> For the complete documentation index, see [llms.txt](https://pnpt.adot8.com/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://pnpt.adot8.com/external-pentest-playbook/common-pentest-findings/ike-agressive-mode.md).

# IKE Agressive mode

## Overview

Having aggressive mode enabled on a VPN allows for an attacker to capture and crack that PSK thus gaining access into the internal network.

The **Likelihood** of this happening are close to zero but the **Impact** is very high. It's just best practice to have aggressive mode on **IKE** be disabled

## Example

<figure><img src="/files/MzwcJ5g3AEPY526DDL54" alt=""><figcaption><p>IKE aggressive mode turned on</p></figcaption></figure>

<figure><img src="/files/xptGR81NWK8Wh93FsYq1" alt=""><figcaption><p>Evidence</p></figcaption></figure>

{% hint style="info" %}
Remediation would be to simply turn it off
{% endhint %}
