YY.YY is at the bottom.
I don't understand what it means, Why it is happening maybe it's because there is the same LAN_Access (10.12.192.0/24) for all of the VPN profiles?
Also what is the priority number means in Edit IPsec site-to-site connection profile>>> Advanced>>>Crypto Map Entry>>>Priority?
The priority of XX.XX.XX.XX is 2 and the priority of YY.YY.YY.YY is 17
Please advise on this what should I do what the issue?
ASA inside Network: 10.12.192.0/24
ASA Outside Network: 176.9.102.214
The default gateway is: 176.9.102.215
Thanks in advance.
01-17-2024 02:47 PM - edited 01-17-2024 02:48 PM
@Hamidsattarrana well "Remote side local Network: 10.0.0.0/8" is going to conflict with any remote network in 10.0.0.0 address space, you should change this 10.0.0.0/8 to be more specific so it does not overlap with the other remote networks used for the other VPNs.
01-17-2024 02:50 PM
How can I view the configuration of 1 ipsec instance in cli?
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide