Okay guys, here's the situation:
I have three sites (sites A, B, and C). There is a site-to-site IPsec tunnel between PIXs from an internal LAN on site A (172.30.10.0 /24) to an internal LAN on site B (192.168.20.0 /24), and another tunnel from site B to site C (172.30.20.0). How can I route traffic from site A to C across the existing tunnels without creating another tunnel between sites A and C? Many thanks in advance.
What you want to do is called hairpinning or u-turn VPN.
Here's a technical tip on cisco.com that goes over the configuration details:
PIX/ASA 7.x Enhanced Spoke-to-Spoke VPN Configuration Example
The key command is "same-security-traffic permit intra-interface" on the PIX on site B.
Hope this helps.