I am now planning to deploy IPSec VPN to laptops and I have the application packaged and the IPSec configuration deployed to the registry. The problem I am having now is with the Preshared Key.... I cannot deploy that via GPO and I can't enter that manually on every computer. How you guys handling this?
Dear @samata ,
As far as i know , There is no documented way to inject a PSK via GPO/registry because FortiClient expects it from the profile source (EMS (if deployed) or local config).
So you can either go for EMS deployment or configure it locally (manually) or using XML backups. You can also explore using certificates instead of PSKs if possible.
Best regards.
Hello,
First you configure one FortiClient and then export it’s configuration. Take XML file and make any further customizations. Use the GPO to install this XML file on each machine by running this command:
"C:\Program Files (x86)\ Fortinet\Forticlient\fcconfig.exe"
Jathin Jayakumar
I'm not 100% sure but I don't think PSK or other password can be deployed via this method, because for security reasons FCT's PSK or password encryption is client dependent and can't be decrypted on another client (as far as I remember).
| User | Count |
|---|---|
| 2910 | |
| 1451 | |
| 850 | |
| 825 | |
| 455 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2026 Fortinet, Inc. All Rights Reserved.