Chapter 10 IPsec VPN : FortiClient dialup-client configurations : Configuration overview : One button FortiGate-to-FortiClient Phase 1 VPN
  
One button FortiGate-to-FortiClient Phase 1 VPN
On the FortiOS VPN IKE page there is a method to create a Phase 1 portion of a VPN tunnel between the FortiGate and FortiClient. Very little information is required for this configuration. No encryption or authentication method is required. This feature is ideal for setting up quick VPN connections with basic settings.
On the Phase 1 screen is the option Create a FortiClient VPN. When selected, the FortiGate uint requires a few basic VPN configuration related questions. Once all the information is added, select OK. This will create a new dial-up IPsec-interface mode tunnel. Phase 1 and Phase 2 will be added using the default IKE settings.
The following Settings will be used when creating a one-button FortiClient VPN Phase 1 object:
Remote Gateway: Dialup User
Mode: Aggressive
Default setting for Phase 1 and 2 Proposals
XAUTH Enable as Server (Auto)
IKE mode-config will be enabled
Peer Option set to “Any peer ID”
Rest of the setting use the current defaults (Default value needs to be the same on FCT side)
Once the completed, you need tocreate a default Phase 2 configuration. This only requires a name for the Phase 2 object, and select the FortiClient connection Phase 1 name.