Go to Router > Static > Static Routes.
Create a route for IPsec traffic, setting
Device to the VPN Phase 1.
If the Router menu is not visible, go to
System > Config > Features to ensure
that Advanced Routing is turned on.
Configuring the Branch's
IPsec VPN
One the Branch FortiGate, Go to VPN >
IPsec > Auto Key (IKE).
Select Create Phase 1. Set IP Address to
the IP of the HQ FortiGate, Local Interface
to the Internet-facing interface, and enter the
same Pre-shared Key used previously.
184
The FortiGate Cookbook 5.0.