You configure Phase 1 and Phase 2 settings for each IPSec VPN.
For a manual Branch Office VPN (BOVPN), you configure Phase 1 settings when you define a Branch Office gateway, and you configure Phase 2 settings when you define a Branch Office tunnel.
For more information about BOVPN Phase 1 and Phase 2 settings, see:
For Mobile VPN with IPSec, you configure the Phase 1 and Phase 2 settings when you add or edit a Mobile VPN with IPSec configuration.
For more information, see:
When an IPSec tunnel is created, the IPSec protocol checks the identity of each endpoint with either a pre-shared key (PSK) or a certificate imported and stored on the XTM device. You configure the tunnel authentication method in the VPN Phase 1 settings.
For more information about how to use a certificate for tunnel authentication, see:
About IPSec VPN Negotiations