Chapter 10 IPsec VPN : FortiClient dialup-client configurations : Configuration overview : Peer identification
  
Peer identification
The FortiClient application can establish an IPsec tunnel with a FortiGate unit configured to act as a dialup server. When the FortiGate unit acts as a dialup server, it does not identify the client using the Phase 1 remote gateway address. The IPsec tunnel is established if authentication is successful and the IPsec security policy associated with the tunnel permits access. If configured, the FortiGate unit could also require FortiClient registration, that is, the remote user would be required to have FortiClient installed before connection is completed.
There are several different ways to authenticate dialup clients and restrict access to private networks based on client credentials. For more information, see “Authenticating remote peers and clients”.