Skip to main content
Anand_Narayana
Explorer
August 21, 2010
Question

How to view Pre-shared Key

  • August 21, 2010
  • 5 replies
  • 13533 views
Hi, I have setup a site-to-site vpn between 2 FG. I wanted to view the pre-shared key of the vpn tunnel. Is there any way to view that similar to cisco pix/asa?

    5 replies

    ede_pfau
    SuperUser
    SuperUser
    August 21, 2010
    Not that I know of. Not even in the config file. Wouldn' t make sense anyway. What about this option with Cisco - wouldn' t they see this as a massive security breach?
    Anand_Narayana
    Explorer
    August 22, 2010
    In Cisco, there is no way to view the pre-shared using the config file, but can be viewed by typing " more:system run" command in CLI through which the pre-shared key can be viewed. Similarly just wanting to know that in FG. Reason to know this is my x-colleague has created several tunnels on the FG & he has updated me only few of the pre-shared keyz the rest he doesn' t have any clues as what the keys might be.
    Carl_Wallmark
    New Member
    August 22, 2010
    you cant view the preshared key, but you can copy them,
    Anand_Narayana
    Explorer
    August 24, 2010
    How to copy then?
    emnoc
    New Member
    August 23, 2010
    If you forgot the PSK, just recreate them on the FG. Cisco gives you the luxury to more the PSK out starting with PIX/ASA code 6.5 and higher and the keys are in plaintext if you should copy the config thru tftp.
    ede_pfau
    SuperUser
    SuperUser
    August 24, 2010
    Just copy the hashes from the config file, strings starting with " ENC" . That is, from a config file which itself is un-encrypted = plain text.