<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: how to View  Pre-Shared key in PA in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/how-to-view-pre-shared-key-in-pa/m-p/349266#M86822</link>
    <description>&lt;P&gt;as &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/43480"&gt;@BPry&lt;/a&gt;&amp;nbsp;said, but to verifiy if there is a mismatch you can use this command in CLI:&lt;/P&gt;&lt;PRE&gt;&lt;SPAN&gt;less mp-log ikemgr.log&lt;/SPAN&gt;&lt;/PRE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Tue, 15 Sep 2020 06:28:19 GMT</pubDate>
    <dc:creator>Abdul-Fattah</dc:creator>
    <dc:date>2020-09-15T06:28:19Z</dc:date>
    <item>
      <title>how to View  Pre-Shared key in PA</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/how-to-view-pre-shared-key-in-pa/m-p/349245#M86819</link>
      <description>&lt;P&gt;i'm have issues with IPSEC Tunnel which is configured by another engineer. currently facing issues with Tunnel connectivity and i need to cross verify the parameters. So can someone guide how to heck pre shared key in plain text format&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/6681"&gt;@IPSec&lt;/a&gt;&amp;nbsp;&lt;LI-MESSAGE title="IPSec S2S VPN between Palo Alto and 3rd party Security FW Vendor -&amp;amp;gt; ISAKMP Negotiation" uid="241280" url="https://live.paloaltonetworks.com/t5/general-topics/ipsec-s2s-vpn-between-palo-alto-and-3rd-party-security-fw-vendor/m-p/241280#U241280" discussion_style_icon_css="lia-mention-container-editor-message lia-img-icon-forum-thread lia-fa-icon lia-fa-forum lia-fa-thread lia-fa"&gt;&lt;/LI-MESSAGE&gt;&amp;nbsp;&lt;LI-MESSAGE title="Question regarding site to site VPN" uid="39217" url="https://live.paloaltonetworks.com/t5/general-topics/question-regarding-site-to-site-vpn/m-p/39217#U39217" discussion_style_icon_css="lia-mention-container-editor-message lia-img-icon-forum-thread lia-fa-icon lia-fa-forum lia-fa-thread lia-fa"&gt;&lt;/LI-MESSAGE&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 14 Sep 2020 22:13:31 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/how-to-view-pre-shared-key-in-pa/m-p/349245#M86819</guid>
      <dc:creator>iamvivekms</dc:creator>
      <dc:date>2020-09-14T22:13:31Z</dc:date>
    </item>
    <item>
      <title>Re: how to View  Pre-Shared key in PA</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/how-to-view-pre-shared-key-in-pa/m-p/349263#M86820</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/141009"&gt;@iamvivekms&lt;/a&gt;,&lt;/P&gt;
&lt;P&gt;This isn't possible. You can't go back and get the clear text value for anything in the configuration when it comes to passwords, pre-shared keys or anything of the sort. The firewall simply stores hash or encrypted form of the value.&lt;/P&gt;</description>
      <pubDate>Tue, 15 Sep 2020 03:34:25 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/how-to-view-pre-shared-key-in-pa/m-p/349263#M86820</guid>
      <dc:creator>BPry</dc:creator>
      <dc:date>2020-09-15T03:34:25Z</dc:date>
    </item>
    <item>
      <title>Re: how to View  Pre-Shared key in PA</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/how-to-view-pre-shared-key-in-pa/m-p/349266#M86822</link>
      <description>&lt;P&gt;as &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/43480"&gt;@BPry&lt;/a&gt;&amp;nbsp;said, but to verifiy if there is a mismatch you can use this command in CLI:&lt;/P&gt;&lt;PRE&gt;&lt;SPAN&gt;less mp-log ikemgr.log&lt;/SPAN&gt;&lt;/PRE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 15 Sep 2020 06:28:19 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/how-to-view-pre-shared-key-in-pa/m-p/349266#M86822</guid>
      <dc:creator>Abdul-Fattah</dc:creator>
      <dc:date>2020-09-15T06:28:19Z</dc:date>
    </item>
    <item>
      <title>Re: how to View  Pre-Shared key in PA</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/how-to-view-pre-shared-key-in-pa/m-p/349342#M86841</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/129900"&gt;@Abdul-Fattah&lt;/a&gt;&amp;nbsp;, you will see "pre-share mismatch" only if the remote site is initiator of the tunnel negotiation and you are receiver. If you are the initiator you will only see "IKE phase1 timeout" message in the logs. This is caused by the nature of the IPsec&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 15 Sep 2020 13:37:31 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/how-to-view-pre-shared-key-in-pa/m-p/349342#M86841</guid>
      <dc:creator>A_Astardzhiev</dc:creator>
      <dc:date>2020-09-15T13:37:31Z</dc:date>
    </item>
    <item>
      <title>Re: how to View  Pre-Shared key in PA</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/how-to-view-pre-shared-key-in-pa/m-p/349363#M86847</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/141009"&gt;@iamvivekms&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;If you see in logs as&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/70130"&gt;@A_Astardzhiev&lt;/a&gt;&amp;nbsp; mentioned then best thing is to have new key on both ends.&lt;/P&gt;
