Here are the steps on how to create Site to Site VPN. Tunnel interface VPN is the same concept.
Step 1. Configure Security Association (clicking on Add then configure it):

Step 2. Add VPN, select Point to Point and Site-to-Site:

Step 3. Select SA:

Step 4. Configure device 1 (hub). GW IP is its X1 IP, for Spoke to reach:

Step 5. Configure device 2 (Spoke). No GW is needed:

Step 6. Save:

Step 7. Apply the topology:

Step 8. Confirm:

Step 9. Commit:

Step 10. Select commit:

Step 11. Successfully applied:

Step 12. Device 1 vpn is up:

Step 13. Device 2 VPN is up (note Gateway is 0.0.0.0):
