Friday, October 11, 2019

Cisco IPSec tunnel with additional routes

I have very strange senario not sure its possible or not. we have public cloud and i am trying to create IPsec tunnel between my office to cloud VPC and from cloud VPC to other region VPC, let me explain in diagram.

This is ALI Cloud and trying to configure CEN (Cloud Enterprise Network) https://www.youtube.com/watch?v=I00gSpL8JKs

[VPC-A]-----------cloud-vpc-peering------------[VPC-B]--------------IPsec--tunnel------[Office]

I can ping from my office to VPC-B IP subnets (vms)

I can ping from VPC-B to VPC-A IP subnests (vms)

But i want to ping from office to direct VPC-A subnet which is not working, I have tried to add VPC-A IP subnet in Cisco ASA (office) IPsec tunnel as interesting traffic but how do i tell Cisco that route VPC-A subnet from VPC-B IPsec tunnel ?

is this possible or i am trying something which is not possible?



No comments:

Post a Comment