&lt;P&gt;Unless you can get the Pre-Shared key from other side of the connection.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Regards&lt;/P&gt;</description>
      <pubDate>Tue, 15 Sep 2020 14:24:04 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/how-to-view-pre-shared-key-in-pa/m-p/349363#M86847</guid>
      <dc:creator>MP18</dc:creator>
      <dc:date>2020-09-15T14:24:04Z</dc:date>
    </item>
    <item>
      <title>Re: how to View  Pre-Shared key in PA</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/how-to-view-pre-shared-key-in-pa/m-p/349399#M86849</link>
      <description>&lt;P&gt;Thanks guys for your response...what i understand is that we have very limited options in Paloalto in terms of troubleshooting Tunnel down issues.. So i can go ahead and reconfigure Pre-shared key and test again.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Appreciated Everyone for your response !!&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/43480"&gt;@BPry&lt;/a&gt;&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/129900"&gt;@Abdul-Fattah&lt;/a&gt;&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/75039"&gt;@MP18&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 15 Sep 2020 15:32:11 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/how-to-view-pre-shared-key-in-pa/m-p/349399#M86849</guid>
      <dc:creator>iamvivekms</dc:creator>
      <dc:date>2020-09-15T15:32:11Z</dc:date>
    </item>
    <item>
      <title>Re: how to View  Pre-Shared key in PA</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/how-to-view-pre-shared-key-in-pa/m-p/349449#M86859</link>
      <description>&lt;P&gt;Hey &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/141009"&gt;@iamvivekms&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I cannot agree with your statement&amp;nbsp; - "&lt;SPAN&gt;we have very limited options in Paloalto in terms of troubleshooting Tunnel down issues"&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;It is quite the opposite:&lt;/SPAN&gt;&lt;/P&gt;&lt;OL&gt;&lt;LI&gt;&lt;SPAN&gt;1. Palo Alto is not the only vendor that does not store pre-shared key in plain text. It is actually way better to do it this way rather have it in plain text just because you lack proper documentation. Having the psk in plain-text for troubleshooting is like having your password written on sticky note on your monitor in case you forgot it...&amp;nbsp;&lt;/SPAN&gt;&lt;/LI&gt;&lt;LI&gt;&lt;SPAN&gt;Palo Alto firewall provides you several ways to troubleshoot IPsec tunnel. PAN is actually my favorite vendor for IPsec troubleshooting as it has excellent document and easy to use tools/commands.&lt;/SPAN&gt;&lt;OL&gt;&lt;LI&gt;You can check here for commands that you can use for debug/troubleshooting -&amp;nbsp;&lt;A href="https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClivCAC" target="_blank"&gt;https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClivCAC&lt;/A&gt;&lt;/LI&gt;&lt;LI&gt;If you have multiple tunnels configured on your firewall it is recommended to enable tunnel debug only for specific peer -&amp;nbsp;&lt;A href="https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClcKCAS" target="_blank"&gt;https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClcKCAS&lt;/A&gt;&lt;/LI&gt;&lt;LI&gt;You could also be useful for you -&amp;nbsp;&lt;A href="https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000PORsCAO" target="_blank"&gt;https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000PORsCAO&lt;/A&gt;&lt;/LI&gt;&lt;/OL&gt;&lt;/LI&gt;&lt;LI&gt;You need to remember that &lt;U&gt;the receiver of the tunnel negotiation&lt;/U&gt; will log the actual reason for negotiation failure. So if you want to troubleshoot the tunnel at your end (on the Palo) you can "enable passive mode" under the IKE Gateway -&amp;gt; Advance options. This will force your firewall to only act as receiver and never as initiator for this peer. I believe Palo Alto TAC recommend this option only during t-shoot as it will cause traffic drop if your fw receive traffic that needs to be sent over the tunnel, but it is not established yet.&lt;/LI&gt;&lt;/OL&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Wrong PSK is the most common mistake when configuring new tunnel so my suggest in this case is:&lt;/P&gt;&lt;P&gt;1. Re-Enter the psk again at your end of the tunnel.&amp;nbsp;&lt;/P&gt;&lt;P&gt;2. Re-enter the psk at remote end of the tunnel&lt;/P&gt;&lt;P&gt;3. Agree on new psk&lt;/P&gt;</description>
      <pubDate>Tue, 15 Sep 2020 18:22:13 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/how-to-view-pre-shared-key-in-pa/m-p/349449#M86859</guid>
      <dc:creator>A_Astardzhiev</dc:creator>
      <dc:date>2020-09-15T18:22:13Z</dc:date>
    </item>
  </channel>
</rss>

