How Do I Ensure That Preshared Keys Match on Phase 1 Configuration?
Knowledge Base ID: KB4408
Version: 3.0
Published: 07 Oct 2008
Updated: 07 Oct 2008
Categories: . NS-5GT
. NS-5XP
. NS-5XT
. NS-25
. NS-50
. NS-204
. NS-208
. NS-5200
. NS-5400
. IPSec

Synopsis:
How Do I Ensure That Preshared Keys Match on Phase 1 Configuration?

Problem:

Solution:

Note: This article applies to ScreenOS 4.0 and higher.

The best way to make sure that the preshared keys match is to re-enter them on both NetScreen devices.

To ensure that the preshared keys match on the phase 1 configuration, perform the following steps:

Open the WebUI. For more information on accessing the WebUI, go to Accessing Your NetScreen Using the WebUI.

From the NetScreen options menu, click VPNs, select AutoKey Advanced, and then click Gateway.

Image of step two


Locate the VPN gateway, and then click Edit.

Image of step three


In the Preshared Key text box, enter the preshared key.

Image of step four and five


Click OK.

Connect to the other NetScreen device, and repeat Step 2 through Step 5.

Purpose:
Troubleshooting