We currently have two locations that are interconnected via a private connection. They are both connected using L3 switches. Site1 currently has an Internet feed off an ASA 5520 but that Internet feed is going away and all traffic will be routed over the private connection to Site2. I am trying to migrate all connections to Site2 which also has an ASA 5520. Currently both sites can get to and from the Internet and each other fine. If I VPN into Site1 I can access Site2, but if I VPN into Site2 I can not get to anything on Site1, just Site2 servers and the Internet. Also Site1 cannot ping/traceroute to the VPN'd PC. I also have a NAT'd device that sits on Site1's L2 network (no Site1 ASA involved) that can not be accessed via the Internet, the Site2 ASA logs show a timeout after 30 seconds.
L3 Link: 172.16.99.1
Route: 172.16.0.0/16 172.16.99.2
0.0.0.0 Site1 ASA's internal IP
Route: 192.168.0.0/16 172.16.99.1
Route: 0.0.0.0 External IP
Any suggestions on where to look would be appreciated.
Getting on a device in the 192.168.x.x subnet and do a traceroute to the VPN assigned IP address. This would help to confirm that it atleast reaches the L3 switch between the ASAs. You could also perform a packet capture on all of your ASAs using specfic access-lists to figure out if the packets reaching the ASA.