DH Groups 22, 23, 24 missing from Phase 2 selection GUI
When configuring IPSec you can select DH Groups 22-24 for Phase 1, but for Phase 2 they are missing from the GUI.
I got the following answer about this from support:
For cli you may change /var/etc/ipsec/ipsec.conf in ESP section, e.g. esp = aes128-sha1-modp2048s256!
But it will work only if you will not change ipsec settings via gui and will not reboot device
which to me suggests that the PFSense should be able to handle them just fine if they were added to the GUI
#4 Updated by Sean McBride over 2 years ago
DH Groups 22-24 are inadvisable:
Did this change ship? I'd recommend reverting it if not.
See also #7248.