Solved

Site to Site VPN - Cisco ASA - Multiple Subnets at Main Location

Posted on 2016-09-19
6
76 Views
Last Modified: 2016-09-20
End Goal:  I need the Remote Office to communicate with the Main Office on the Security Camera Subnet too.

Current Situation:  The Site to Site is functional as I can route traffic from the Remote Office and Main Office on the Local Production LAN but nothing from the Remote Site can route traffic to the Security Camera Network.

Main Office Setup:
  • Cisco ASA 5515
  • Local Production LAN 10.5.1.0/24
  • Security Camera Network 10.10.15.0/24

Remote Office Setup:
  • Meraki MX 64
  • Local Production LAN 10.5.2.0/24

Please see attached ASA config and Network Diagram.  I have trimmed the config down but if it's missing something you need to see then please let me know.

Thank You
Config_ASA.txt
Simple_Network_Daigram.jpg
0
Comment
Question by:Wes Fields
  • 3
  • 2
6 Comments
 
LVL 28

Expert Comment

by:Jan Springer
ID: 41805477
Without having yet read the configuration, there are typically four areas that need configuration for this to all work:

1) the subnets must be appropriately reachable from the destination device either by being directly connected or routed further downstream.

2) the "nonat" statements as both ends of the VPN need to include any subnets that are "interesting"

3) the access list applied to the crypto map needs to list these same interesting subnets.

4) the access list applied to the crypto map should be an exact inverse match of the other end.
1
 
LVL 3

Author Comment

by:Wes Fields
ID: 41805484
I will be the first to admit that I am no well versed in ASA land.  I have just enough knowledge to do some basic setup, configuration, and troubleshooting but the issue has just went above my head.  It doesn't help that obviously this ASA was configured prior to me taking over the company.

I am definitely going to use this as a learning experience if we can get this resolved.
0
 
LVL 28

Expert Comment

by:Jan Springer
ID: 41805511
That's no problem.  We all have different areas of expertise.

If you would be do a:

sh run crypto
sh run nat detail
sh access-list <acl of cryptomap to warehoue>

send it to my EE inbox.  we can work it out and i'll post an explanation of the fix without compromising network detail.
0
Zoho SalesIQ

Hassle-free live chat software re-imagined for business growth. 2 users, always free.

 
LVL 57

Expert Comment

by:Pete Long
ID: 41806443
I read this this morning, and its made me write this up..

Cisco ASA – Adding New Networks to Existing VPNs

Pete
0
 
LVL 28

Accepted Solution

by:
Jan Springer earned 500 total points
ID: 41807085
We corrected a static NAT statement that referenced the proper nameif interface, inserted it in the proper order and permitted ICMP on that interface.
0
 
LVL 3

Author Closing Comment

by:Wes Fields
ID: 41807174
Thank you for all the help!
0

Featured Post

PRTG Network Monitor: Intuitive Network Monitoring

Network Monitoring is essential to ensure that computer systems and network devices are running. Use PRTG to monitor LANs, servers, websites, applications and devices, bandwidth, virtual environments, remote systems, IoT, and many more. PRTG is easy to set up & use.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Suggested Solutions

Let’s list some of the technologies that enable smooth teleworking. 
I recently attended Cisco Live! in Las Vegas, a conference that boasted over 28,000 techies in attendance, and a week of hands-on learning hosted by a solid partner with which Concerto goes to market.  Every year, Cisco displays cutting-edge technol…
After creating this article (http://www.experts-exchange.com/articles/23699/Setup-Mikrotik-routers-with-OSPF.html), I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…
After creating this article (http://www.experts-exchange.com/articles/23699/Setup-Mikrotik-routers-with-OSPF.html), I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…

937 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

10 Experts available now in Live!

Get 1:1 Help Now