Enabling this option ensures Perfect Forward Secrecy takes place during the IPsec key exchanges. PFS significantly enhances the security of the VPN, so you should only disable this when you encounter a client who does not support it.
If in doubt, leave this option enabled.