Secure traffic processing really happens on the local MX, where clients are connected - you will get limited protection, if you're relying on just the VPN Hub to (Advanced Security) process the traffic. You most likely need Adv Sec for the Spoke. This is one reason why we simplify everything to the same license level, per Org.
... View more