Chapter 11 IPsec VPN for FortiOS 5.0 : Phase 2 parameters : Advanced phase 2 settings : P2 Proposals
  
P2 Proposals
In phase 2, the VPN peer or client and the FortiGate unit exchange keys again to establish a secure communication channel. The P2 Proposal parameters select the encryption and authentication algorithms needed to generate keys for protecting the implementation details of Security Associations (SAs). The keys are generated automatically using a Diffie-Hellman algorithm.