FortiGate-7000 for FortiOS 6.0.6 does not support IPsec VPN load balancing and
ipsec-vpn-load-balance must be disabled (and is disabled by default). Just like the FortiGate-6000, when
ipsec-vpn-load-balance is disabled, all IPsec VPN traffic is sent to the primary FPM and no load balancing flow rules are required.
Previous versions of FortiOS for FortiGate-7000 used load balancing flow rules. These rules are no longer required and Fortinet recommends that you manually remove them. See Manually deleting IPsec VPN load balancing flow rules.
As well, FortiGate-7000 for FortiOS 6.0.6 no longer requires you to add source and destination subnets to phase 2 configurations.