If multiple phase 2 exist, FortiGate directs traffic to the correct phase 2. 
Allows granular security settings for each LAN. 
If traffic does not match an lPsec SA selector, it is dropped.  
ln point-to-pointVPNs, selectors must match. 
- The source on one FortiGate is the destination setting on the other.  
Select which SA to apply using: 
Destination and source IP subnet(s) 
Protocol number 
Source port and destination port  
Select one of the following: