How can I change the IPsec tunnel preshared key? It can't be done in the gui. When I edit my tunnel and select the option for preshared key, the field key entry field doesn't appear like it does when creating a new tunnel. Is there a way to do this in the cli? So far I haven't found it.
Solved! Go to Solution.
Nominating a forum post submits a request to create a new Knowledge Article based on the forum post topic. Please ensure your nomination includes a solution within the reply.
Yes, it does.
From the cli, editing my tunnel in
config vpn ipsec phase1-interface
If I type "set psksecret" and a new key, will that replace the existing preshared key and encode it?
Yes it will.
Yes. it will.
Yes, it does.
Thanks guys.
With CLI you can even copy and paste the encrypted PSK (ENC) to other phase1-interface without knowing the original PSK. That's how we migrate IPSecs from one FG to another as long as the software version is the same or close enough.
Yes
Select Forum Responses to become Knowledge Articles!
Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.
User | Count |
---|---|
1662 | |
1077 | |
752 | |
446 | |
220 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2024 Fortinet, Inc. All Rights Reserved.