Thursday, November 14, 2019

Having a three site p2p VPN but with only 2 IPSEC tunnels?

I was sure this was possible but I'm struggling to get it working.

I have a ipsec VPN from an ASA (in my control) to a third party (out of my control). I've connected another site via a new IPSEC VPN to the ASA. What I want to happen is for this third site to connect to the ASA via the IPSEC VPN and then be able to send traffic across the original IPSEC to the third party.

I've enabled same traffic intra & inter interfaces and made sure the subnets are encompassed in the original VPN but I cannot get traffic to come into the ASA via the IPSEC VPN and then hop over the original.

Is it just a case where I'm mistaking and this isn't possible? I know I can do it via a client based VPN fine.

Thanks



No comments:

Post a Comment