First off - awesome graphic. That is exactly how the network is set up - thanks so much for taking the time to help.
- Why are the WAN-facing interfaces in different subnets (10.1.2.0/30, 10.1.2.4/30, 10.1.2.8/30)?
To be honest, I don't know. I can say that each site has its own subnet.
So Sites A, B and C each have one address for the Network, the VPN hub, the Router, and Broadcast. Why they aren't all on the same network... not sure. They shouldn't have to be, correct?
- The router at Site C has interfaces with /30 subnets (10.1.1.0/30, 10.1.2.0/30). Does that mean the network behind the ASA firewall is another completely different network?
This is to separate my servers and equipment from the remote sites. Not a completely different network, just a way to separate things (ie: I should have 1 address for Network, Router, ASA, Broadcast)
-GP