Converting FortiGate NGFW to a FortiSASE SPA hub using FortiOS CLI or GUI
FortiSASE points of presence integrate with a hub-and-spoke network using ADVPN as its VPN overlay and BGP for its routing.
This section describes the following configuration settings and the FortiOS GUI configuration steps using the IPsec wizard and additional CLI and GUI configuration that you must configure on your FortiGate NGFW to convert it to a FortiSASE secure private access hub:
- IPsec VPN configuration using IPsec wizard and CLI
- Tunnel interface configuration
- Loopback interface configuration
- Firewall policy configuration
- BGP configuration
For details on configuring using the FortiOS GUI without using the IPsec wizard or FortiOS CLI, see Appendix C - Converting FortiGate NGFW configured using FortiOS GUI to a FortiSASE SPA hub without using the IPsec wizard.