Hondabuff wrote: » Did you try "ip route 0.0.0.0 0.0.0.0 tunnel 0"
eten wrote: » The subnets are defined by your crypto ACL. If your destination IP at your branch location is "any", then it should encrypt all traffic towards your HQ. Did you remove the NAT statements at your branch ASA? Post your configs or enable some logging so you can see what is happening.