Which outbound control policy assigned to branch sites establishes a strict hub-and-spoke topology for VPN2?
A strict VPN2 hub-and-spoke design advertises hub-originated VPN2 routes to branches and suppresses all other VPN2 routes, preventing direct branch-to-branch reachability. The policy must therefore accept routes from hub site IDs 1–2 in VPN2 and reject the remaining VPN2 routes, while allowing routes outside VPN2 through the default action. Control-policy sequences are evaluated in numeric order and stop when a route matches.
Community Discussion