вот выводы команд
PIX515E-hub# show cry isa sa Active SA: 2
Rekey SA: 0 (A tunnel will report 1 Active and 1 Rekey SA during rekey)
Total IKE SA: 2
1 IKE Peer: 172.16.110.179
Type : L2L Role : responder
Rekey : no State : MM_ACTIVE
2 IKE Peer: 172.16.110.81
Type : L2L Role : initiator
Rekey : no State : MM_ACTIVE
PIX515E-hub#
PIX515E-hub# show cry ipsec sa
interface: outside
Crypto map tag: mymap, local addr: 172.16.110.7
local ident (addr/mask/prot/port): (192.168.200.0/255.255.255.0/0/0)
remote ident (addr/mask/prot/port): (192.168.201.0/255.255.255.0/0/0)
current_peer: 172.16.110.81
Crypto map tag: mymap, local addr: 172.16.110.7
local ident (addr/mask/prot/port): (192.168.202.0/255.255.255.0/0/0)
remote ident (addr/mask/prot/port): (192.168.201.0/255.255.255.0/0/0)
current_peer: 172.16.110.81
Crypto map tag: mymap, local addr: 172.16.110.7
local ident (addr/mask/prot/port): (192.168.200.0/255.255.255.0/0/0)
remote ident (addr/mask/prot/port): (192.168.202.0/255.255.255.0/0/0)
current_peer: 172.16.110.179
Crypto map tag: mymap, local addr: 172.16.110.7
local ident (addr/mask/prot/port): (192.168.201.0/255.255.255.0/0/0)
remote ident (addr/mask/prot/port): (192.168.202.0/255.255.255.0/0/0)
current_peer: 172.16.110.179
PIX515E-hub#
не знаю с чем это связано но пинги со стороны АSA (т.е. с 3750) доходят до роутера и он на них отвечает, но далее они видно уходят в никуда....