Cisco ASA VPN Access Subnet Access Issue
Posted on 2009-02-17
I have a network of several Cisco ASA's and would like to access them all using one vpn tunnel.
I currently have the network setup where I can access most of the Hub ASA subnet, which is 192.168.20.0 255.255.255.0 and all the spoke ASA subnets such as 192.168.25.0 255.255.255.0 and 192.168.30.0 255.255.255.0
However the line we are using to assign the VPNAccess ip is...
ip local pool VPNAccess 192.168.20.230-192.168.20.235 mask 255.255.255.248
which blocks out some of the ip's on the Hub network 20.
I changed the VPN Access to 172.16.20.0-172.16.20.100 mask 255.255.255.0 but then can't access the machines on the spokes.
I prefer to use the 172.16.20.0 subnet for my VPNAccess but don't know how to setup the Hub and Spoke ASA's to accomplish this.
Thanks for the help