Enhanced Security Measures in Place:   To ensure a safer experience, we’ve implemented additional, temporary security measures for all users.

IPSec PSK view over CLI. Possible?

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Announcements

IPSec PSK view over CLI. Possible?

L6 Presenter

I guess the answer is no, but is it possible to view PSK over the CLI in plain text or with the exported XML config?

 

Thanks All,

Myky

1 accepted solution

Accepted Solutions

They are in XML file so I'd say yes (tho i don't think i ever migrated them cross platforms).

 

Exanple of PSK in XML:

<key>-AQ==MTmkWKuz1MeX9w6MmYSXGPbwbuU=OEFI/kxWUYPIkxWuSdtMgihZjdcoWnM11wIaPQpp3YM=</key>

View solution in original post

7 REPLIES 7

L6 Presenter

It's not.

Nice and simple answer! Thank you

@santonic a quick question actually. Unfrotunetluy l was not able to confirm as got no VPN tunnels running. Do you know if PSK keys are exported and imported when doing the config migration between the different platforms? 

 

thanks,

Myky

They are in XML file so I'd say yes (tho i don't think i ever migrated them cross platforms).

 

Exanple of PSK in XML:

<key>-AQ==MTmkWKuz1MeX9w6MmYSXGPbwbuU=OEFI/kxWUYPIkxWuSdtMgihZjdcoWnM11wIaPQpp3YM=</key>

L6 Presenter

@santonic By any chance, you got some details about master key on PA and if that is in some way encrypt/hash the private key same as PSK. Or master key is irrelevant for PSK password encryption, or maybe it is exported with the configuration? l am just thinking how another device can read that hash password without the key? (will mark your answer as a "solution" later) for now just want to bring the attention of others:0

Good question. Unfortunately I don't know the answer.

Heys,

 

l am back with some updates on this, more FYI. We had a case opened with TAC for a similar issue. So default master key on PA indeed doing encryption (not hashing, as it is one-way process you cannot apply the key and get re-hash) of all plain text passwords and private cert keys etc. The default key is the same across all platforms. If you exporting/importing the config between the devices with the different master keys (as you have an option to generate a new key) you will get an error (some complaints about mismatch). Simple advice - do not change the key as it can lead to further issue if you want to manage the devices with Panorama.  

  • 1 accepted solution
  • 6822 Views
  • 7 replies
  • 0 Likes
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!