cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
789
Views
0
Helpful
6
Replies

Site to site VPN - Spoke Internet access through Hub site

gizbri
Level 1
Level 1

I established a site to site VPN between Hub (5520) and spoke (5505), now I want the user in the spoke site to access the Internet through the 5520. On the 5505 I have the crypto map set for inside traffic to any and on the 5520 added a nat statement for the 5505 subnet for the outside..... what am i missing ??

6 Replies 6

rahgovin
Level 4
Level 4

same-security permit intra interface. Coz traffic is entering and exiting on the same interface.

no, sorry I left that out. The VPN tunnel is established through a WAN connection, like this:

5505 ------ > WAN -------- 5520 ----------- Internet

What are the nat configs on the hub ASA?Could you post them here. Can you see a nat translation for hosts behind the 5505?

file attached -

Is the crypto acl on the 5520 from any to 5505 subnet? What does the show cry ips sa show on both devices? equal encaps and decaps.

And post the 5520 config if possible. Also check for logs on 5520.

Attached is the 5520 - I inherited this a week or so ago .... There are 2 other site to site vpn networks (10.65.37.0 and 10.65.36.0) that access the Internet from the 5520. I am having a bit of difficulty understand the rules that allow this , could you explain ?

Thanks

Brian

Getting Started

Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community: