What Is a Hub-and-Spoke Network?

Also called: Hub-and-spoke topology, Hub-and-spoke WAN

Related problems: When headquarters goes down, every branch loses access; Traffic between two branches is slow because it goes through the data center; Headquarters links are congested with traffic from all the sites; Not sure whether our WAN design still fits now that apps are in the cloud

A hub-and-spoke network is a wide area network design in which each remote site (a spoke) connects to one or more central sites (hubs), such as a headquarters or data center, rather than to every other site. Traffic between two spokes travels through a hub. The design is relatively simple to build and secure, and it has long been the default shape for branch networks built on MPLS, VPN tunnels and many SD-WAN deployments.

At a glance

  • Each branch connects to a hub; branches do not connect directly to each other.
  • Traffic between branches, and often to the internet, passes through the hub.
  • Fewer connections make it easier to manage, monitor and secure than a full mesh.
  • The hub is a critical point: designs commonly add a second hub and redundant circuits.
  • Cloud adoption has pushed many networks to add local internet breakout or selective mesh links.

What problem it solves

Connecting every site to every other site gets complicated quickly. With ten sites, a full mesh needs 45 links or tunnels; with a hundred sites, it needs thousands. Each must be configured, monitored and secured. When most traffic flows between branches and a central data center, that complexity buys little.

Hub-and-spoke keeps the number of connections close to the number of sites. Each branch needs one link to the hub, or two to two hubs for resilience. Security inspection, internet access and shared services can live at the hub, where one team can manage them. For organizations whose applications live in one or two data centers, it is often the most practical shape.

How it works

Hubs. A hub is usually a data center, headquarters or colocation site with larger circuits, firewalls, routers and shared services. Larger networks may have regional hubs serving nearby branches.

Spokes. Each branch connects to its hub over a private circuit, an MPLS service or an encrypted tunnel across the internet. In a classic design, routing sends traffic not destined for the local site toward the hub.

Branch-to-branch traffic. A call or file transfer between two branches goes from the first branch to the hub and back out to the second. That adds latency and uses hub capacity, which matters for voice and video between sites.

Internet traffic. In a classic design, branches send internet traffic to the hub as well, so it passes a central firewall. Many organizations now move some of that internet breakout closer to users, sending selected cloud traffic out at a regional point or locally at each branch instead.

Resilience. Because the hub carries so much, failures there affect many sites. Common network redundancy measures include a second hub in another location, redundant hub equipment and diverse circuits into each hub. How well a network survives a hub failure depends on that design.

Variations. Partial mesh designs keep the hub-and-spoke shape but add direct links between busy sites. Some SD-WAN platforms build branch-to-branch tunnels on demand when traffic needs them.

For private networks built on this and other designs, see our Private Networking solution page.

When it matters for buyers

  • Redesigning the WAN. Moving from MPLS to SD-WAN is a chance to decide which traffic should still flow through a hub.
  • Moving applications to the cloud. If the data center is no longer where applications live, backhauling everything to it may add delay without benefit.
  • Voice and video between sites. Branch-to-branch calls through a distant hub can suffer from added latency.
  • Business continuity planning. If one hub outage would cut off every site, a second hub may be worth the cost.
  • Mergers and acquisitions. Joining two networks often means choosing hubs and deciding how acquired sites connect.

Questions to ask vendors

  • Where will our hubs be, and how much capacity will each need?
  • What happens to every branch if a hub or its circuits fail, and how quickly does traffic move to another hub?
  • Will traffic between branches go through a hub, or can busy sites connect directly?
  • Which internet traffic will go out at the hub and which will break out locally?
  • How are hub circuits and equipment made redundant, and are the paths into each hub physically diverse?
  • How does pricing change if we add a hub or move to partial mesh?

How it differs from internet breakout

Hub-and-spoke describes the overall shape of the WAN: which sites connect to which. Internet breakout describes where internet-bound traffic leaves the network. A hub-and-spoke WAN can send internet traffic out at the hub (central breakout), at a regional hub or cloud security point of presence (regional breakout), or at each branch (local breakout), and many networks combine them, keeping internal traffic on hub-and-spoke paths while cloud traffic leaves locally. Choosing one does not decide the other; they are separate design decisions that are often made together.

Frequently Asked Questions

What is the difference between hub-and-spoke and full mesh?
In hub-and-spoke, each branch connects to a central hub and traffic between branches goes through it. In a full mesh, every site connects directly to every other site. Mesh shortens paths between sites but means many more connections to manage; partial mesh designs fall in between.
Is hub-and-spoke outdated?
No, but its role has changed. It still fits when most traffic goes to central applications or when central security inspection is required. Where most traffic goes to SaaS and cloud, many organizations combine it with local internet breakout or direct branch-to-branch tunnels.
How do you make a hub-and-spoke network resilient?
The hub is the critical point, so designs often add a second hub in a different location, redundant hub equipment and diverse circuits into each hub. Branches typically connect to both hubs and fail over if one is unavailable.
Does SD-WAN use hub-and-spoke?
Many SD-WAN deployments can. Most SD-WAN platforms let you choose hub-and-spoke, partial mesh or full mesh per traffic type, and some build branch-to-branch tunnels on demand.

You Don’t Need Another Sales Call. You Need an Answer.

30 minutes. No pitch. Just an honest conversation about where you are, what you need, and whether working together makes sense.

We use your details to set up and prepare for the call, and send the newsletter only if you ask for it. Privacy policy.