Morning!
Yes! It is a temp migration of a lot of data.
VRFs I considered but the problem is
The 10.10.30.0/24 and 10.10.70.0/24 are subnets with servers that need to provide services while migrating to the new site.
So I could separate the routes with another vrf but I need all migration traffic to go down the 10.10.20.0 pipe while the services at both sites need to use the default route
I looked at pbr and couldn't seem to make it work without breaking the firewall piece not shown.
Access-list can't deal with the routing that I have seen
The problem is the actual default route for internet traffic vs wan traffic is not shown and I will adjust with this diagram below
I am not sure if this can be done without using a firewall and to change how things are setup physically.
And the way I have it setup is with static routes from the subnets that will send some traffic down the migration pipe due to accessibility to the servers on both ends
Not sure if it is doable with changes(and it has to be done without changing the structure and $$)

PATIENTS ARE ASKED NOT TO SEND MESSAGES TO THIS ADDRESS AS STAFF MAY NOT SEE THEM IN A TIMELY MANNER. IF YOU ARE EXPERIENCING A PSYCHIATRIC (MENTAL HEALTH) CRISIS, PLEASE CALL OUR MOBILE CRISIS/COMMUNITY CRISIS RESPONSE AND INTERVENTION TEAM, TOLL-FREE, AT (833) 364-2274. IT IS AVAILABLE AT ALL TIMES. AS ALWAYS, IF YOU ARE EXPERIENCING A MEDICAL EMERGENCY, PLEASE CALL 911.
PRIVACY NOTICE: THIS COMMUNICATION IS INTENDED ONLY FOR THE USE OF THE INDIVIDUAL OR ENTITY TO WHICH IT IS ADDRESSED AND MAY CONTAIN SCDMH PATIENT OR OTHER INFORMATION THAT IS PRIVATE AND PROTECTED FROM DISCLOSURE BY APPLICABLE LAW INCLUDING: 45 CFR PART 160 (HIPAA), § 44-22-100, S.C. CODE OF LAWS (SCDMH PATIENT CONFIDENTIALITY), AND WHEN APPLICABLE, 42 CFR PART 2 (ALCOHOL AND DRUG PROGRAM CONFIDENTIALITY.) IF THE READER OF THIS MESSAGE IS NOT THE INTENDED RECIPIENT OR RESPONSIBLE FOR DELIVERING THE MESSAGE TO THE INTENDED RECIPIENT, YOU ARE HEREBY NOTIFIED THAT ANY DISSEMINATION, DISTRIBUTION OR COPYING OF THIS COMMUNICATION, OR THE INFORMATION CONTAINED WITHIN IT, IS STRICTLY PROHIBITED AND MAY SUBJECT THE VIOLATOR TO CIVIL AND/OR CRIMINAL PENALTIES. IF YOU HAVE RECEIVED THIS COMMUNICATION IN ERROR, PLEASE NOTIFY US IMMEDIATELY BY TELEPHONE, REPLY E-MAIL OR FAX USING THE PHONE NUMBER OR ADDRESS IDENTIFIED IN THIS COMMUNICATION AND DESTROY OR DELETE ALL COPIES OF THIS COMMUNICATION AND ALL ATTACHMENTS.
Original Message:
Sent: 3/6/2025 4:22:00 AM
From: willembargeman
Subject: RE: Aruba CX How to control multiple routes to the same Source
You will make it your self difficult :-).
The traffic is forwarded based on the routing table. Did you consider to create a dedicated VRF for the communication over the P2P link?
Other option is to use Policy Based Routing (PBR). With PBR you can override the routing table and make decisions based on source / destination matching.
------------------------------
Willem Bargeman
Systems Engineer Aruba
ACEX #125
------------------------------
Original Message:
Sent: Mar 05, 2025 11:56 AM
From: cleveljd1
Subject: Aruba CX How to control multiple routes to the same Source
Diagram

Platforms
8400 and 8360 with same ver 10.11.1010
Problem
I can't seem to figure out a direction to allow all access to and from 10.10.30.0/24 10.10.70.0/24 but only allow traffic between them to route on the point to point connection.