Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
MsComX
New Contributor

Pre-shared-key for VPN Site-To-Site

Hello guys !

I'm new to the VPN environnement, and trying to configure a site-to-site VPN tunnel between two Fortigate 60D.

At the step "Pre-shared-key", I don't know if it's a specific key to the device (in that case where can i find it ?) or it's a secret word that i can randomly create and share between the two fortigates.

I know that the PSK must be shared before any login/pasword authentification, but my question is:

Where to get the PSK from ? Or I can create it myself ?

 

Thanks !

2 Solutions
Markus
Valued Contributor

Hi, Welcome to the Forums. You can create the PSK for your self and share between the FGs. https://docs.fortinet.com...pn-with-two-fortigates Best


________________________________________________________
--- NSE 4 ---
________________________________________________________

View solution in original post

________________________________________________________--- NSE 4 ---________________________________________________________
sw2090

yep psk is a secret word of your choice ;)

So go ahead and choose one. It just has to be the same on both FGT....

-- 

"It is a mistake to think you can solve any major problems just with potatoes." - Douglas Adams

View solution in original post

-- "It is a mistake to think you can solve any major problems just with potatoes." - Douglas Adams
4 REPLIES 4
Markus
Valued Contributor

Hi, Welcome to the Forums. You can create the PSK for your self and share between the FGs. https://docs.fortinet.com...pn-with-two-fortigates Best


________________________________________________________
--- NSE 4 ---
________________________________________________________

________________________________________________________--- NSE 4 ---________________________________________________________
sw2090

yep psk is a secret word of your choice ;)

So go ahead and choose one. It just has to be the same on both FGT....

-- 

"It is a mistake to think you can solve any major problems just with potatoes." - Douglas Adams

-- "It is a mistake to think you can solve any major problems just with potatoes." - Douglas Adams
MsComX
New Contributor

Got it !

Thanks for answering.

emnoc
Esteemed Contributor III

As far as creating one you can do this with bash or perl, of just use a online generator 

 

https://www.ifm.net.nz/cookbooks/IPSec-Pre-shared-Key-PSK-Generator.html

 

 

Ken Felix

PCNSE 

NSE 

StrongSwan  

PCNSE NSE StrongSwan
Announcements

Select Forum Responses to become Knowledge Articles!

Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.

Labels
Top Kudoed Authors