Event ID 4650

An IPsec main mode security association was established

An IPsec main mode security association was established. Extended mode was not enabled.  Certificate authentication was not used.

Local Endpoint:
    Principal Name:     %1
    Network Address:    %3
    Keying Module Port: %4

Remote Endpoint:
    Principal Name:     %2
    Network Address:    %5
    Keying Module Port: %6

Security Association Information:
    Lifetime (minutes): %12
    Quick Mode Limit:   %13
    Main Mode SA ID:    %17

Cryptographic Information:
    Cipher Algorithm:   %9
    Integrity Algorithm:    %10
    Diffie-Hellman Group:   %11

Additional Information:
    Keying Module Name:     %7
    Authentication Method:  %8
    Role:                   %14
    Impersonation State:    %15
    Main Mode Filter ID:    %16


Generated on the computer that initiates or receives an IPsec connection once Main Mode negotiation (phase 1) is complete.

Microsoft Documentation

Event ID - 4650



NameFieldInsertion StringOS
Local Endpoint Principal NameLocalMMPrincipalName%1Any
Remote Endpoint Principal NameRemoteMMPrincipalName%2Any
Local Endpoint Network AddressLocalAddress%3Any
Local Endpoint Keying Module PortLocalKeyModPort%4Any
Remote Endpoint Network AddressRemoteAddress%5Any
Remote Endpoint Keying Module PortRemoteKeyModPort%6Any
Keying Module NameKeyModName%7Any
Authentication MethodMMAuthMethod%8Any
Cipher AlgorithmMMCipherAlg%9Any
Integrity AlgorithmMMIntegrityAlg%10Any
Diffie-Hellman GroupDHGroup%11Any
Lifetime (minutes)MMLifetime%12Any
Quick Mode LimitQMLimit%13Any
RoleRole%14Any
Impersonation StateMMImpersonationState%15Any
Main Mode Filter IDMMFilterID%16Any
Main Mode SA IDMMSAID%17Any


Lookup Audit Policy Configuration Settings

C:\> AuditPol.exe /get /subcategory:"IPsec Main Mode"



LEFT/RIGHT arrow keys for navigation

Back to List