You have much more options for tuning and compatibility when directly editing your configuration. And with those directories, configuration is preserved during updates.
See here for tutorial and samples:https://forum.opnsense.org/index.php?topic=12147.0
Did you add the registry option to enable 2048 bits? Else add aes128-sha256-modp1048 to ciphers