If you have a dedicated DMVPN router and want to apply a simple access list to the public interface to block all other traffic, this is what you need opened up:
permit esp any any
permit udp any eq isakmp any eq isakmp
and if you have NAT-T, then you