Configure the hub
At the FortiGate unit that acts as the hub, you need to
• configure the VPN to each spoke
• configure communication between spokes
You configure communication between spokes differently for a policy-based VPN than for a route-based VPN. For a policy-based VPN, you configure a VPN concentrator. For a route-based VPN, you must either define security policies or group the IPsec interfaces into a zone