In a Dynamic Multipoint VPN (DMVPN) setup, you may need to allow specific traffic from Spoke1 to communicate with Spoke2's LAN while preventing other VLANs on Spoke1 from accessing Spoke2. To achieve this, you can configure a policy route table to permit only the specified source IP network to traverse the tunnel, while directing all other traffic directly to the internet.
For a policy route designed to match all ingress traffic on a LAN, it is recommended to configure the match based on the source interface. However, using the source IP range of the LAN can unintentionally include router-originated or proxied traffic, leading to issues such as failed DNS resolutions for the Ericsson Cradlepoint router or hotspot authentications.