How can I extract the IKEv2 encryption keys SK_ei and SK_er on PAN-OS 11.2?

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Announcements

Content translations are temporarily unavailable due to site maintenance. We apologize for any inconvenience. Visit our blog to learn more.

How can I extract the IKEv2 encryption keys SK_ei and SK_er on PAN-OS 11.2?

L1 Bithead

How can I extract the IKEv2 encryption keys SK_ei and SK_er on PAN-OS 11.2 (for the purpose of decoding a packet capture file in Wireshark)?

 

The following article describes the procedure:

https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000PLMzCAO

 

This worked fine on PAN-OS 11.1. 

 

But it does not seem to work on PAN-OS 11.2 anymore, because the necessary log messages no longer appear in the log file (in fact, it seems that [INFO] and [DEBUG] message are no longer logged, only [DUMP] messages are logged, regardless of what the debug level is set to)

1 REPLY 1

Community Team Member

Hi @brunor ,

 

I would recommend reaching out to support and sharing the details of your findings on this one. 

 

LIVEcommunity team member
Stay Secure,
Jay
Don't forget to Like items if a post is helpful to you!

Please help out other users and “Accept as Solution” if a post helps solve your problem !

Read more about how and why to accept solutions.
  • 172 Views
  • 1 replies
  • 0 Likes
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!