Shows phase 2 proposals and selectors.
Why this answer
The 'diagnose vpn ike config' command (D) displays the IKE configuration that the FortiGate is actually using for phase 2 negotiations, including proxy IDs, encryption algorithms, and lifetimes. This helps identify mismatches between the local and peer configurations that cause phase 2 to fail. The 'diagnose debug application ike 255' command (E) enables verbose IKE debugging, which logs every phase 2 exchange, including error messages like 'no proposal chosen' or 'mismatched proxy ID', directly pinpointing the failure reason.