Dynamic IPSEC :

object-group network Eyre_Remote_Private_nonat
network-object 192.168.3.0 255.255.255.0
!
object-group network Eyre_HQ_Private_nonat
network-object 172.16.0.0 255.255.0.0
!
!
nat (DC_LAN,PUBLIC) source static Eyre_HQ_Private_nonat Eyre_HQ_Private_nonat destination static Eyre_Remote_Private_nonat Eyre_Remote_Private_nonat
!
!
crypto ipsec security-association lifetime seconds 86400
crypto ipsec security-association lifetime kilobytes 9908000
!
crypto dynamic-map draytech_map 5 set ikev1 transform-set ESP-3DES-MD5
crypto dynamic-map draytech_map 5 set reverse-route
!
crypto map Public_map 10 ipsec-isakmp dynamic draytech_map
!
crypto map Public_map interface outside
!
crypto isakmp identity address
crypto isakmp nat-traversal 10
crypto ikev1 enable outside
sysopt connection permit-ipsec
!
crypto ikev1 policy 1
authentication pre-share
encryption 3des
hash md5
group 2
lifetime 86400
!
tunnel-group DefaultL2LGroup type ipsec-l2l
tunnel-group DefaultL2LGroup ipsec-attributes
ikev1 pre-shared-key PASSWORD
isakmp keepalive threshold 20 retry 5

 

If all traffic is to be pushed down the tunnel from remote site, we need to make sure both ends
Access-list policies match :

eg :

ASA 5520 V8.3 :

name 10.171.53.0 ee053
! 
object-group network Remote_Private_Range
description Remote Summarisation of Private IP Address
network-object ee053 255.255.255.0
!
object network Eyre_HQ_Private_nonat
description HQ site private range
subnet 0.0.0.0 0.0.0.0
!
access-list Colo_cryptomap_5 extended permit ip any object-group Remote_Private_Range
!
!
nat (DC_LAN,PUBLIC) source static Eyre_HQ_Private_nonat Eyre_HQ_Private_nonat destination static Eyre_Remote_Private_nonat Eyre_Remote_Private_nonat
!
nat (PUBLIC,DC_LAN) source static Eyre_Remote_Private_nonat Eyre_Remote_Private_nonat destination static Eyre_HQ_Private_nonat Eyre_HQ_Private_nonat
!
crypto dynamic-map draytech_map 5 match address Colo_cryptomap_5


Remote Site Cisco :

ip access-list extended VPN
permit ip 10.171.53.0 0.0.0.255 any