Hi I must build up an IPSEC tunel between PA and Watchguard XTM. The other Side gives me ike phase where DH Group is 15. On PA I only can choose Group 1—768 bits, Group 2—1024 bits (default), Group 5—1536 bits, Group 14—2048 bits, Group 19—256-bit elliptic curve group, and Group 20—384-bit elliptic curve group Is there a way to build up a "custom" DH Group or must the otherside set the DH Group to a value that my PA side can work with? https://www.watchguard.com/help/docs/fireware/12/en-US/Content/en-US/bovpn/manual/diffie_hellman_c.html https://www.paloaltonetworks.com/documentation/80/pan-os/pan-os/vpns/site-to-site-vpn-concepts/internet-key-exchange-ike-for-vpn/ike-phase-1
... View more