- CheckMates
- :
- Products
- :
- Quantum
- :
- Remote Access VPN
- :
- Re: Pre-Share Keys CMD CLISH
- Subscribe to RSS Feed
- Mark Topic as New
- Mark Topic as Read
- Float this Topic for Current User
- Bookmark
- Subscribe
- Mute
- Printer Friendly Page
Are you a member of CheckMates?
×- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Pre-Share Keys CMD CLISH
Hi,
does anyone the CMD to see the vpn Pre-Share Keys in Checkpoint?
In Fortinet the PSK is saved in the config File like:
set remote-gw 77.56.199.43
set psksecret ENC Sqjxee+N3ZaTG2lL..........wa27N+XALaSxVQ==
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
As far as I know, no such command exists.
If you don't know what it is, you have to reset it, per this SK:
Is it possible to recover the VPN pre-shared secrets, if they are unknown?
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
I can assure you the shared VPN key will NOT appear in /config/active as that contains OS config only, nothing related to firewall, VPN, or Threat Prevention.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
As Dameon wrote, there is an sk about that - sk92561 Is it possible to recover the VPN pre-shared secrets, if they are unknown? In older (<R75.40) version dashboard, the PSK entry was unmasked and readable, but that has been changed for good! I assume that even using GuiDBedit to search a known PSK in the database would not yield any success... At least it should not .
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
The unencrypted pre-shared key is needed to establish the VPN. Therefor it must be stored somewhere on the CP FW in a reversible format.
The question is, where is it stored, and how is it decrypted?
Any claim that it cannot be recovered is just security by obscurity ....
