vpn: Only use AES GCM for Phase 2

Per [1] this does not seem to be supported in IKEv1 Phase 1.  Specifying
it causes strongSwan to quietly send a malformed proposal, which breaks
interop with older clients.

[1] https://wiki.strongswan.org/projects/1/wiki/CipherSuiteExamples

BUG=chromium:707139
TEST=manually connect to Sophos VPN

Change-Id: I6a7dff956659cccab53ca8a78f43852fbdfe8e4b
Reviewed-on: https://chromium-review.googlesource.com/487738
Commit-Ready: Kevin Cernekee <[email protected]>
Tested-by: Kevin Cernekee <[email protected]>
Reviewed-by: Mattias Nissler <[email protected]>
Reviewed-by: Maksim Ivanov <[email protected]>
(cherry picked from commit c48ff6b7ff70a14e3538d7742ab25401ebcc5935)
Reviewed-on: https://chromium-review.googlesource.com/490691
Reviewed-by: Kevin Cernekee <[email protected]>
Commit-Queue: Kevin Cernekee <[email protected]>
1 file changed