cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
791
Views
0
Helpful
3
Replies

DMVPN control traffic between spokes

neroshake
Level 1
Level 1

Hello All,

 

I am having a small network of HQ and branches implemented using DMVPN and everything works fine. The hub is a default gateway for all branches and all traffic going from brunch first reaches the Hub. The problem is that I want to know the best way to control traffic flow between spokes. For example I want to allow only voip traffic between spokes everything else between spokes should be blocked. Anything else is being already inspected by ASA to which HUB is connected and that ASA controls traffic from other zones (DMZ, SERVERS, etc). Which is the preferred way to implement this? Will outgoing ACL on tunnel interface on HUB work?

 

 

3 Replies 3

neroshake
Level 1
Level 1
Any idea ?

Easiest is to go for Phase-I DMVPN to make it hub and spoke. In this case
all traffic pass through HUB and you can control whatever you want

Yes, in our case all the traffic is passing through HUB. The question is what is the best practice/way to implement control? Outgoing ACL on tunnel interface?