Chapter 10 IPsec VPN : Phase 2 parameters : Advanced Phase 2 settings : Phase 2 Proposals
  
Phase 2 Proposals
In Phase 2, the VPN peer or client and the FortiGate unit exchange keys again to establish a secure communication channel. The Phase 2 Proposal parameters select the encryption and authentication algorithms needed to generate keys for protecting the implementation details of Security Associations (SAs). The keys are generated automatically using a Diffie-Hellman algorithm.