FlexVPN spoke to spoke communication fails with IPSec tunnel
When implementing FlexVPN in a hub and spoke topology, it uses the Next Hop Resolution Protocol (NHRP) in order to enable spoke-to-spoke communication. NHRP will only function correctly over a GRE tunnel. A native IPSec tunnel will not tunnel NHRP communication and thus spoke to spoke communication will fail. However, communication via the hub is still possible.