Thats what I meant by using stronger ciphers and adding the two DHG’s in the proposal.
> On 2 May 2018, at 09:37, Tobias Brunner <[email protected]> wrote: > > Hi Christian, > >> For the record, the IKE proposals that work for OSX and Windows (with >> weak or strong ciphers enabled) is as follows >> >> aes256-sha256-prfsha256-modp2048-modp1024 > > If you want to use a stronger DH group with Windows clients see [1]. > > Regards, > Tobias > > [1] > https://wiki.strongswan.org/projects/strongswan/wiki/Windows7#AES-256-CBC-and-MODP2048
