The CNSSP 15 compliant algorithms suggested by the NSA are as follows of IKE:
DH Group 16,
And for IPSec:
Currently the Digi's with FW 188.8.131.52 only support:
DH Group 14,
AES 256 ----good
Is there going to be FW update to bump these up?