I am planning for DMVPN deployment where the hub router is going to be directly connected to the Internet while spokes will reside behind firewalls (PIX 501s). I would like spokes to do just the multipoint GRE and offload encryption to firewalls. The hub router will terminate both mGRE and IPSec. Will it work?
I don't care much for spoke to spoke connectivity.