cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
1019
Views
5
Helpful
5
Replies

site-to-site route

balashovmm
Level 1
Level 1

Hello.

I have site-to-site VPN using two ASAs 5505. I can ping between two computers C1 and C2. Now I want to add subnet 192.168.1.0. How do I configure routes on ASA so that I can ping between computers C3 and C2?

Документ5.jpg

5 Replies 5

Jon Marshall
Hall of Fame
Hall of Fame

You don't configure routes as such, you just need to add the subnet 192.168.1.0/24 to both crypto map access-lists on the ASAs. If you are doing nat exemption on the existing subnets ie. 192.168.2.x and 192.168.3.x then you will also need to setup a nat exemption for the 192.168.1.x subnet.

Jon

Thank you very much.

Now I can ping between C3 and C2, but I can’t ping form C3 (192.168.1.2) to A2(192.168.3.1).

Just clarify - where is A2 ?

Jon

I circle A2 on the scheme )

This is probably just a security settings issue on A2, either not allowing pings or not allowing pings from the C3 subnet.