Site-to-site VPN with 3 sites

Unanswered Question
Mar 13th, 2008
User Badges:

I have 3 sites. On each site there is a ASA5505 resp. 5510.

I have a working ipsec tunnel between site A and B, and between B and C. What I am looking for is a way to pass traffic between A and C without creating an own tunnel between A and C. So somehow a way that the ASA on site B routes the traffic from tunnel site A to the tunnel site C.

Is that possible?

Any hints are very welcome.


  • 1
  • 2
  • 3
  • 4
  • 5
Overall Rating: 0 (0 ratings)
acomiskey Thu, 03/13/2008 - 09:30
User Badges:
  • Green, 3000 points or more

Yes, this is possible.

Here is a doc describing how to do it with remote access vpn to site to site. You can do it the same way with site to site instead of remote access.

Basically you just need to add the interesting traffic to the tunnels, add the extra nat exemption to the tunnels, and apply same-security-traffic permit intra-interface to site B.

Post up some configs if you need help.


This Discussion