FortiGate
FortiGate Next Generation Firewall utilizes purpose-built security processors and threat intelligence security services from FortiGuard labs to deliver top-rated protection and high performance, including encrypted traffic.
ronmar
Staff
Staff
Article Id 351708
Description

This article describes an issue where the HUB option is greyed out when creating an ADVPN setup using IPSec Wizard.

 

HUB_grey.jpg

Scope FortiOS.
Solution

This is due to a Spoke configuration that is still present on the IPSec VPN configuration of the FortiGate.

 

Set_autodiscovery.jpg


To be able to select the HUB template, auto-discovery-receiver must be disabled.

 

config vpn ipsec phase1-interface

    edit <VPN_Name>

        set auto-discovery-receiver disable

end

 

Or:

 

Delete the whole IPSec VPN phase1-interface configuration.

 

Note: All the references of the IPSec Phase1-interface must be deleted first for us to be able to delete the whole IPSec Phase1-interface tunnel including the Firewall policies and Phase2-interface.

 

After doing one of the steps above, the HUB template can be selected again on the IPSec Wizard.

 

HUB.jpg

 

Related article:

Troubleshooting Tip: 'Unable to setup VPN' error when using IPsec Wizard Hub-and-Spoke template