10-05-2015 12:53 PM
I'm having a tough time getting a VPN Tunnel to work and I've built these before. But, this is a scenario I have not been in. I have two sites that are already connected with MPLS. We want to run a new subnet across the internet on a VPN tunnel for backing up servers. It's a new subnet on each side and the internet is already set up at each site as each sites primary internet. Is this possible. I'm attaching a drawing that hopefully will explain. If this is possible I'll dig into the config and ask more help.
Thank You!!!
10-05-2015 10:22 PM
setup the l2l tunnel with the new subnets in the crypto acl; you need to make sure that the traffic from that new subnet towards the remote subnet reaches the ASA; you can then add a route for the remote subnet pointing out through your outside interface so that it hits your crypto.
10-06-2015 04:06 AM
I have done that and a route back from the firewall and can ping each router from the asa at its own site but not the router on at the other end (I have enabled icmp in the firewalls). I must have something else mixed up them. I see tunnel built with crypto commands either. I'll try to post relevant parts of the config later today. Thank you for your response.
10-27-2015 04:58 AM
I finally got back to this. I couldn't find any mistakes in the programming at all. I have been trying to ping router to router on each side. Once I did a ping 192.168.1.1 source 192.168.2.1 (with the correct addresses of course) it recognized my source was correct and routed/tunneled appropriate.
So, the diagram I attached above does work no problem as pjain2 stated.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide