Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
samata
New Contributor

IPSec VPN for laptops

I am now planning to deploy IPSec VPN to laptops and I have the application packaged and the IPSec configuration deployed to the registry. The problem I am having now is with the Preshared Key.... I cannot deploy that via GPO and I can't enter that manually on every computer. How you guys handling this?

3 REPLIES 3
AEH
New Contributor III

Dear @samata ,

As far as i know , There is no documented way to inject a PSK via GPO/registry because FortiClient expects it from the profile source (EMS (if deployed) or local config).

So you can either go for EMS deployment or configure it locally (manually) or using XML backups. You can also explore using certificates instead of PSKs if possible.

 

Best regards.

AEH.
AEH.
eng_jathin
New Contributor

Hello,

First you configure one FortiClient and then export it’s configuration. Take XML file and make any further customizations. Use the GPO to install this XML file on each machine by running this command:

"C:\Program Files (x86)\ Fortinet\Forticlient\fcconfig.exe"

 

 

Jathin Jayakumar

Sr. Network Engineer | Fortinet NSE4/FCP, Cybersecurity
Sr. Network Engineer | Fortinet NSE4/FCP, Cybersecurity
AEK

I'm not 100% sure but I don't think PSK or other password can be deployed via this method, because for security reasons FCT's PSK or password encryption is client dependent and can't be decrypted on another client (as far as I remember).

AEK
AEK
Announcements
Check out our Community Chatter Blog! Click here to get involved
Labels
Top Kudoed Authors