Traffic from one VPN tunnel to another

Unanswered Question
Jul 8th, 2008
User Badges:

Hi - not sure how to do this so I hope you can help. I have a number of servers in a disaster recovery site that is at the other ond of a L2L VPN tunnel. Now on this end, I have users who VPN in to the ASA. The users can get everywhere except to the machines on the other end of the L2L tunnel. Let me know if you have any ideas. How can I route or allow traffic from users coming in on a remote access vpn tunnel to a server at the far end of an L2L tunnel? I can post a config if needed. Thanks!

  • 1
  • 2
  • 3
  • 4
  • 5
Overall Rating: 5 (1 ratings)
adcorbett_2 Tue, 08/05/2008 - 06:52
User Badges:

Had to step away from this to deal with some other stuff, but now I am back. Ok, so I added that command but still cannot get to the DR site. Let me try to explain our setup. In the coporate HQ, we have an ASA 5520 (ASA - 1). Inside address There is a L2L tunnel to an ASA 5520 in another state (ASA - 2) - inside address of that one I have VPN user connect to ASA-1 and they get an address of 192.168.200.X. I need them to to be able to get to the servers behind ASA - 2 (192.168.100.X). The VPN users can get to everything else on our network (, but not the subnet.

acomiskey Tue, 08/05/2008 - 06:59
User Badges:
  • Green, 3000 points or more

You need to add the interesting traffic to ASA 1.

access-list extended permit ip

..and ASA 2.

access-list extended permit ip

Also, nat exemption for ASA 2.

access-list extended permit ip

Also, be sure if you are split tunneling the vpn clients, that the 192.168.100 network is being tunneled.


This Discussion