Chapter 3 Authentication for FortiOS 5.0 : Certificate-based authentication : Certificates overview : IPsec VPNs and certificates
  
IPsec VPNs and certificates
Certificate authentication is a more secure alternative to preshared key (shared secret) authentication for IPsec VPN peers. Unlike administrators or SSL VPN users, IPsec peers use HTTP to connect to the VPN gateway configured on the FortiGate unit. The VPN gateway configuration can require certificate authentication before it permits an IPsec tunnel to be established. See “Authenticating IPsec VPN users with security certificates”.