<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Pre-Share Keys CMD CLISH in SASE and Remote Access</title>
    <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Pre-Share-Keys-CMD-CLISH/m-p/66733#M13938</link>
    <description>&lt;P&gt;The unencrypted pre-shared key is needed to establish the VPN.&amp;nbsp; Therefor it must be stored somewhere on the CP FW in a reversible format.&lt;/P&gt;&lt;P&gt;The question is, where is it stored, and how is it decrypted?&lt;/P&gt;&lt;P&gt;Any claim that it cannot be recovered is just security by obscurity ....&lt;/P&gt;</description>
    <pubDate>Thu, 07 Nov 2019 03:46:51 GMT</pubDate>
    <dc:creator>thallam08</dc:creator>
    <dc:date>2019-11-07T03:46:51Z</dc:date>
    <item>
      <title>Pre-Share Keys CMD CLISH</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Pre-Share-Keys-CMD-CLISH/m-p/33686#M13933</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;&lt;SPAN style="color: #333333; background-color: #ffffff;"&gt;Hi, &amp;nbsp; &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #333333; background-color: #ffffff;"&gt;does anyone the CMD to see the vpn Pre-Share Keys in Checkpoint?&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #333333; background-color: #ffffff;"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #333333; background-color: #ffffff;"&gt;In Fortinet the PSK is saved in the config File like:&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #333333; background-color: #ffffff;"&gt;set remote-gw 77.56.199.43 &lt;BR /&gt;set psksecret ENC Sqjxee+N3ZaTG2lL..........wa27N+XALaSxVQ==&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 04 Mar 2018 14:33:18 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Pre-Share-Keys-CMD-CLISH/m-p/33686#M13933</guid>
      <dc:creator>jessica_stanson</dc:creator>
      <dc:date>2018-03-04T14:33:18Z</dc:date>
    </item>
    <item>
      <title>Re: Pre-Share Keys CMD CLISH</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Pre-Share-Keys-CMD-CLISH/m-p/33687#M13934</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;As far as I know, no such command exists.&lt;/P&gt;&lt;P&gt;If you don't know what it is, you have to reset it, per this SK:&lt;/P&gt;&lt;P&gt;&lt;A class="link-titled" href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk92561" title="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk92561"&gt;Is it possible to recover the VPN pre-shared secrets, if they are unknown?&lt;/A&gt;&amp;nbsp;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 04 Mar 2018 17:40:21 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Pre-Share-Keys-CMD-CLISH/m-p/33687#M13934</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2018-03-04T17:40:21Z</dc:date>
    </item>
    <item>
      <title>Re: Pre-Share Keys CMD CLISH</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Pre-Share-Keys-CMD-CLISH/m-p/33688#M13935</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;DIV style="color: #222222; font-size: small;"&gt;Hi Dameon,&lt;/DIV&gt;&lt;DIV style="color: #222222; font-size: small;"&gt; &lt;/DIV&gt;&lt;DIV style="color: #222222; font-size: small;"&gt;thanks for your reply.&lt;/DIV&gt;&lt;DIV style="color: #222222; font-size: small;"&gt; &lt;/DIV&gt;&lt;DIV style="color: #222222; font-size: small;"&gt;Maybe in the active connections?&lt;/DIV&gt;&lt;DIV style="color: #222222; font-size: small;"&gt; &lt;/DIV&gt;&lt;DIV style="color: #222222; font-size: small;"&gt;&lt;STRONG style="font-size: 13px;"&gt;&lt;EM&gt;grep radius /config/active&lt;/EM&gt;&lt;/STRONG&gt;&lt;/DIV&gt;&lt;DIV style="color: #222222; font-size: small;"&gt;&lt;SPAN style="font-size: 11px;"&gt;&lt;EM&gt;....&lt;/EM&gt;&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV style="color: #222222; font-size: small;"&gt;&lt;SPAN style="font-size: 11px;"&gt;&lt;EM&gt;aaa:auth_profile:base_radius_authprofile:radius_sr v:0:secret \ &lt;STRONG&gt;lDGLiWozsw&lt;/STRONG&gt;==&lt;/EM&gt;&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV style="color: #222222; font-size: small;"&gt;&lt;SPAN style="font-size: 11px;"&gt;&lt;EM&gt;.....