By default, Cisco routers display pre-shared keys for VPN groups as clear text.
crypto isakmp client configuration group vpn-group key thisIsMyKey (...)
To encrypt present and upcoming keys, you need to enter the following commands in router global configuration mode:
key config-key password-encryption [encryptionKey] password encryption aes
From now on, the keys will be encrypted using AES:
crypto isakmp client configuration group vpn-group key 6 J_APCTe]eS]aCOOeK_GZT]`QOdCZH[BgNYddiA_TVGGgbeGHFOAAB (...)