Chapter 10 IPsec VPN : Phase 2 parameters : Advanced Phase 2 settings : Perfect Forward Secrecy (PFS)
  
Perfect Forward Secrecy (PFS)
By default, Phase 2 keys are derived from the session key created in Phase 1. Perfect Forward Secrecy (PFS) forces a new Diffie-Hellman exchange when the tunnel starts and whenever the Phase 2 keylife expires, causing a new key to be generated each time. This exchange ensures that the keys created in Phase 2 are unrelated to the Phase 1 keys or any other keys generated automatically in Phase 2.