have 2 sites, connected via ipsec tunnel with 2821's on each end. the main site has several vlans as does the other side. One particular vlan (32) 10.15.32.x can't see 10.15.250.x (250) vlan on the other side of the tunnel, all the other vlans at the same site of the 32 vlan can see that network no problem. I see the acl for that vlan that includes the 32 vlan and the other side has the return as well. This was working before swapping the vlan gateway from the 2821 to a 4900 and left the 2821 as vpn enpoint and internet gateway. I don't think I'm missing anything, but i've been staring at it too long. Hopefully you guys can see. basically if i tracert to that 10.15.250.x address from the machine on the 10.15.32.x network it dies at the internet gateway 192.168.253.25 which is the also the default route for the 4900. I am attaching the configs. I appreciate any help.