@harmankardon you’re on the right track. Hub and spoke is the way to go, as everyone else has said, and yes, the spokes can still communicate via the hub. The site-to-site VPN rules are organisation-wide - so you only create and apply one set of rules and they appear on all sites. They are also applied in the outbound direction only (I.e. as the traffic leaves the site over the AutoVPN). I’d create rules that allow connections from the HQ subnets to all the other site subnets and from the site subnets to the HQ subnets, and then after them a series of deny rules that prevent traffic between the site subnets.
... View more