Chapter 11 IPsec VPN for FortiOS 5.0 : FortiClient dialup-client configurations : Configuration overview : One button FortiGate - to - FortiClient Phase1 VPN
  
One button FortiGate - to - FortiClient Phase1 VPN
On the FortiOS VPN IKE page there is a method to create a Phase1 portion of a VPN tunnel between the FortiGate and FortiClient. Very little information is required for this configuration. No encryption or authentication method is required. This feature is ideal for setting up quick VPN connections with basic settings.
On the Phase 1 screen (VPN > IPsec > Phase 1) is the option Create a FortiClient VPN. When selected, the FortiGate uint requires a few basic VPN configuration related questions. Once all the information is added, select OK. This will create a new dial-up IPsec-interface mode tunnel. Phase 1 and Phase 2 will be added using the default ike settings.
The following Settings will be used when creating a one-button FortiClient VPN Phase1 object:
Remote Gateway: Dialup User
Mode: Aggressive
Enable IPSec Interface Mode
Default setting for P1 and P2 Proposal
XAUTH Enable as Server (Auto)
IKE mode-config will be enabled
Peer Option set to “Accept any peer ID”
Rest of the setting use the current defaults (Default value needs to be the same on FCT side)
Once the completed, you need tocreate a default Phase2 configuration. This only requires a name for the Phase2 object, and select the FortiClient connection Phase1 name.