<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: IPSec  PSK view over CLI. Possible? in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/ipsec-psk-view-over-cli-possible/m-p/148865#M49668</link>
    <description>&lt;P&gt;Nice and simple&amp;nbsp;answer! Thank you&lt;/P&gt;</description>
    <pubDate>Wed, 22 Mar 2017 13:48:38 GMT</pubDate>
    <dc:creator>TranceforLife</dc:creator>
    <dc:date>2017-03-22T13:48:38Z</dc:date>
    <item>
      <title>IPSec  PSK view over CLI. Possible?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ipsec-psk-view-over-cli-possible/m-p/148852#M49664</link>
      <description>&lt;P&gt;I guess the&amp;nbsp;answer is no, but is it possible to view PSK over the CLI in plain text or with the exported XML config?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks All,&lt;/P&gt;&lt;P&gt;Myky&lt;/P&gt;</description>
      <pubDate>Wed, 22 Mar 2017 13:34:13 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ipsec-psk-view-over-cli-possible/m-p/148852#M49664</guid>
      <dc:creator>TranceforLife</dc:creator>
      <dc:date>2017-03-22T13:34:13Z</dc:date>
    </item>
    <item>
      <title>Re: IPSec  PSK view over CLI. Possible?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ipsec-psk-view-over-cli-possible/m-p/148864#M49667</link>
      <description>&lt;P&gt;It's not.&lt;/P&gt;</description>
      <pubDate>Wed, 22 Mar 2017 13:47:11 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ipsec-psk-view-over-cli-possible/m-p/148864#M49667</guid>
      <dc:creator>santonic</dc:creator>
      <dc:date>2017-03-22T13:47:11Z</dc:date>
    </item>
    <item>
      <title>Re: IPSec  PSK view over CLI. Possible?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ipsec-psk-view-over-cli-possible/m-p/148865#M49668</link>
      <description>&lt;P&gt;Nice and simple&amp;nbsp;answer! Thank you&lt;/P&gt;</description>
      <pubDate>Wed, 22 Mar 2017 13:48:38 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ipsec-psk-view-over-cli-possible/m-p/148865#M49668</guid>
      <dc:creator>TranceforLife</dc:creator>
      <dc:date>2017-03-22T13:48:38Z</dc:date>
    </item>
    <item>
      <title>Re: IPSec  PSK view over CLI. Possible?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ipsec-psk-view-over-cli-possible/m-p/148880#M49674</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/10238"&gt;@santonic&lt;/a&gt;&amp;nbsp;a quick question actually. Unfrotunetluy l was not able to confirm as got no VPN tunnels running. Do you know&amp;nbsp;if PSK keys&amp;nbsp;are exported and imported when doing the&amp;nbsp;config migration between the different platforms?&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;thanks,&lt;/P&gt;&lt;P&gt;Myky&lt;/P&gt;</description>
      <pubDate>Wed, 22 Mar 2017 14:24:30 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ipsec-psk-view-over-cli-possible/m-p/148880#M49674</guid>
      <dc:creator>TranceforLife</dc:creator>
      <dc:date>2017-03-22T14:24:30Z</dc:date>
    </item>
    <item>
      <title>Re: IPSec  PSK view over CLI. Possible?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ipsec-psk-view-over-cli-possible/m-p/148882#M49675</link>
      <description>&lt;P&gt;They are in XML file so I'd say yes (tho i don't think i ever migrated them cross platforms).&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Exanple of PSK in XML:&lt;/P&gt;&lt;P&gt;&amp;lt;key&amp;gt;-AQ==MTmkWKuz1MeX9w6MmYSXGPbwbuU=OEFI/kxWUYPIkxWuSdtMgihZjdcoWnM11wIaPQpp3YM=&amp;lt;/key&amp;gt;&lt;/P&gt;</description>
      <pubDate>Wed, 22 Mar 2017 14:28:10 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ipsec-psk-view-over-cli-possible/m-p/148882#M49675</guid>
      <dc:creator>santonic</dc:creator>
      <dc:date>2017-03-22T14:28:10Z</dc:date>
    </item>
    <item>
      <title>Re: IPSec  PSK view over CLI. Possible?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ipsec-psk-view-over-cli-possible/m-p/149202#M49751</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/10238"&gt;@santonic&lt;/a&gt;&amp;nbsp;By any chance, you got some details about master key on PA and if that is in some way encrypt/hash the private key same as PSK. Or master key is irrelevant for PSK password encryption, or maybe it is exported with the configuration? l am just thinking how another device can read that hash password without the&amp;nbsp;key? (will mark your answer as a "solution" later) for now just want to bring the attention of others:0&lt;/P&gt;</description>
      <pubDate>Thu, 23 Mar 2017 17:05:54 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ipsec-psk-view-over-cli-possible/m-p/149202#M49751</guid>
      <dc:creator>TranceforLife</dc:creator>
      <dc:date>2017-03-23T17:05:54Z</dc:date>
    </item>
    <item>
      <title>Re: IPSec  PSK view over CLI. Possible?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ipsec-psk-view-over-cli-possible/m-p/149306#M49770</link>
      <description>&lt;P&gt;Good question. Unfortunately I don't know the answer.&lt;/P&gt;</description>
      <pubDate>Fri, 24 Mar 2017 06:42:45 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ipsec-psk-view-over-cli-possible/m-p/149306#M49770</guid>
      <dc:creator>santonic</dc:creator>
      <dc:date>2017-03-24T06:42:45Z</dc:date>
    </item>
    <item>
      <title>Re: IPSec  PSK view over CLI. Possible?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ipsec-psk-view-over-cli-possible/m-p/151057#M50064</link>
      <description>&lt;P&gt;Heys,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;l am back with some updates on this, more FYI. We had a case opened with TAC for a similar issue. So default master key on PA indeed doing encryption (not hashing, as it is one-way process you cannot apply the&amp;nbsp;key and get re-hash) of all plain text passwords and private cert keys etc. The default key is the same across all platforms. If you exporting/importing the config between the devices with the&amp;nbsp;different master keys (as you have an option to generate a new key) you will get an error (some complaints about mismatch). Simple advice - do not change the key as it can lead to further issue if you want to manage the devices with Panorama. &amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 04 Apr 2017 14:02:23 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ipsec-psk-view-over-cli-possible/m-p/151057#M50064</guid>
      <dc:creator>TranceforLife</dc:creator>
      <dc:date>2017-04-04T14:02:23Z</dc:date>
    </item>
  </channel>
</rss>

