Chapter 1 What’s New for FortiOS 5.2.1 : IPsec VPN : Internet Key Exchange (IKE) : Inheriting Groups from the Security Policy
  
Inheriting Groups from the Security Policy
IPsec VPNs can now be configured to authenticate users again the group(s) specified in a policy that refers to the VPN's phase 1. To use this feature, do the following:
1. Go to VPN > IPsec > Tunnels and edit a tunnel.
2. Set XAUTH Type to Auto Server.
3. Set User Group to Inherit Groups from Policy.
This feature can be used for both interface-based and policy-based IPsec VPN phase 1s.
Syntax
config vpn ipsec {phase1 | phase1-interface}
edit <name>
set xauthtype auto
end
end