Chapter 11 IPsec VPN for FortiOS 5.0 : Hub-and-spoke configurations : Configuration overview
  
Configuration overview
In a hub-and-spoke configuration, VPN connections radiate from a central FortiGate unit (the hub) to a number of remote peers (the spokes). Traffic can pass between private networks behind the hub and private networks behind the remote peers. Traffic can also pass between remote peer private networks through the hub.
Figure 258: Example hub-and-spoke configuration
The actual implementation varies in complexity depending on
whether the spokes are statically or dynamically addressed
the addressing scheme of the protected subnets
how peers are authenticated.
This guide discusses the issues involved in configuring a hub-and-spoke VPN and provides some basic configuration examples.