This is a Phase 2 mismatch, most likely due to multiple subnets on
either side of the encryption domain. For a fortigate to cisco IPSEC
VPN, you will need to have multiple phase 2 policies if there are
multiple subnets on either end. For example, if ...