A hub-and-spoke network is a wide area network design in which each remote site (a spoke) connects to one or more central sites (hubs), such as a headquarters or data center, rather than to every other site. Traffic between two spokes travels through a hub. The design is relatively simple to build and secure, and it has long been the default shape for branch networks built on MPLS, VPN tunnels and many SD-WAN deployments.
At a glance
- Each branch connects to a hub; branches do not connect directly to each other.
- Traffic between branches, and often to the internet, passes through the hub.
- Fewer connections make it easier to manage, monitor and secure than a full mesh.
- The hub is a critical point: designs commonly add a second hub and redundant circuits.
- Cloud adoption has pushed many networks to add local internet breakout or selective mesh links.
What problem it solves
Connecting every site to every other site gets complicated quickly. With ten sites, a full mesh needs 45 links or tunnels; with a hundred sites, it needs thousands. Each must be configured, monitored and secured. When most traffic flows between branches and a central data center, that complexity buys little.
Hub-and-spoke keeps the number of connections close to the number of sites. Each branch needs one link to the hub, or two to two hubs for resilience. Security inspection, internet access and shared services can live at the hub, where one team can manage them. For organizations whose applications live in one or two data centers, it is often the most practical shape.
How it works
Hubs. A hub is usually a data center, headquarters or colocation site with larger circuits, firewalls, routers and shared services. Larger networks may have regional hubs serving nearby branches.
Spokes. Each branch connects to its hub over a private circuit, an MPLS service or an encrypted tunnel across the internet. In a classic design, routing sends traffic not destined for the local site toward the hub.
Branch-to-branch traffic. A call or file transfer between two branches goes from the first branch to the hub and back out to the second. That adds latency and uses hub capacity, which matters for voice and video between sites.
Internet traffic. In a classic design, branches send internet traffic to the hub as well, so it passes a central firewall. Many organizations now move some of that internet breakout closer to users, sending selected cloud traffic out at a regional point or locally at each branch instead.
Resilience. Because the hub carries so much, failures there affect many sites. Common network redundancy measures include a second hub in another location, redundant hub equipment and diverse circuits into each hub. How well a network survives a hub failure depends on that design.
Variations. Partial mesh designs keep the hub-and-spoke shape but add direct links between busy sites. Some SD-WAN platforms build branch-to-branch tunnels on demand when traffic needs them.
For private networks built on this and other designs, see our Private Networking solution page.
When it matters for buyers
- Redesigning the WAN. Moving from MPLS to SD-WAN is a chance to decide which traffic should still flow through a hub.
- Moving applications to the cloud. If the data center is no longer where applications live, backhauling everything to it may add delay without benefit.
- Voice and video between sites. Branch-to-branch calls through a distant hub can suffer from added latency.
- Business continuity planning. If one hub outage would cut off every site, a second hub may be worth the cost.
- Mergers and acquisitions. Joining two networks often means choosing hubs and deciding how acquired sites connect.
Questions to ask vendors
- Where will our hubs be, and how much capacity will each need?
- What happens to every branch if a hub or its circuits fail, and how quickly does traffic move to another hub?
- Will traffic between branches go through a hub, or can busy sites connect directly?
- Which internet traffic will go out at the hub and which will break out locally?
- How are hub circuits and equipment made redundant, and are the paths into each hub physically diverse?
- How does pricing change if we add a hub or move to partial mesh?
How it differs from internet breakout
Hub-and-spoke describes the overall shape of the WAN: which sites connect to which. Internet breakout describes where internet-bound traffic leaves the network. A hub-and-spoke WAN can send internet traffic out at the hub (central breakout), at a regional hub or cloud security point of presence (regional breakout), or at each branch (local breakout), and many networks combine them, keeping internal traffic on hub-and-spoke paths while cloud traffic leaves locally. Choosing one does not decide the other; they are separate design decisions that are often made together.
