Content Filtering need to be configured for every network?
We currently have one HQ network with multiple branch networks with site to site vpn. I'm in the process of setting up content filtering and I was wondering:
1. If the HQ network is set as an exit hub NOT default route, will I need to set up content filtering for each network or will it mirror the HQ network since it is set up as the exit hub? If no, will it mirror the HQ network if it is set up as a default route for the spokes?
2. We have to have all of our networks setup as a hub at the moment because of our phones not working in hub/spoke mode. Will this significantly decrease performance in the network as Meraki stated?
>Will this significantly decrease performance in the network as Meraki stated?
The decrease in performance is due to the additional VPN tunnels that the MX has to maintain. In a hub and spoke each spoke will have between 1 and 4 VPN tunnels depending on the design. When running in hub mode the MX is having to maintain 1 to 4 VPN tunnels to all other hubs in the organisation... a significant increase, which is what creates the load on the MX. You need to check the MX Sizing Guide to see how many VPN tunnels your devices will support.