Event ID 5451
An IPsec quick mode security association was established.An IPsec quick mode security association was established.
Local Endpoint:
Network Address: %1
Network Address mask: %2
Port: %3
Tunnel Endpoint: %4
Remote Endpoint:
Network Address: %5
Network Address Mask: %6
Port: %7
Private Address: %8
Tunnel Endpoint: %9
Protocol: %10
Keying Module Name: %11
Cryptographic Information:
Integrity Algorithm - AH: %12
Integrity Algorithm - ESP: %13
Encryption Algorithm: %14
Security Association Information:
Lifetime - seconds: %15
Lifetime - data: %16
Lifetime - packets: %17
Mode: %18
Role: %19
Quick Mode Filter ID: %20
Main Mode SA ID: %21
Quick Mode SA ID: %22
Additional Information:
Inbound SPI: %23
Outbound SPI: %24Event 5451 records the successful establishment of an IPsec Quick Mode security association (SA).
Security events in the Audit IPsec Quick Mode subcategory are monitored primarily for IPsec Quick Mode troubleshooting. Not recommended for general security monitoring due to volume. Enable only when actively diagnosing IPsec SA negotiation issues, auditing compliance requirements around encrypted host-to-host communication, or forensically reconstructing which hosts established IPsec sessions during a specific timeframe.
On any system actively using IPsec, a new Quick Mode SA is negotiated for every protected connection and refreshed on key lifetime expiry. On a busy server this can produce hundreds of events per hour.
Lookup Audit Policy Configuration Settings
C:\> AuditPol.exe /get /subcategory:"IPsec Quick Mode" LEFT/RIGHT arrow keys for navigation
Back to List