The topology is as follows
HQ LAN<-->HQ router<-->internet router<-->br router<-->br LAN
Configured as follows
Headquarters hq!
IP Access-list Extended S2S
Permit IP 192.168.11.0 0.0.0.255 192.168.12.0 0.0.0.255
!
!
Crypto ISAKMP Policy 10
ENCR 3DES
Hash MD5
Authentication Pre-share
Group 5
Crypto ISAKMP key Cisco address 202.202.202.1
!
!
Crypto IPSec Transform-set Mytran esp-3des Esp-md5-hmac
!
Crypto map MYMAP IPSEC-ISAKMP
Set Peer 202.202.202.1
Set Transform-set Mytran
Match Address S2s
Reverse-route Static
!
IP NAT inside source list NAT interface serial1/0 overload
!
IP Access-list Extended NAT
Deny IP 192.168.11.0 0.0.0.255 192.168.12.0 0.0.0.255
Permit IP 192.168.11.0 0.0.0.255 any
Branch BR
IP Access-list Extended S2S
Permit IP 192.168.12.0 0.0.0.255 192.168.11.0 0.0.0.255
!
!
Crypto ISAKMP Policy 10
ENCR 3DES
Hash MD5
Authentication Pre-share
Group 5
Crypto ISAKMP key Cisco address 101.101.101.1
!
!
Crypto IPSec Transform-set Mytran esp-3des Esp-md5-hmac
!
Crypto map MYMAP IPSEC-ISAKMP
Set Peer 101.101.101.1
Set Transform-set Mytran
Match Address S2s
Reverse-route Static
!
IP NAT inside source list NAT interface serial1/0 overload
!
IP Access-list Extended NAT
Deny IP 192.168.12.0 0.0.0.255 192.168.11.0 0.0.0.255
Permit IP 192.168.12.0 0.0.0.255 any
Site to site VPN