Something like:
access-list extended farsidesubnet
permit ip any x.x.x.x y.y.y.y
class-map match-all farsidesubnet
match group farsidesubnet
policy-map restrictsomeoutbound
class farsidesubnet
shape 4500000 (or police 4500000)
Use above on both hub and remote spoke.
interface type #
service-policy outbound restrictsomeoutbound