This config is typically done to send spoke traffic to another egress point like another firewall. For example internet bound traffic from a spoke going over the full tunnel to the routed mode hub will enter the hub then be sent out the hub's default gateway (WAN interface). I've seen instances in which the requirement is to not exit right back out of the hub's WAN port, but rather send to another firewall to do whatever inspection, rules, etc. And in such cases that's when the 0/0 LAN side route is needed on the hub. But when that is the requirement I think there's a serious question that need to be asked of why use routed mode and not concentrator mode.
... View more