Hello,
I am going through an ASA audit, and have found Customer A and Customer B have the same subnet in use. The crypto maps permit correct "interesting" traffic for each L2L (Customer network A mapped to remote site A and Customer network B is mapped to remote site B), but I have a monitoring subnet in which I would like to monitor the remote ASA and servers on remote subnet.
I am attaching a diagram to illustrate better. I am not sure if I should be NAT'ing the subnets into the local ASA where the L2L terminates. I don't see how the ASA will know which tunnel to forward monitoring traffic either. If I have to NAT, then my concern would be Customer A being able to use their tunnel to connect to their other 3 tunnels without having to point them at the new NAT block.
Any ideas or thoughts would be appreciated.