Bug ID 438159: Anonymous Internet Key Exchange (IKE) peer doesn't support pre-shared key

Last Modified: Apr 28, 2025

Affected Product(s):
BIG-IP LTM(all modules)

Known Affected Versions:
11.4.0, 11.4.1, 11.5.0, 11.5.1, 11.5.1 HF1, 11.5.1 HF2, 11.5.1 HF3, 11.5.1 HF4

Fixed In:
11.6.0, 11.5.1 HF5, 11.4.1 HF10

Opened: Nov 18, 2013

Severity: 3-Major

Related Article: K16144

Symptoms

anonymous Internet Key Exchange (IKE) peer does not work with pre-shared key

Impact

User can't use pre-shared key with anonymous IKE peer

Conditions

IKEv1 negotiation using anonymous IKE peer configured with pre-shared key will fail.

Workaround

Use X.509 certificate with the anonymous IKE peer or configure specific IKE peer with the proper remote address for each remote IKE peer to use pre-shared key.

Fix Information

Users can now use pre-shared key with anonymous IKE peer for IKEv1 negotiation.

Behavior Change

Guides & references

K10134038: F5 Bug Tracker Filter Names and Tips