Solved

Site to Site VPN - Cisco ASA - Multiple Subnets at Main Location

Posted on 2016-09-19
6
102 Views
Last Modified: 2016-09-20
End Goal:  I need the Remote Office to communicate with the Main Office on the Security Camera Subnet too.

Current Situation:  The Site to Site is functional as I can route traffic from the Remote Office and Main Office on the Local Production LAN but nothing from the Remote Site can route traffic to the Security Camera Network.

Main Office Setup:
  • Cisco ASA 5515
  • Local Production LAN 10.5.1.0/24
  • Security Camera Network 10.10.15.0/24

Remote Office Setup:
  • Meraki MX 64
  • Local Production LAN 10.5.2.0/24

Please see attached ASA config and Network Diagram.  I have trimmed the config down but if it's missing something you need to see then please let me know.

Thank You
Config_ASA.txt
Simple_Network_Daigram.jpg
0
Comment
Question by:Wes Fields
  • 3
  • 2
6 Comments
 
LVL 28

Expert Comment

by:Jan Springer
ID: 41805477
Without having yet read the configuration, there are typically four areas that need configuration for this to all work:

1) the subnets must be appropriately reachable from the destination device either by being directly connected or routed further downstream.

2) the "nonat" statements as both ends of the VPN need to include any subnets that are "interesting"

3) the access list applied to the crypto map needs to list these same interesting subnets.

4) the access list applied to the crypto map should be an exact inverse match of the other end.
1
 
LVL 3

Author Comment

by:Wes Fields
ID: 41805484
I will be the first to admit that I am no well versed in ASA land.  I have just enough knowledge to do some basic setup, configuration, and troubleshooting but the issue has just went above my head.  It doesn't help that obviously this ASA was configured prior to me taking over the company.

I am definitely going to use this as a learning experience if we can get this resolved.
0
 
LVL 28

Expert Comment

by:Jan Springer
ID: 41805511
That's no problem.  We all have different areas of expertise.

If you would be do a:

sh run crypto
sh run nat detail
sh access-list <acl of cryptomap to warehoue>

send it to my EE inbox.  we can work it out and i'll post an explanation of the fix without compromising network detail.
0
Connect further...control easier

With the ATEN CE624, you can now enjoy a high-quality visual experience powered by HDBaseT technology and the convenience of a single Cat6 cable to transmit uncompressed video with zero latency and multi-streaming for dual-view applications where remote access is required.

 
LVL 57

Expert Comment

by:Pete Long
ID: 41806443
I read this this morning, and its made me write this up..

Cisco ASA – Adding New Networks to Existing VPNs

Pete
0
 
LVL 28

Accepted Solution

by:
Jan Springer earned 500 total points
ID: 41807085
We corrected a static NAT statement that referenced the proper nameif interface, inserted it in the proper order and permitted ICMP on that interface.
0
 
LVL 3

Author Closing Comment

by:Wes Fields
ID: 41807174
Thank you for all the help!
0

Featured Post

Free learning courses: Active Directory Deep Dive

Get a firm grasp on your IT environment when you learn Active Directory best practices with Veeam! Watch all, or choose any amount, of this three-part webinar series to improve your skills. From the basics to virtualization and backup, we got you covered.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Suggested Solutions

Title # Comments Views Activity
Cisco Trunk question 4 30
BGP recommended setup with failover 2 46
domian network access 5 20
Grant drive/folder change permissions to VPN user 6 13
If you use NetMotion Mobility on your PC and plan to upgrade to Windows 10, it may not work unless you take these steps.
Use of TCL script on Cisco devices:  - create file and merge it with running configuration to apply configuration changes
After creating this article (http://www.experts-exchange.com/articles/23699/Setup-Mikrotik-routers-with-OSPF.html), I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…
As a trusted technology advisor to your customers you are likely getting the daily question of, ‘should I put this in the cloud?’ As customer demands for cloud services increases, companies will see a shift from traditional buying patterns to new…

856 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question