Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
Not applicable

How to view the unencrypted PSK of a VPN

Hi all, we have an IPsec VPN to a client network and have forgotten (not documented yet) the PSK of the Phase 1 of VPN. How can I get the unencrypted value of PSK?
4 REPLIES 4
abelio
SuperUser
SuperUser

unless you' ve a sniffer in the wire to catch poor or very short PSK and try to desencrypt it and you' ve a lot of free time, you can' t

regards




/ Abel

regards / Abel
abelio

sorry, you don' t need a sniffer if you' ve admin passwd in FTG-box CLI command " show vpn ipsec phase1 <your_tunnel_number> " shows to you pksecret in encrypted form but, if you' ve Fortinet admin pass and Forticlient access, all this remains an academic exercise change your PSK

regards




/ Abel

regards / Abel
Not applicable

I know I can change the PSK. But in the other side our client is running FreeSwan and I cant' t manage it. I didn' t want to say it we have lost the PSK.
abelio

José, Then I repeat my first post unless you can beat yourself against des-encrypt something like 0rPUFsPLJ3fYgV7yQDYr9+KWgoklz3wA890OhOgO9HKb0AshweoLvXZSU0z/HqzlodXsCTKgH/AozjRnjqEkb2D44U9WYJ7q9iS4qReyvzK657Li (that is ' JoseGerez' string encrypted like a psksecret ENC Fortinet phase1 VPN) regards,

regards




/ Abel

regards / Abel
Announcements

Select Forum Responses to become Knowledge Articles!

Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.

Labels
Top Kudoed Authors