Internal network(branch)---->ASA5505 <------->BT ADSL(dynamic IP, NAT)<-------Internet------->ASA5510<----Internal network(HQ)
You can ping successfully from left to right but not from right to left.
Had this been a route issue then PING would not have been successful any way.
We need to check:
1. When you ping from right to left (HQ->BR) ,
- does the packet make it to the HQ FW
- Does the HQ FW encrypts it (do you see increasing TX in ipsec sa (sh cry ipsec sa))
- Do you see increasing RX in the BR (sh cry ipsec SA)
- Do you see increasing TX in the BR (if you see this, that means the echo request made it to the destination and echo reply came back - this probably will not be the case since you are here reading this )
- Does the echo request make it to the actual destination
- Do you see echo reply coming out of the destination
Check for any FW on the destination, If Windows XP and if Cisco VPN client installed, check for Stateful FW option in the VPN client. if on turn it off.
Try again.