In this case, as it is all VPN users, I believe you could use the VPN site-to-site outbound firewall policies to restrict your Spoke<>Hub traffic by using the appropriate source/destination IPs. For example your policy could be source of VPN subnet, destination of the list of specific servers, you would then need a deny policy below this (if you don't already have a default deny all). Site-to-site VPN Firewall Rule Behavior - Cisco Meraki Documentation
... View more