07-04-2017 02:03 AM - edited 02-21-2020 09:21 PM
I have ISR4331 at one end and three ASA at three different site which is connected via IPSEC VPN. I facing one way traffic at all the three sites. Let be define the topology as best as I can.
3750switch <--------> ISR4331 <-----> ISP cloud <----->ASA<------->3750switch
Thing is I can reach or ping to all the subnet at the ASA side but i could reach only upto the gateway(internal) on the ISR side. By the by the gateway is the IP address of the sub interface configured on the ISR.
I am not sure whether it is routing issue or IPSEC tunnel issue. Would like you have suggestions from Cisco. I have attached the running configuration of ISR, ASA and 3750switch at ISR side.
07-04-2017 02:33 AM
I don't see inside-self zone configured. Also, check your natting to make sure that your traffic to remotes isn't getting natted.
07-04-2017 02:46 AM
Thank you for checking this issue. Can you provide me some idea or command to check on the above things. I am not expert on this.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide