Dear Support Community,
as i'm looking through the config guides about 870 series router, i only find information about config with eazy vpn.
is there a classic way on configuring 870 series IPSec site-2-site without eazy vpn?
Having a classic way if a tunnel? Having the 870 not acting as a vpn-client?
Base on the "show cry ipsec sa" output, the traffic is being sent from the router towards the ASA, and ASA decrypts the traffic, however, I did not see that the traffic is being encrypted on the ASA end, hence there is no decrypt on the router.
You might want to check the NAT exemption configuration on othe ASA, and also if the internal subnet of the ASA knows to route the router subnet of 192.168.1.0/24 towards the ASA.
The crypto configuration looks correct.
I saw that there is ACL 101 applied to vlan 1 however didn't see the actual ACL on the configuration. You might want to remove that.
Can you pls run debug and share the output:
debug cry isa
debug cry ipsec
Sure, here is sample configuration for Site-to-Site VPN for your reference:
Hope that helps.