I have an hub and spoke configuration.
ASA5520 is the hub, zyxel are spokes.
Due to limitation on zyxel, I can only setup a single line remote network/local network.
the two branches must talk each other, and with a server on central site.
I wanted to perform the following.
1) zyxel 1 use local: 10.15.1.201/32 and remote 10.15.0.0/16
2) zyxel 2 use local: 10.15.2.201/32 and remote 10.15.0.0/16
3) ASA has local 10.15.0.0/24, but uses 10.15.0.0/16 when establishing tunnels.
host on spokes can communicate to hub, but they cannot ping each other.
output is a packet trace from spoke 1 to spoke1.
it seems summarization made bad things to VPN rerouting.
shall I make it work without creating multiple vpn sets?