cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
820
Views
0
Helpful
2
Replies

One way traffic over IPSEC VPN

usucsupport
Level 1
Level 1

I have ISR4331 at one end and three ASA at three different site which is connected via IPSEC VPN. I facing one way traffic at all the three sites. Let be define the topology as best as I can.

3750switch <--------> ISR4331 <-----> ISP cloud <----->ASA<------->3750switch

Thing is I can reach or ping to all the subnet at the ASA side but i could reach only upto the gateway(internal) on the ISR side. By the by the gateway is the IP address of the sub interface configured on the ISR.

I am not sure whether it is routing issue or IPSEC tunnel issue. Would like you have suggestions from Cisco. I have attached the running configuration of ISR, ASA and 3750switch at ISR side.

2 Replies 2

I don't see inside-self zone configured. Also, check your natting to make sure that your traffic to remotes isn't getting natted. 

Thank you for checking this issue. Can you provide me some idea or command to check on the above things. I am not expert on this.