FortiGate as dialup Remote VPN To configure IPsec VPN with FortiGate as the dialup client in the GUI: Configure the dialup VPN server FortiGate: Go to VPN > IPsec Wizard and configure the following settings for VPN Setup: Enter a VPN name. For Template Type, select Site to Site. For Remote Device Type, select FortiGate. For NAT Configuration, select The remote site is behind NAT. Click Next. Configure the following settings for Authentication: For Incoming Interface, select the incoming interface. For Authentication Method, select Pre-shared Key. In the Pre-shared Key field, enter your-psk as the key. Click Next. Configure the following settings for Policy & Routing: From the Local Interface dropdown menu, select the local interface. Configure the Local Subnets as 10.1.100.0/24. Configure the Remote Subnets as 172.16.101.0/24. Click Create. Configure the dialup VPN client FortiGate: Go to VPN > IPsec Wizard and configure the following settings for VPN Setup: Enter a VPN name. For Template Type, select Site to Site. For Remote Device Type, select FortiGate. For NAT Configuration, select This site is behind NAT. Click Next. Configure the following settings for Authentication: For IP Address, enter 11.101.1.1. For Outgoing Interface, select port13. For Authentication Method, select Pre-shared Key. In the Pre-shared Key field, enter your-psk as the key. Click Next. Configure the following settings for Policy & Routing: From the Local Interface dropdown menu, select the local interface. In this example, it is port9. Configure the Local Subnets as 172.16.101.0. Configure the Remote Subnets as 10.1.100.0. Click Create. CLI Commnd For Firewall What use Phase1 And phase2 Proposal Example DES,AES,MD5 etc,Configuration Match Fortigate firewall + Forti Client show vpn ipsec phase1-interface show vpn ipsec phase2-interface