Hi all,
We don't have EMS and I've managed to push out a new IPSEC connection to the machines via group policy but obviously as the pre-shared key is encrypted it then creates a random one on each machine so has anyone found a way to do this using group policy at all. We are using the free VPN from Fortinet and not the Windows native one.
Thanks
you might try and do a import of xml configuration from a existing working one via cli ( script it ) of the VPN Profile with the necessary settings
I saw someone else say that but is this the "backup" config you mean (as that comes out as a .conf file) and then convert that to an XML or is there a way to export it as an XML to begin with?
Got it, that's imported the settings but they key is still wrong... there is a "preshared_key" line on the XML with a long string starting ENCx and then \preshared_key at the end but it doesn't look as though i can just put the pre-shared key in here instead unless i'm adding it wrong on here ?
Created on 08-28-2025 05:52 AM Edited on 08-28-2025 05:52 AM
it means that its encrypted, the FortiClient will pass on the correct/cleartext one if it was typed correctly, to the FortiGate.
When you say "pass on" do you mean that i should be able to put it in the XML and import it or do you mean if I then manually edit the connection within FortiClient AFTER it's imported ?
Thanks
User | Count |
---|---|
2534 | |
1351 | |
795 | |
641 | |
455 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.