the feature “multiple DH groups for phase 1” introduced with version 6.34 is still missing in the Winbox configuration. i can select only one through the GUI. But you can set multiple DH Groups through the console.
Probably an experimental option. Not sure if it is a good experiment, other implementations I know do not support this
so I presume there is a protocol standards issue.
Yes, but in the documentation of e.g. racoon on Linux, where you could configure this, it warns that this is not
going to work. I guess there is something in the protocol or in existing implementations that might cause problems.
Maybe a trick was found to work around this. (like alternating these settings on subsequent sessions until one works)
Winbox support for this new feature is already added (v6.35.2 definitely have it).
It works as nz_monkey stated, picked one from the set of supported DH groups. Also note that whenever possible strongest will be used first.
Feature was added to support as many devices as possible in road warrior setups, because recent windows phones works only with 2048, but iphones only with 1024.