Windows Security Log Event ID 5451
Operating Systems |
Windows 2008 R2 and 7
Windows 2012 R2 and 8.1
Windows 2016 and 10
Windows Server 2019 and 2022
|
Category • Subcategory | Logon/Logoff • IPsec Quick Mode |
Type
|
Success
|
Corresponding events
in Windows
2003 and before |
|
5451: An IPsec Quick Mode security association was established
On this page
I haven't been able to produce this event. Have you? If so, please start a discussion (see above) and post a sample along with any comments you may have! Don't forget to sanitize any private information.
Free Security Log Resources by Randy
Setup PowerShell Audit Log Forwarding in 4 Minutes
An IPsec Quick Mode security association was established.
Local Endpoint:
Network Address: 10.40.1.123
Network Address mask: 255.255.255.255
Port: 0
Tunnel Endpoint: -
Remote Endpoint:
Network Address: 10.40.1.112
Network Address Mask: 255.255.255.255
Port: 443
Private Address: 0.0.0.0
Tunnel Endpoint: -
Protocol: 6
Keying Module Name: IKEv1
Cryptographic Information:
Integrity Algorithm - AH: -
Integrity Algorithm - ESP: SHA1
Encryption Algorithm: 3DES
Security Association Information:
Lifetime - seconds: 900
Lifetime - data: 100000
Lifetime - packets: 2164876353
Mode: Transport
Role: Initiator
Quick Mode Filter ID: 71719
Main Mode SA ID: 103
Quick Mode SA ID: 2511
Additional Information:
Inbound SPI: 13682941006
Outbound SPI: 15970807004
Virtual Interface Tunnel ID: 0
Traffic Selector ID: 0
Top 10 Windows Security Events to Monitor
Free Tool for Windows Event Collection