I have a router 580 as a hub tunneling with 30 spokes. behind the HUB there are servers on different VLANs. is there a way to restrict certain users from the spokes to access this VLAN? If yes, would it be from the HUB or from the spokes themselves?

you can’t restrict users, but you can restrict IP-Adresses or subnets with the internal firewall rules

