Can you advertise summary routes that are turned on in the VPN in a hub site to on only selective MX VPN peers? What can you do if you do not want all meraki spoke/hub sites and non meraki peers to send traffic to a summary route that is advertised?



if you don't want devices to send traffic via a known summary route, you put a more specific route in your route table for that device and point it to the next hop you want it to use.


You can also modify route metrics to influence routes as well

Please explain in more detail how to do that? I don't see an option of route metrics.And if you now turn on a more specific route would that not also advertise to other VPN peers? Maybe an example would help me understand it better. 

All MXs share the same route table.

Ok. So all the sites in an organization that participate in site to site VPNs will join the mesh. We intend to have a small number of regional hubs. IS it possible to have some of the MX's in spoke sites not join this mesh and just have a single site to site connection to one hub? 

Yes.  As soon as you select spoke, you have to explicitly configure the hub(s) that it connects to.


Spokes never build an AutoVPN to another spoke.

Good info. In the mesh can you have one route advertised by 2 or multiple hubs? For instance I would like to advertise a summary route on at least two of our hubs. I've tried this but get an error.

>In the mesh can you have one route advertised by 2 or multiple hubs?


Yes.  They can not be directly connected to the hub(s) though.  You need to have the hub(s) connected via a transit network (such as to a layer 3 switch).

Just found this 

Routed Mode and AutoVPN

You can only advertise the same subnet from more than one appliance if all appliances advertising that subnet are in Passthrough or VPN Concentrator mode. All subnets advertised from an appliance in Routed mode must be unique within the AutoVPN topology.

