[strongSwan] policy mismatch

Tobias Brunner tobias at strongswan.org
Wed May 2 10:37:12 CEST 2018


Hi Christian,

> For the record, the IKE proposals that work for OSX and Windows (with
> weak or strong ciphers enabled) is as follows
>
> aes256-sha256-prfsha256-modp2048-modp1024

If you want to use a stronger DH group with Windows clients see [1].

Regards,
Tobias

[1]
https://wiki.strongswan.org/projects/strongswan/wiki/Windows7#AES-256-CBC-and-MODP2048


More information about the Users mailing list