Remote VPN access over Site to Site IPSEC tunnel on same device

We are replacing our PIX and VPN Concentrator with an ASA5520.
Currently our PIX firewall has IPSEC VPN tunnels to remote offices and the VPN concentrator is used for remote client access.
The way the traffic is routed, if a remote user VPN's into the concentrator, they can access the remote offices over the Site to Site VPN tunnels through the PIX.
The solution I'm looking to do is to create the same scenario, but only using the single ASA 5520.
I know that as a remote user, you cannot VPN into the outside interface of the ASA and then go back out the same interface to the remote offices over the site to site tunnels.
Is there a way to do this with just the once device?
I thought that maybe I could assign a second outside interface on the ASA and have the remote users VPN to that interface, then the site the site tunnels would be built on a second outside interface.  Then the remote users could go into one outside interface and get routed out the 2nd interface with the Site to Site tunnels to reach the remote offices.  
Problem is when I attempted to assign a second outside interface an IP address from the /28 block given to us by our ISP, it didn't work because the IP's overlapped.
Any ideas?
ingersoeAsked:
Who is Participating?
 
SaineolaiCommented:
On an ASA it is possible to allow traffic to enter and exit the same interface, allowing the scenario you are looking for.  The command to enable that is:

same-security-traffic permit intra-interface

Have a look at this Cisco document,
http://www.cisco.com/en/US/products/ps6120/products_tech_note09186a0080734db7.shtml
0
 
ingersoeAuthor Commented:
Thanks for the quick response.  That looks like it'll work.  Guess I need to ready up on the new features of the 7 and 8 code.
0
Question has a verified solution.

Are you are experiencing a similar issue? Get a personalized answer when you ask a related question.

Have a better answer? Share it in a comment.

All Courses

From novice to tech pro — start learning today.