Local Interface | Select the hub’s interface to the internal (private) network. |
Local Protected Subnet | Select the source address that you defined in Step 1. |
Outgoing VPN Interface | Select the hub’s public network interface. |
Remote Protected Subnet | Select the address name you defined in Step 2 for the private network behind the spoke FortiGate unit. |
VPN Tunnel | Select Use Existing and select the name of the Phase 1 configuration that you created for the spoke in Step 1. Select Allow traffic to be initiated from the remote site to enable traffic from the remote network to initiate the tunnel. |