Solved

Site to Site VPN - Cisco ASA - Multiple Subnets at Main Location

Posted on 2016-09-19
6
66 Views
Last Modified: 2016-09-20
End Goal:  I need the Remote Office to communicate with the Main Office on the Security Camera Subnet too.

Current Situation:  The Site to Site is functional as I can route traffic from the Remote Office and Main Office on the Local Production LAN but nothing from the Remote Site can route traffic to the Security Camera Network.

Main Office Setup:
  • Cisco ASA 5515
  • Local Production LAN 10.5.1.0/24
  • Security Camera Network 10.10.15.0/24

Remote Office Setup:
  • Meraki MX 64
  • Local Production LAN 10.5.2.0/24

Please see attached ASA config and Network Diagram.  I have trimmed the config down but if it's missing something you need to see then please let me know.

Thank You
Config_ASA.txt
Simple_Network_Daigram.jpg
0
Comment
Question by:Wes Fields
  • 3
  • 2
6 Comments
 
LVL 28

Expert Comment

by:Jan Springer
Comment Utility
Without having yet read the configuration, there are typically four areas that need configuration for this to all work:

1) the subnets must be appropriately reachable from the destination device either by being directly connected or routed further downstream.

2) the "nonat" statements as both ends of the VPN need to include any subnets that are "interesting"

3) the access list applied to the crypto map needs to list these same interesting subnets.

4) the access list applied to the crypto map should be an exact inverse match of the other end.
1
 
LVL 3

Author Comment

by:Wes Fields
Comment Utility
I will be the first to admit that I am no well versed in ASA land.  I have just enough knowledge to do some basic setup, configuration, and troubleshooting but the issue has just went above my head.  It doesn't help that obviously this ASA was configured prior to me taking over the company.

I am definitely going to use this as a learning experience if we can get this resolved.
0
 
LVL 28

Expert Comment

by:Jan Springer
Comment Utility
That's no problem.  We all have different areas of expertise.

If you would be do a:

sh run crypto
sh run nat detail
sh access-list <acl of cryptomap to warehoue>

send it to my EE inbox.  we can work it out and i'll post an explanation of the fix without compromising network detail.
0
Threat Intelligence Starter Resources

Integrating threat intelligence can be challenging, and not all companies are ready. These resources can help you build awareness and prepare for defense.

 
LVL 57

Expert Comment

by:Pete Long
Comment Utility
I read this this morning, and its made me write this up..

Cisco ASA – Adding New Networks to Existing VPNs

Pete
0
 
LVL 28

Accepted Solution

by:
Jan Springer earned 500 total points
Comment Utility
We corrected a static NAT statement that referenced the proper nameif interface, inserted it in the proper order and permitted ICMP on that interface.
0
 
LVL 3

Author Closing Comment

by:Wes Fields
Comment Utility
Thank you for all the help!
0

Featured Post

Free Trending Threat Insights Every Day

Enhance your security with threat intelligence from the web. Get trending threat insights on hackers, exploits, and suspicious IP addresses delivered to your inbox with our free Cyber Daily.

Join & Write a Comment

#Citrix #Citrix Netscaler #HTTP Compression #Load Balance
Let’s list some of the technologies that enable smooth teleworking. 
After creating this article (http://www.experts-exchange.com/articles/23699/Setup-Mikrotik-routers-with-OSPF.html), I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…
After creating this article (http://www.experts-exchange.com/articles/23699/Setup-Mikrotik-routers-with-OSPF.html), I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…

771 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

12 Experts available now in Live!

Get 1:1 Help Now