remote-access VPN: IPSec settings

I have configured a remote-access VPN using L2TP/IPSec. It works fine, but I’d like to force use of a certain encryption type. How can I do that? It seems VyOS accepts everything the vpn client proposes.

Is it possible to define IKE phase1 and phase2 proposals for this connection? Shouldn’t there be an option to assign ike-group and esp-group for the remote-access VPN?

thanks