Avatar of MitebS
MitebS asked on

DMVPN 3, deny Spoke to Spoke Traffic, and allow a certain Spoke to be reached by the other Spokes.

In DMVPN Phase 3, I need to deny Spokes to reach each other, except a certain Spoke I will name it here SPOKE-X.
I need all the Spokes to communicate with SPOKE-X, but all the Spokes must not communicate with each other.

With DMVPN Phase 1, the answer is turn of  split-horizon on tunnel interface and to use Distribute-List in the EIGRP (My interior routing protocols).

I will upgrade My DMVPN to Phase 3, to Save the Bandwidth on the HUB for the Traffic from Spokes to SPOKE-X

 I need your help please.
Network SecurityNetworkingVPNNetwork Architecture

Avatar of undefined
Last Comment
rauenpc

8/22/2022 - Mon
arnold

You can not use LANs of the spokes in the Nonat rule on the hub, your site to site hub to spoke using dynamic publishing networks, while your ACL will dictate whether the spoke has access rights to the other remote spoke.
Limit the advertising of routes hub to spoke ....... Just the segments to which it can go.
Make sure you also do not exempt IPSec/VPN from nat rules.
This way your hub ACL rules along with your network advertisement will dictate which and whether a spoke can access another spoke via the hub.

Since you mentioned a spoke, you do not have a mesh setup where certain spokes have direct connection between them.
ASKER
MitebS

thanks arnold
i need to prevent Spokes to receive other Spokes routs

thanks
arnold

Control the advertisement of those routes to the spokes, it sounds as though your HUB transmits the same set of routes to all spokes.

Does the Cisco cover your setup?
http://www.cisco.com/c/en/us/support/docs/security-vpn/ipsec-negotiation-ike-protocols/29240-dcmvpn.html

I.e. whether the spoke to spoke communication is not via the HUB but rather the spoke initiates/establishes a VPN connection directly to the spoke to which there is traffic .......?
All of life is about relationships, and EE has made a viirtual community a real community. It lifts everyone's boat
William Peck
ASKER CERTIFIED SOLUTION
rauenpc

Log in or sign up to see answer
Become an EE member today7-DAY FREE TRIAL
Members can start a 7-Day Free trial then enjoy unlimited access to the platform
Sign up - Free for 7 days
or
Learn why we charge membership fees
We get it - no one likes a content blocker. Take one extra minute and find out why we block content.
See how we're fighting big data
Not exactly the question you had in mind?
Sign up for an EE membership and get your own personalized solution. With an EE membership, you can ask unlimited troubleshooting, research, or opinion questions.
ask a question