I' ve created a hub-and-spoke IPsec VPN configuration for our company
network with IPsec-protected OSPF using the Fortinet-recommended
procedure (loopback addresses, tunnel-end addresses, binding the OSPF
interface to the virtual IPsec interface, etc...