Hi @AndreasE, Hoping I can help clarify a few things and maybe improve our documentation a bit while we're at it. Site-to-site VPN cannot be enabled for a security appliance template unless VLANs are enabled, and at least one VLAN emits unique subnets. By default cloning templates sets VPN to off to prevent subnet overlap within the Organisation. Config sync doesn't work for "network tags" or "Template networks" (containing an MX appliance and a MS switch) 1. The "VLANs enabled" bit is mentioned in the "IP Address Range Allocations" section, as @PhilipDAth pointed out, but I agree with you that the "emits unique subnets" bit could be a bit more clear. 2. This is not mentioned, and I agree that it should be. I updated this section of the documentation with a couple notes to make these requirements a bit more clear. 3. As @PhilipDAth mentioned, the inability to clone combined networks is currently a shortcoming of the config sync feature. I can't personally speak much to our plans to address this, but we're aware that it is an issue. 1. "known issues": they never tell you, but just keep it under the blanket 2. software bugs: no bug bounty program, instead you get silly reply questions about settings they should better know about than we do (why are they asking for a device ref when they never look into the device whilst working on a case?) 3. really bad or aged documentation on the web 4. instead of an error message or at least a warning, the dashboard falls back into a default setting and doesn't tell you about the risks 1. It's not our intent to hide known issues, it's just difficult to always ensure that we're presenting them in a way that is helpful. Our support engineers use the same documentation site that our users do and help keep it up-to-date, so if it's not recorded, it is almost certainly not an intentional omission. I appreciate feedback like this when you notice we're missing something. 3. I'm personally working on cleaning up as much as we can. I agree that some items are a bit dated and deserve some attention. If something stands out to you as particularly misleading or inaccurate, I'll take a look if you let me know. I realize that doesn't address everything you were concerned about, but hopefully that helps a bit with the things I'm able to speak to. Thanks for the feedback!
... View more