IPsec site-to-site permanently links two networks. Negotiation happens in two phases: Phase 1 builds an encrypted management channel and authenticates the peers, Phase 2 defines which traffic actually enters the tunnel.
- Phase 1 — IKE: peer identity (pre-shared key or certificate), encryption, DH group and lifetime.
- Phase 2 — IPsec SA: the selectors (local vs remote network) and PFS.
- SSL VPN — remote user access via browser (web mode) or (tunnel mode).
Two FortiGates talk over UDP 500 and 4500. Phase 1 (IKE) settles who is who: main or aggressive mode, PSK or certificate, DH group, encryption and lifetime. Phase 2 settles what gets encrypted: local and remote selectors, PFS, lifetime and ESP. Even with the tunnel up you still need firewall policies in both directions and a static route to the remote subnet. Phase 1 up with phase 2 down almost always means mismatched selectors, PFS or lifetime.