To add a hub and spoke
Select a device that is part of a group from the Choose Devices drop-down menu. You can also search for the device or group in the list by typing the name in the input field.
Enter the Hub details.
| WAN Interface | Select a WAN Interface from the existing list or add a new Custom Interface. |
| Primary WAN IP | Enter the primary gateway in the field. |
| Secondary WAN IP | Enter the secondary gateway in the field. |
| Local IKE ID Criteria |
Choose from Firewall ID, IPV4 Address, Domain Name, Key Identifier, or Email Address. |
| IKE ID |
This field is auto-populated when Firewall ID is selected as Local IKE ID Criteria and cannot be edited. Enter the IKE ID if any other option is selected. |
| Protected Network/Local Network |
Select a network which participates in VPN connection from hub side. Select an Address Object or Address Group (default or custom) from the drop-down menu. If the list is empty, you can create a new custom address object and group. Click the Edit icon to add or edit Address Object and Group. If you are creating an Address Object while configuring a Hub, the Zone Assignment drop-down menu displays the Default and Custom zones of the selected device. |
Click the caret icon next to the ADD SPOKE details.
Select devices from the Choose devices drop-down menu and click Apply. You can also search for the devices or groups in the list by typing the name in the input field. The devices that are selected are displayed in a list.
You can select multiple devices.
Hub and Spokes should not have overlapping IP Addresses in any of the fields.
Select the Configuration Type to be used.
After selecting the Configuration Type and creating a topology, the configuration type cannot be modified.
Common Configuration: Select this option to apply a common configuration to multiple devices.
Enter the configuration details.
| WAN Interface | Select a WAN Interface from the existing list or add a new Custom Interface. |
| Local IKE ID Criteria |
Choose from Firewall ID, IPV4 Address, Domain Name, Key Identifier, and Email Address. |
| IKE ID |
This field is auto-populated if Firewall ID is selected as Local IKE ID Criteria and cannot be edited. Enter the IKE ID if any other option is selected. |
| Protected Network/Local Network |
Select an Address Object or Address Group (default or custom) from the drop-down menu. If the list is empty, you can create a new custom address object and group. If you are creating an Address Object while configuring a Spoke with the Common Configuration option, the Zone Assignment drop-down menu displays only the common Default and Custom zones of the selected devices. Select an Existing Address Object or Address Group:
Create a New Address Object:
Create a New Address Group:
|
Click Accept For All for Common Configuration.
Make sure that all the required fields are filled before clicking Accept For All
Per Spoke: Select this option to apply a configuration to a specific device.
The devices that are selected are displayed in a list. You can also search for the devices or groups in the list by typing the name in the input field.
Click the Edit icon in the ACTION column of the selected device.
Enter the configuration details.
| WAN Interface | Select a WAN Interface from the existing list or add a new Custom Interface. |
| Local IKE ID Criteria |
Choose from Firewall ID, IPV4 Address, Domain Name, Key Identifier, and Email Address. |
| IKE ID |
This field is auto-populated if Firewall ID is selected as Local IKE ID Criteria and cannot be edited. Enter the IKE ID if any other option is selected. |
| Protected Network/Local Network |
Select an Address Object or Address Group (default or custom) from the drop-down menu. If the list is empty, you can create a new custom address object and group. Click the Edit icon to add or edit Address Object and Group. If you are creating an Address Object while configuring a Spoke with the Common Configuration option, the Zone Assignment drop-down menu displays the Default and Custom zones of the selected device. |
Click Save.
Save is enabled only when all the fields are filled.
Click Next.
Sections with incomplete fields are marked as Need input. When all required fields are completed and accepted (if applicable), the section is marked as Configured, and Next becomes available.