&lt;/EM&gt;&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV style="color: #222222; font-size: small;"&gt;So instead of radius maybe vpn?&lt;/DIV&gt;&lt;DIV style="color: #222222; font-size: small;"&gt; &lt;/DIV&gt;&lt;DIV style="color: #222222; font-size: small;"&gt;&lt;STRONG&gt;&lt;EM&gt;grep vpn /config/active&lt;/EM&gt;&lt;/STRONG&gt;&lt;/DIV&gt;&lt;DIV style="color: #222222; font-size: small;"&gt; &lt;/DIV&gt;&lt;DIV style="color: #222222; font-size: small;"&gt;Finally i would search this in the CP Firewall with&amp;nbsp;&lt;/DIV&gt;&lt;DIV style="color: #222222; font-size: small;"&gt; &lt;/DIV&gt;&lt;DIV style="color: #222222; font-size: small;"&gt;find / -type f&amp;nbsp; -not -path "/var/log"&amp;nbsp; | xargs grep&amp;nbsp; -i "&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN style="color: #222222; background-color: #ffffff; font-size: small;"&gt;lDGLiWozsw==&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;" 2&amp;gt;&amp;amp;1 | grep -v "Permission denied"&amp;nbsp;&lt;/DIV&gt;&lt;DIV style="color: #222222; font-size: small;"&gt; &lt;/DIV&gt;&lt;DIV style="color: #222222; font-size: small;"&gt;Unfortunately, at the moment, i install a CP and i don"t&amp;nbsp; have a finished CP Installation to&lt;/DIV&gt;&lt;DIV style="color: #222222; font-size: small;"&gt;to see if this could find this key?&lt;/DIV&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 06 Mar 2018 08:55:46 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Pre-Share-Keys-CMD-CLISH/m-p/33688#M13935</guid>
      <dc:creator>jessica_stanson</dc:creator>
      <dc:date>2018-03-06T08:55:46Z</dc:date>
    </item>
    <item>
      <title>Re: Pre-Share Keys CMD CLISH</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Pre-Share-Keys-CMD-CLISH/m-p/33689#M13936</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I can assure you the shared VPN key will NOT appear in /config/active as that contains OS config only, nothing related to firewall, VPN, or Threat Prevention.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 06 Mar 2018 15:16:00 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Pre-Share-Keys-CMD-CLISH/m-p/33689#M13936</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2018-03-06T15:16:00Z</dc:date>
    </item>
    <item>
      <title>Re: Pre-Share Keys CMD CLISH</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Pre-Share-Keys-CMD-CLISH/m-p/33690#M13937</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;As Dameon wrote, there is an sk about that - &lt;A href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk92561" rel="nofollow"&gt;sk92561 Is it possible to recover the VPN pre-shared secrets, if they are unknown?&lt;/A&gt; In older (&amp;lt;R75.40) version dashboard, the PSK entry was unmasked and readable, but that has been changed for good! I assume that even using GuiDBedit to search a known PSK in the database would not yield any success... At least it should not &lt;IMG src="https://community.checkpoint.com/legacyfs/online/checkpoint/emoticons/wink.png" /&gt;.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 08 Mar 2018 08:07:37 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Pre-Share-Keys-CMD-CLISH/m-p/33690#M13937</guid>
      <dc:creator>G_W_Albrecht</dc:creator>
      <dc:date>2018-03-08T08:07:37Z</dc:date>
    </item>
    <item>
      <title>Re: Pre-Share Keys CMD CLISH</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Pre-Share-Keys-CMD-CLISH/m-p/66733#M13938</link>
      <description>&lt;P&gt;The unencrypted pre-shared key is needed to establish the VPN.&amp;nbsp; Therefor it must be stored somewhere on the CP FW in a reversible format.&lt;/P&gt;&lt;P&gt;The question is, where is it stored, and how is it decrypted?&lt;/P&gt;&lt;P&gt;Any claim that it cannot be recovered is just security by obscurity ....&lt;/P&gt;</description>
      <pubDate>Thu, 07 Nov 2019 03:46:51 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Pre-Share-Keys-CMD-CLISH/m-p/66733#M13938</guid>
      <dc:creator>thallam08</dc:creator>
      <dc:date>2019-11-07T03:46:51Z</dc:date>
    </item>
  </channel>
</rss>

