OK, we have existing connections up and running to a mix of remote network devices. Up till now everything has been rosy with our 28 character PSK, but we are trying to add a new device that has a limitation of a 24 character PSK. Astaro gives the impression from the new user interface, ie. 7.X that the PSK's are unique to each connection, but apparently that isn't the case.
Questions:
1) Exactly what is shared in terms of the PSK's? Do all PSK's have to match, or only the respond-only gateway PSK's? The email response we got from Astaro support is so unclear as to be useless.
2) Why didn't you stick with the 6.X interface that defined PSK's seperate from the VPN, so it would be obvious that are shared? Doh!
3) Why is a blinking field that doesn't accept input supposed to make me aware that I already have defined a PSK that can't be altered?
4) Are you really saying we have to modify all VPN's down to the lowest common denominator?
5) How does this promote ad-hoc network management and backup? Those are the primary benefits of VPN's but this restriction makes it difficult to now predict what will and what won't work when the chips are down. Specifically, it is obvious now that if I get an off-the-wall request to set up an emergency vpn with off the chelf components, I can't do it. The available off-the-shelf tools at the local big box is in now way guaranteed to support the key lengths we are currently using. This is the exact situation I am in now.
This thread was automatically locked due to age.