We use a site-to-site vpn from A (DMZ, 10.10.10.0/24) to B (172.20.20.0/24) and it works fine. Now a SAP-Server (B) have to send the printjobs to Printserver (10.20.20.1) behind network A. So I have configured:
static (inside,dmz) 10.10.10.1 10.20.20.1 netmask 255.255.255.255
conduit permit tcp host 10.10.10.1 eq 515 172.20.20.1 (SAP-Server)
If I do a telnet for 10.10.10.1 with tcp/515 I get a time out an cant see any packets in debug mode. If I do ping I can see the packets. No ports are closed for the tunnel.
Now I cancel the static and conduit command and configure for test a printer directly with 10.10.10.1 and it works properly.
What?s going wrong with the static?