Chapter 11 IPsec VPN for FortiOS 5.0 : IPsec VPN concepts : Phase 1 and Phase 2 settings : Phase 2
  
Phase 2
Similar to the Phase 1 process, the two VPN gateways exchange information about the encryption algorithms that they support for Phase 2. You may choose different encryption for Phase 1 and Phase 2. If both gateways have at least one encryption algorithm in common, a VPN tunnel can be established. Keep in mind that more algorithms each phase does not share with the other gateway, the longer negotiations will take. In extreme cases this may cause timeouts during negotiations.
To configure default Phase 2 settings on a FortiGate unit, you need only select the name of the corresponding Phase 1 configuration. In FortiClient, no action is required to enable default Phase 2 settings.
For more detailed information about Phase 2 settings, see “Phase 2 parameters”.