Hi All,
Client ask is to add a new VLAN which should have direct internet breakout with no access to DC services. Currently site has default routes coming from DC hence all internet + VPN traffic goes to DC from site. Restriction to DC services can be set up using group policies but how to allow local breakout for particular VLAN?
In order to manage the request, I need to
1. Remove IPv4 Default Route checkbox from Hubs under Site-to-Site VPN
2. select VLANS that I want to follow DC path and select appropriate DC as next hop for them.
Doing this, not selected VLANS in step 2 will automatically have local breakout as bi-product of first 2 steps.
However, I only see one DC as a next hop can be selected. what if primary DC fails, will that route automatically sends the traffic to next available DC Hop without explicitly configuring that or not ? What happens when next hop fails?
Also, is there any other workaround available?