Cisco Support Community
Showing results for 
Search instead for 
Did you mean: 

Welcome to Cisco Support Community. We would love to have your feedback.

For an introduction to the new site, click here. And see here for current known issues.

New Member

IPsec site2site routing problem


How does the ASA firewall ACL permiting traffic for two cisco 1811 site to site IPSEC? Site A and B connected through IPSec. Site A has a ASA firewall and this firewall only use to connect to an outsource application. If I need to permit acl_nonat , do I permitting public or private address of site B? Our problem is we use MPLS then everything works fine but after we switched to IPSec site to site then it broke. I am able to access everything on IPSEC site to site but except this outsource application.

New Member

Re: IPsec site2site routing problem

If I understand correctly, you are trying to get to site A from Site B and vice versa? If your spoke are all ASA, you might want to look at how it is possible from

especially on the section of Hairpinning or U-turn which you need to execute a special command at the hub.

I have similar problem, to get pass this problem, a GRE tunnel was constructed bt site A & B. So intersite traffic between A & B go via this tunnel instead of via the hub. Of course this is just one of the way to do this.

CreatePlease login to create content