The tech. document does not completely reflect my scenario. Indeed, I need conc-to-conc connection not router-to-conc.
I think this is the real point. The concentrator at HQ cannot be configured to accept LAN-to-LAN from *any* in the list of peers. Anf this is required due to the dynamic IP address at the branch office.
Table of ContentsIntroductionVersion HistoryPossible Future
UpdatesDocuments PurposeNAT Operation in ASA 8.3+ SectionsRule Types
Network Object NATTwice NAT / Manual NATRule Types used per SectionNAT
Types used with Twice NAT / Manual NAT and Network Obje...
[toc:faq]Introduction:This document describes details on how NAT-T
works.Background:ESP encrypts all critical information, encapsulating
the entire inner TCP/UDP datagram within an ESP header. ESP is an IP
protocol in the same sense that TCP and UDP are I...