As I was testing with PFS "off", I thought to myself "Perphaps they configured more groups except PFS 19" and I just tried with PFS group 14 and I think I was right. They told me 19 but 14 seems to exist, too. As far as I can tell, it works with 14 as expected, after 1 hour the rekey starts and seems to work fine. The MTU is not too big and a new child_sa is created.
Apr 13 19:19:32 charon 06[CHD] <con4000|30> CHILD_SA con4000{1584} state change: INSTALLING => INSTALLED
Apr 13 19:19:32 charon 06[IKE] <con4000|30> CHILD_SA con4000{1584} established with SPIs c25045b2_i 495408d7_o and TS 10.207.239.61/32|192.168.1.0/24 === 10.11.0.0/11|/0
Apr 13 19:19:32 charon 06[CHD] <con4000|30> SPI 0x495408d7, src 213.34.11.17 dst 185.121.192.8
Apr 13 19:19:32 charon 06[CHD] <con4000|30> adding outbound ESP SA
Apr 13 19:19:32 charon 06[CHD] <con4000|30> SPI 0xc25045b2, src 185.121.192.8 dst 213.34.11.17
Apr 13 19:19:32 charon 06[CHD] <con4000|30> adding inbound ESP SA
Apr 13 19:19:32 charon 06[CHD] <con4000|30> using HMAC_SHA2_256_128 for integrity
Apr 13 19:19:32 charon 06[CHD] <con4000|30> using AES_CBC for encryption
Apr 13 19:19:32 charon 06[CHD] <con4000|30> CHILD_SA con4000{1584} state change: CREATED => INSTALLING
Apr 13 19:19:32 charon 06[CFG] <con4000|30> config: 10.11.0.0/11|/0, received: 10.11.0.0/11|/0 => match: 10.11.0.0/11|/0
Apr 13 19:19:32 charon 06[CFG] <con4000|30> selecting traffic selectors for other:
Apr 13 19:19:32 charon 06[CFG] <con4000|30> config: 10.207.239.61/32|192.168.1.0/24, received: 10.207.239.61/32|/0 => match: 10.207.239.61/32|192.168.1.0/24
Apr 13 19:19:32 charon 06[CFG] <con4000|30> selecting traffic selectors for us:
Apr 13 19:19:32 charon 06[CFG] <con4000|30> selected proposal: ESP:AES_CBC_256/HMAC_SHA2_256_128/MODP_2048/NO_EXT_SEQ
Apr 13 19:19:32 charon 06[CFG] <con4000|30> configured proposals: ESP:AES_CBC_256/HMAC_SHA2_256_128/MODP_2048/NO_EXT_SEQ
Apr 13 19:19:32 charon 06[CFG] <con4000|30> received proposals: ESP:AES_CBC_256/HMAC_SHA2_256_128/MODP_2048/NO_EXT_SEQ
Apr 13 19:19:32 charon 06[CFG] <con4000|30> proposal matches
Apr 13 19:19:32 charon 06[CFG] <con4000|30> selecting proposal:
Apr 13 19:19:32 charon 06[IKE] <con4000|30> received ESP_TFC_PADDING_NOT_SUPPORTED, not using ESPv3 TFC padding
Apr 13 19:19:32 charon 06[IKE] <con4000|30> received NON_FIRST_FRAGMENTS_ALSO notify
Apr 13 19:19:32 charon 06[IKE] <con4000|30> received ESP_TFC_PADDING_NOT_SUPPORTED notify
Apr 13 19:19:32 charon 06[ENC] <con4000|30> parsed CREATE_CHILD_SA response 2 [ SA No KE TSi TSr N(ESP_TFC_PAD_N) N(NON_FIRST_FRAG) ]
Apr 13 19:19:32 charon 06[NET] <con4000|30> received packet: from 185.121.192.8[500] to 213.34.11.17[500] (480 bytes)
Apr 13 19:19:32 charon 06[NET] <con4000|30> sending packet: from 213.34.11.17[500] to 185.121.192.8[500] (480 bytes)
Apr 13 19:19:32 charon 06[ENC] <con4000|30> generating CREATE_CHILD_SA request 2 [ N(ESP_TFC_PAD_N) SA No KE TSi TSr ]
Apr 13 19:19:32 charon 06[IKE] <con4000|30> establishing CHILD_SA con4000{1584} reqid 70
Apr 13 19:19:32 charon 06[CFG] <con4000|30> configured proposals: ESP:AES_CBC_256/HMAC_SHA2_256_128/MODP_2048/NO_EXT_SEQ
Apr 13 19:19:32 charon 06[CFG] <con4000|30> 10.11.0.0/11|/0
Apr 13 19:19:32 charon 06[CFG] <con4000|30> proposing traffic selectors for other:
Apr 13 19:19:32 charon 06[CFG] <con4000|30> 10.207.239.61/32|192.168.1.0/24
Apr 13 19:19:32 charon 06[CFG] <con4000|30> proposing traffic selectors for us:
Apr 13 19:19:32 charon 06[IKE] <con4000|30> activating CHILD_CREATE task
Apr 13 19:19:32 charon 06[IKE] <con4000|30> activating new tasks
I'll let it run through the night to see if it works but I'm pretty confident that it will. I don't know why PFS group 19 raises this problems I described above but if it works with 14, this should be a problem for another day.