Hi Makarand, > Is the system behaving correctly? i.e. the DH group is used only during reneg after expiry of lifetime? Yes, see [1]. Regards, Tobias [1] https://wiki.strongswan.org/projects/strongswan/wiki/ExpiryRekey#IKEv2