Hi,
We have configured password policy for both admin and ipsec preshared key as below
conf system password-policy
set apply-to admin-password ipsec-preshared-key
set expire-day 90
set expire-status enable
Now the strange behaviour is, after 90 days we really didnt get any notification about ipsec preshared key expired neither IPSEC tunnel went down. We tried shutting down the ipsec tunnel and still the old key was working. There is no clear documentation about this in fortinet public document..
This is working fine for admin-password where after 90 days, its prompting to change the password. With this scenario, can we assume that this password expiration is applicable only for admin password and not for ipsec preshared key??.. Please clarify it..
Regards
Raja
Solved! Go to Solution.
Hi @rajamanickam ,
The expiry setting you configured effectively governs only administrator logins; IPsec pre-shared keys will not expire or tear down the tunnel unless you manually change them. Quick summary – IPsec PSK vs. password-policy expiry:
BR.
If my answer provided a solution for you, please mark the reply as solved it so that others can get it easily while searching for similar scenarios.
CCIE #68781
Hi @rajamanickam ,
The expiry setting you configured effectively governs only administrator logins; IPsec pre-shared keys will not expire or tear down the tunnel unless you manually change them. Quick summary – IPsec PSK vs. password-policy expiry:
BR.
If my answer provided a solution for you, please mark the reply as solved it so that others can get it easily while searching for similar scenarios.
CCIE #68781
Hello Atakan Atak, Thank you for your explanation. It really makes logical as well.
I would strongly recommend to fortinet team on explicitly mention this in their documents to avoid any confusion
Thanks again..
Regards
Raja
User | Count |
---|---|
2570 | |
1364 | |
796 | |
651 | |
455 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.