I find that Nating from one internal network to another is adds unnecissary complexity and extra processing for the ASA. What has worked well for me is if you remove all NAT statements. Add your dynamic NAT statement to get out to the internet through your outside interface. Then use Nat exempt statements so that your internal networks communicate directly. If your design is good and all your interal networks are in the same class (IE. 192.168.x.x) then you can do an easy blanket NAT exempt statement that would exempt 192.168.0.0 to 192.169.0.0, If not you may end up with 4 NAT exempt statements.
You then just need to make sure your VPN pool is NAT exempt to all you internal networks.
Hope this helps
Darkstriker
Main Topics
Browse All Topics





by: ikalmarPosted on 2009-09-29 at 03:21:31ID: 25447365
did you confiugured other address the VPN pools than 4 networks?