Hq mx is in routed mode? You have a simple network drawing? Not sure if your hq is behind asa,coreswitch or both.. On the hq mx you create a route for 172.30.x.x to the next hop (ip of the coreswitch 10.32.0.??? ) , and you select advertise this route in vpn. The coreswitch knows the way(routing table) to 172.30.x.x and 10.32.18.x ?
... View more