We help IT Professionals succeed at work.

We've partnered with Certified Experts, Carl Webster and Richard Faulkner, to bring you two Citrix podcasts. Learn about 2020 trends and get answers to your biggest Citrix questions!Listen Now


Cisco ASA VPN Access Subnet Access Issue

Bob asked
Medium Priority
Last Modified: 2012-06-27
I have a network of several Cisco ASA's and would like to access them all using one vpn tunnel.  

I currently have the network setup where I can access most of the Hub ASA subnet, which is  and all the spoke ASA subnets such as and

However the line we are using to assign the VPNAccess ip is...
ip local pool VPNAccess mask
    which blocks out some of the ip's on the Hub network 20.

I changed the VPN Access to mask but then can't access the machines on the spokes.

I prefer to use the subnet for my VPNAccess but don't know how to setup the Hub and Spoke ASA's to accomplish this.

Thanks for the help
Watch Question

You will have to modify the hub and spoke VPNs to support your new subnet.

There should be a line on the crypto map that references the access-list.  You have to modify the access list on both ends of the VPN.


access-list VPN-Access extended permit ip w.x.y.z


access-list VPN-Access extended permit ip w.x.y.z

Where w.x.y.z is the spoke subnet.

Not the solution you were looking for? Getting a personalized solution is easy.

Ask the Experts


Ok   Finely able to do this but still no joy.

Do I need to make a route entry somewhere to let the spoke know that it needs to use the hub to access the 172 subnet?
Access more of Experts Exchange with a free account
Thanks for using Experts Exchange.

Create a free account to continue.

Limited access with a free account allows you to:

  • View three pieces of content (articles, solutions, posts, and videos)
  • Ask the experts questions (counted toward content limit)
  • Customize your dashboard and profile

*This site is protected by reCAPTCHA and the Google Privacy Policy and Terms of Service apply.


Please enter a first name

Please enter a last name

8+ characters (letters, numbers, and a symbol)

By clicking, you agree to the Terms of Use and Privacy Policy.