Windows Security Log Event ID 4984

Operating Systems Windows 2008 R2 and 7
Windows 2012 R2 and 8.1
Windows 2016 and 10
Windows Server 2019
Category
 • Subcategory
Logon/Logoff
 • IPsec Main Mode
Type Success
Corresponding events
in Windows 2003
and before
 
Discussions on Event ID 4984
IPSec Extended Mode 4984 error with DA/UAG

4984: An IPsec Extended Mode negotiation failed

On this page

I haven't been able to produce this event. Have you? If so, please start a discussion (see above) and post a sample along with any comments you may have! Don't forget to sanitize any private information.

Free Security Log Resources by Randy

Setup PowerShell Audit Log Forwarding in 4 Minutes

 

Examples of 4984

An IPsec Extended Mode negotiation failed. The corresponding Main Mode security association has been deleted.

Local Endpoint:

Principal Name:  %1
Network Address: %3
Keying Module Port: %4

Remote Endpoint:

Principal Name:  %2
Network Address: %5
Keying Module Port: %6

Additional Information:

Keying Module Name: AuthIP
Authentication Method: %9
Role:   %11
Impersonation State: %12
Quick Mode Filter ID: %13

Failure Information:

Failure Point:  %7
Failure Reason:  %8
State:   %10

Keep me up-to-date on the Windows Security Log.
Email*:
*We will NOT share this

Top 10 Windows Security Events to Monitor

Free Tool for Windows Event Collection



 

Additional Resources