cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
246
Views
0
Helpful
4
Replies

ada5500 vpn same interface

whanson
Level 2
Level 2

I have gotten this working for clients who are vpned in and then are able to access sites in which the ASA has a site to site tunnel. Can this also be done between site to site tunnels? I can't seem to get it work. ASA A has a site to site with ASA B and ASA C. I want users at ASA C to access ASA B without making a separate tunnel between ASA B and ASA C by having the traffic come from ASA B to ASA A and then have it go out the same interface toward ASA C. Sifficently, complicated?

Thx

4 Replies 4

Jon Marshall
Hall of Fame
Hall of Fame

Hi

Yes it can be done on an ASA device.

You will need to add the command "same-security-traffic permit intra-interface". You then need to make sure that traffic coming out of tunnel from site B is defined as intersting traffic in the IPSEC crypto map for site C and vice-versa.

HTH

Jon

Hi,

Please find attached a configuration example:

http://cisco.com/en/US/products/hw/vpndevc/ps2030/products_configuration_example09186a00804675ac.shtml

Please rate if this helped.

Regards,

Daniel

Daniel,

Thx much. Problem turned out to be at site C which was a Watchguard. It is now working.

Bill

Thanks Jon,

The problem turned out to be at Site C which was Watchguard. Got it working.

Getting Started

Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community: