I'd like a scenario as below:
LAN1 ---> ASA5505-50-BUN-K9 --- NAT/Firewall by ISP ---> ISP --> Internet ---> Public IP --> ASA5505-50-BUN-K9 --> LAN2
I'd like a site to site IPSec VPN but LAN1 will always initiate and will be always so that LAN2 can reach LAN1 always.
Why I want LAN1 VPN Gateway to always initiate is that LAN2 VPN Gateway will never see LAN1 VPN Gateway since it is behind an ISP NAT while LAN1 VPN Gateway can always reach out to LAN2 VPN Gateway.
Is this scenario going to be possible?