Event ID 5452

An IPsec quick mode security association ended.

An IPsec quick mode security association ended.

Local Endpoint:
    Network Address:    %1
    Port:           %2
    Tunnel Endpoint:        %3

Remote Endpoint:
    Network Address:    %4
    Port:           %5
    Tunnel Endpoint:        %6

Additional Information:
    Protocol:       %7
    Quick Mode SA ID:   %8


Event 5452 is logged when an established IPsec Quick Mode security association (SA) expires or is terminated. The event is intentionally minimal, containing only the fields necessary to identify which SA ended without restating the cryptographic details already captured during establishment.

Auditing:     Rarely

Enable only when diagnosing IPsec SA lifecycle issues, auditing encrypted host-to-host session durations for compliance, or correlating IPsec teardowns with application disconnections.


Volume:     High

Every SA establishment produces a corresponding teardown. On any active IPsec environment, expect a 1:1 ratio of 5452 to 5451 events over time, with the same high-volume characteristics on busy servers running domain isolation or DirectAccess.




NameFieldInsertion StringOSExample
Local Network AddressLocal Network Address%1Any 10.40.1.123
Local PortLocalPort%2Any 0
Local Tunnel EndpointLocalTunnelEndpoint%3Any -
Remote Network AddressRemoteAddress%4Any 10.40.1.112
Remote PortRemotePort%5Any 3389
Remote Tunnel EndpointRemote Tunnel Endpoint%6Any -
ProtocolProtocol%7Any 6
Quick Mode SA IDQuickModeSaId%8Any 59


Lookup Audit Policy Configuration Settings

C:\> AuditPol.exe /get /subcategory:"IPsec Quick Mode"



LEFT/RIGHT arrow keys for navigation

Back to List