I've had to go down this road to due IkeV1 deprecation and having to
maintain FortiToken MFA, etc. etc. It is definitely a real pain. Key
configuration elements on the firewall that only exist in CLI must be
set and then the XML file for "VPN Only" c...