cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
281
Views
3
Helpful
9
Replies

Hub-and-Spoke Topology Question

Joel0748363
Level 1
Level 1

SDWAN.jpg

Hi All

I'm working on a SD-WAN Hub-and-Spoke Topology, but i want to avoid traffic flow between spoke to spoke, for example : the DC site using VPN 100, and the branch A using VPN 10, branch B using VPN 20, in this circumstances i need to route-leaking between 100-10、100-20, but now the routing table on VPN 100 will allow traffic from 10 forward to 20

Because of the default route advertise from the DC site, branch can easily route through anyway via VPN 100, because VPN 100 need to have every VPN's route in the fabric

Is there any way that i can prevent traffic between 10 and 20 without using SD-WAN ZBFW ?

thanks for answering 

2 Accepted Solutions

Accepted Solutions

since you receive default route toward hub then we can not prevent spoke to spoke traffic without ACL 
you need to use Local Data Policy in both Spoke 

https://www.networkacademy.io/ccie-enterprise/sdwan/explicit-access-control-list-acl

MHM

View solution in original post

Hi,

I don't know how many sites you have. But one option could be to list remote branches and in centralized data policy you select drop action.

There is no way to filter this without manually written access-list.

HTH,
Please rate and mark as an accepted solution if you have found any of the information provided useful.

View solution in original post

9 Replies 9

What I get you want to make traffic via Hub only ? Or something else 

MHM

Yes, even though i am using hub and spoke topology, but i need to avoid any traffic from spoke to spoke via Hub

since you receive default route toward hub then we can not prevent spoke to spoke traffic without ACL 
you need to use Local Data Policy in both Spoke 

https://www.networkacademy.io/ccie-enterprise/sdwan/explicit-access-control-list-acl

MHM

Torbjørn
Spotlight
Spotlight

You can solve this with a centralised policy that prevents spoke originated TLOC and OMP routes to be advertised to other spokes combined with a centralized data policy that restricts spoke-spoke traffic through the hub.

Happy to help! Please mark as helpful/solution if applicable.
Get in touch: https://torbjorn.dev

SDWAN.jpg

Yes I am using centralized policy to make sure there was no TLOC and Route exchange between spoke-spoke, but because of the default route that learn from the DC site, spoke-spoke can still communicate via DC 

hi sir 

Could you please explain specific which function to use in control policy ?

Joel0748363
Level 1
Level 1

Because of the default route advertise from the DC site, branch can easily route through anyway via VPN 100, because VPN 100 need to have every VPN's route in the fabric

Hi,

I don't know how many sites you have. But one option could be to list remote branches and in centralized data policy you select drop action.

There is no way to filter this without manually written access-list.

HTH,
Please rate and mark as an accepted solution if you have found any of the information provided useful.

Review Cisco Networking for a $25 gift card