I have a customer who wants to connect 4 locations with IPSEC tunnels in a full mesh using ASA 5505's. The catch is that hosts in locations A, B and C are trusted but location D is a partner location so the hosts are not fully trusted. The customer would like hosts in A, B, or C to be able to initiate connections to any host in location D but not allow hosts in location D to initiate connections to anyone in locations A, B or C.
These are all small sites so the ASAs will be the only devices available.
Does anyone have suggestions how I can accomplish this?