Site A: Astaro with Web Security and Network Security
- IPsec Connection Local networks: "Internal (Network)" and "Internet"
- Remote Gateway Remote networks: {Site B local network}
Site B: Astaro with only Network Security
- IPsec Connection Local networks: "Internal (Network)"
- Remote Gateway Remote networks: "Internet" and {Site A local network}
In Web Security in Site A, 'Allowed networks' includes "Internal (Network)" and {Site B local network}. If the proxy is in a Transparent mode, then the FTP Proxy also should allow {Site B local network} and a packet filter rule is necessary to allow {Site B local network} access to web surfing services outside of those handled by the two proxies.
I don't know the commands for Cisco, but the trick, if there's already a VPN Connection, is to add "Internet" and {Site A/B local network} in the right places on both sides.