I'm planning to build S2S VPN Network with one-armed VPN concentrator configuration.
Simplified network topology is like below:
In this case, I'm assuming routing config for Dist. L3 is like this:
- Each site : Static to Meraki center MX
- Default : Core L3 -> eventually goes to Internet via DC edge firewall
But on the other hand, I think that if routing is like above, traffic goes from DC to site loops between center VPN and dist. L3.
Dist L3 : It headed to Site network. Forward it to Center VPN.
Center VPN : Hmm, this one goes to Site network. So, I'll give it to my next hop -Dist L3- to forward it to site.
Dist L3 : Huh, this one goes to Site network. Give it to Center VPN. (Did I saw this packet before? Kinda familiar...)
And goes on and on....
Am I thinking wrong? If it's wrong, can I get some advice for underlying routing config for one-armed VPN concentrator configuration?