Chapter 11 IPsec VPN for FortiOS 5.0 : IPsec VPN concepts : Phase 1 and Phase 2 settings : Phase 1
  
Phase 1
In Phase 1, the two VPN gateways exchange information about the encryption algorithms that they support and then establish a temporary secure connection to exchange authentication information.
When you configure your FortiGate unit or FortiClient application, you must specify the following settings for Phase 1:
Remote Gateway
The remote VPN gateway’s address.
FortiGate units also have the option of operating only as a server by selecting the “Dialup User” option.
Preshared key
This must be the same at both ends. It is used to encrypt phase 1 authentication information.
Local interface
The network interface that connects to the other VPN gateway. This applies on a FortiGate unit only.
All other Phase 1 settings have default values. These settings mainly configure the types of encryption to be used. The default settings on FortiGate units and in the FortiClient application are compatible. The examples in this guide use these defaults.
For more detailed information about Phase 1 settings, see the “Auto Key phase 1 parameters”.