I have a couple of ios routers 1841 series as the spokes and a central hub using a ASA5520 box. The Lan to Lan VPN has no problem communicating with sub nets behind the ASA box to the spokes A & spoke B.
Problem occurs with inter spoke communication, spoke A can't ping spoke B and vice versa. I am now using GRE tunnels for inter spoke communication.I know this is not a good way to do this if the L2L VPN has to scale up in size.Is there better way like using DMPVPN or some way to turn on the some feature on the ASA box? (Tried using the command same-security-traffic permit intra-interface on the ASA but did not work).Can any experts here advise further?
Spoke to Spoke via the ASA Hub is possible. And looks like you were going down the right path by configuring "same-security-traffic permit intra-interface". Did you get a chance to look at the below URL and configure the Crypto and NONAT ACLs to include the remote subnets. Also, did you make the necessary changes on the spoke side to reflect the new set up.
*Pls rate if it helps*