It doesnt take much. The HUB itself is just a "vpn orchestrator" you can
get away with really any fortigate. How many spokes do you have.Make
sure you set it up like we show here with BGP on Loopback:
https://youtu.be/04BjjyMYEEk?si=glf86nLVIPtUmiD4
Either session stuck in the incorrect outbound session table, thus
needing a blackhole route.Or NATT needs to be forced as ISP may have put
you behind some cgnat or other device