Pulling my hair out here over something that should have been massively simple. Needed to two new subnets, one per site, to our network. Traffic from these subnets should be allowed over the site-to-site tunnel.
I created the new subnets locally (on 3750-X switching, just for clarity), then created the relevant network objects on the ASAs and added those network objects to the network object groups that correspond to both ends of the (already existing) tunnel. Simplified, the network topology is like this:
3750X Switching (L3 Routing enabled) <---> ASA 5512X <---> WAN <---> ASA 5510 <---> 3750G Switching (L3 Routing enabled).
Now, traffic was already flowing for the previously existing subnets (SERVERS, CLIENT, WIFI), and these subnets are either part of a network object group called VPN_NET_LOCAL or VPN_NET_REMOTE depending on which end of the tunnel they are. The new subnets were added to these groups in theory resulting in no further configuration required (as the No-NAT rules, access rules, crypto maps, etc were all referencing the group objects).
Yet here I am, with traffic to Site B's new subnet from Site A being completely unreachable, yet traffic to Site A's new subnet from Site B's old subnets is fine
Halp plz.
I created the new subnets locally (on 3750-X switching, just for clarity), then created the relevant network objects on the ASAs and added those network objects to the network object groups that correspond to both ends of the (already existing) tunnel. Simplified, the network topology is like this:
3750X Switching (L3 Routing enabled) <---> ASA 5512X <---> WAN <---> ASA 5510 <---> 3750G Switching (L3 Routing enabled).
Now, traffic was already flowing for the previously existing subnets (SERVERS, CLIENT, WIFI), and these subnets are either part of a network object group called VPN_NET_LOCAL or VPN_NET_REMOTE depending on which end of the tunnel they are. The new subnets were added to these groups in theory resulting in no further configuration required (as the No-NAT rules, access rules, crypto maps, etc were all referencing the group objects).
Yet here I am, with traffic to Site B's new subnet from Site A being completely unreachable, yet traffic to Site A's new subnet from Site B's old subnets is fine

Halp plz.