Only the hub has a VPN gateway to the grain elevator. Spokes must use that hybrid path without each deploying a gateway. Which peering settings should the security engineer enable?
Select an answer to reveal the explanation.
Short Explanation
One VPN gateway at the hub is enough. Flip Allow gateway transit on the hub peering and Use remote gateways on the spokes—don’t plant a gateway in every cornfield.
Full Explanation
Gateway transit lets spoke VNets use a VPN or ExpressRoute gateway in a peered hub. The hub peering needs Allow gateway transit, and each spoke peering needs Use remote gateways. Deploying a gateway per spoke is unnecessary and costly for this pattern. Virtual WAN is an alternative architecture, not the only valid answer when classic hub-spoke gateway transit meets the requirement. Reversing the transit flags breaks the design.