Tobias Brunner tobias at strongswan.org
Mon Sep 19 13:35:06 CEST 2016

Hi Joe,

> I was under the impression that strongswan was using the mysql DB to obtain the PSK for Cisco IPsec connections but it seems that I was wrong. 
> Would you happen to know if that is possible ?

Yes, that should be possible.  You'll find several examples using PSKs
at [1].  However, they use IKEv2 and pull the complete config from the
database (not just the secrets), which is not necessary.  Also, for
IKEv1 the PSK lookup is initially based on the IP addresses, so you
have to consider that when associating identities with the PSK.


[1] https://www.strongswan.org/testing/testresults/sql/

