2 sites Cisco routers terminating vpn on a linux firewall.
See configuration of 2 cisco router as well as linux firewall
.
!
!
HQ advertising 2 internal networks :

128.0.0.0/16
10.0.0.0/16

Remote site advertising 1 internal network :

128.0.0.0/16

Cisco HQ IPSEC VPN Config :

crypto isakmp policy 1
encr 3des
hash md5
authentication pre-share
group 2
crypto isakmp key ahdbpr0t3ct address 80.74.16.223
!
crypto ipsec transform-set secure esp-3des esp-md5-hmac
!
crypto map armadillo 1 ipsec-isakmp
set peer 80.74.16.223
set transform-set secure
match address 101
!
crypto map armadillo 2 ipsec-isakmp
set peer 80.74.16.223
set security-association lifetime seconds 28800
set security-association idle-time 86400
set transform-set secure
match address 102
!
access-list 101 permit ip 128.0.0.0 0.0.255.255 128.0.0.0 0.255.255.255
access-list 102 permit ip 10.0.0.0 0.0.255.255 128.10.0.0 0.0.255.255

!
interface FastEthernet0/0
description WAN-Interface
ip address 213.121.189.250 255.255.255.0
crypto map armadillo
!
interface vlan 1
description MLC vlan
ip address 128.0.15.250 255.255.0.0
!
interface vlan 2
description AHDB vlan
ip address 10.0.15.1 255.255.0.0
!
!
Cisco RemoteSite IPSEC VPN Config :

crypto isakmp policy 1
encr 3des
hash md5
authentication pre-share
group 2
crypto isakmp key ahdbpr0t3ct address 80.74.16.223
!
!
crypto ipsec transform-set secure esp-3des esp-md5-hmac
!
crypto map securewan 1 ipsec-isakmp
set peer 80.74.16.223
set security-association lifetime seconds 28800
set security-association idle-time 86400
set transform-set secure
match address VPN
!

ip access-list extended VPN
permit ip 128.10.0.0 0.0.255.255 128.0.0.0 0.0.255.255
permit ip 128.10.0.0 0.0.255.255 10.0.0.0 0.0.255.255

!
interface Dialer0
ip address 80.74.22.136 255.255.255.0
crypto map securewan
!
!

Linux Firewall Configuration :
Directory path of ipsec conf file ( /etc/ipsec/site name)
!
HQ Network : 128.0.0.0/16 & 10.0.0.0/16
!
128.0.0.0/16 to HQ 128.0.0.0/16
10.0.0.0/16 to HQ 128.0.0.0/16

conn HQ1
left=80.74.16.223
leftsubnet=128.0.0.0/16
right=213.121.189.250
rightsubnet=128.0.0.0/16
type=tunnel
authby=secret
auth=esp
esp=3des-md5-96
keyexchange=ike
ikelifetime=24h
keylife=28800s
keyingtries=3
pfs=no
rekey=yes
auto=start
dpdaction=restart
dpddelay=15
dpdtimeout=60
!
conn HQ2
left=80.74.16.223
leftsubnet=128.10.0.0/16
right=213.121.189.250
rightsubnet=10.0.0.0/16
type=tunnel
authby=secret
auth=esp
esp=3des-md5-96
keyexchange=ike
ikelifetime=24h
keylife=28800s
keyingtries=3
pfs=no
rekey=yes
auto=start
dpdaction=restart
dpddelay=15
dpdtimeout=60
!
!
RemoteSite Network : Access to HQ Network :
128.0.0.0/16 to HQ 128.0.0.0/16
128.0.0.0/16 to HQ 10.0.0.0/16

conn remotesite1
left=80.74.16.223
leftsubnet=128.0.0.0/16
right=80.74.22.136
rightsubnet=128.10.0.0/16
type=tunnel
authby=secret
auth=esp
esp=3des-md5-96
keyexchange=ike
ikelifetime=24h
keylife=28800s
keyingtries=3
pfs=no
rekey=no
auto=start
dpdaction=restart
dpddelay=15
dpdtimeout=60
!
conn remotesite2
left=80.74.16.223
leftsubnet=10.0.0.0/16
right=80.74.22.136
rightsubnet=128.10.0.0/16
type=tunnel
authby=secret
auth=esp
esp=3des-md5-96
keyexchange=ike
ikelifetime=24h
keylife=28800s
keyingtries=3
pfs=no
rekey=yes
auto=start
dpdaction=restart
dpddelay=15
dpdtimeout=60

Configure Linux Firewall Iptables to forward traffic from RemoteSite over to HQ.

sudo iptables -I FORWARD -s 128.0.0.0/16 -d 128.0.0.0/16 -j ACCEPT
sudo iptables -I FORWARD -s 128.0.0.0/16 -d 10.0.0.0/16 -j ACCEPT

Configure Linux Firewall Iptables to forward traffic from HQ to RemoteSite.

sudo iptables -I FORWARD -s 128.0.0.0/16 -d 128.0.0.0/16 -j ACCEPT
this one is configured in a previous rule as above.
!
sudo iptables -I FORWARD -s 10.0.0.0/16 -d 128.0.0.0/16 -j ACCEPT