Chapter 10 IPsec VPN : FortiClient dialup-client configurations : Configuration overview : One button FortiGate-to-FortiClient Phase 1 VPN : How the FortiGate unit determines which settings to apply
  
How the FortiGate unit determines which settings to apply
The FortiGate unit follows these steps to determine the configuration information to send to the FortiClient application:
1. Check the virtual domain associated with the connection to determine which VPN policies might apply.
2. Select the VPN policy that matches the dialup client’s user group and determine which tunnel (Phase 1 configuration) is involved.
3. Check all IPsec security policies that use the specified tunnel to determine which private networks the dialup clients may access.
4. Retrieve the rest of the VPN policy information from the existing IPsec Phase 1 and Phase 2 parameters in the dialup-client configuration.