FortiGate
FortiGate Next Generation Firewall utilizes purpose-built security processors and threat intelligence security services from FortiGuard labs to deliver top-rated protection and high performance, including encrypted traffic.
pdelapena
Staff
Staff
Article Id 318170
Description This article describes the reason why VPN creation using the Hub-and-Spoke template in IPsec Wizard cannot proceed further while in Step 4 (Policy & Routing) and how to complete the VPN creation.
Scope FortiGate.
Solution

When recreating Hub-and-Spoke VPN in IPsec Wizard an issue where the 'Next' button in Step 4 (Policy & Routing) is grayed out and cannot be selected may happen. 

 

hs1.png

 

This issue occurs when there is an old configuration with the same setup via IPsec Wizard and there is an attempt to recreate a new one with the same settings. Though the previous VPN configuration was already deleted, the BGP neighbor configuration was kept configured. 

 

hs5.jpg

 

hs2.png

 

In the image above, the BGP neighbor - 10.10.1.1 which is the remote IP configured in the previous configuration needs to be deleted. When this is left in the configuration before recreating a new VPN, there will be a conflict due to a duplicate entry when trying to reconfigure the same configuration in IPsec Wizard.

This BGP neighbor configuration cannot be seen under the references of the IPsec tunnel which is why there is a high chance this configuration is retained.

 

After deleting the old BGP neighbor configuration, recreate again the VPN in IPsec Wizard either manually or using the Spoke Easy Configuration Key. Moving forward in the Policy & Routing section in the IPsec Wizard, the 'Next' button should now be selectable and it is possible to proceed further.

 

hs4.png

 

Review the settings in Step 5 and finalize the creation of the VPN. The below image indicates the successful creation of Hub-and-Spoke VPN using the IPsec Wizard.

 

hs6.png