Windows Security Log Event ID 5451

Operating Systems Windows 2008 R2 and 7
Windows 2012 R2 and 8.1
Windows 2016 and 10
Windows Server 2019 and 2022
Category
 • Subcategory
Logon/Logoff
 • IPsec Quick Mode
Type Success
Corresponding events
in Windows 2003
and before
 

5451: An IPsec Quick Mode security association was established

On this page

I haven't been able to produce this event. Have you? If so, please start a discussion (see above) and post a sample along with any comments you may have! Don't forget to sanitize any private information.

Free Security Log Resources by Randy

Setup PowerShell Audit Log Forwarding in 4 Minutes

 

Examples of 5451

An IPsec Quick Mode security association was established.

Local Endpoint:
  Network Address:           10.40.1.123
  Network Address mask:      255.255.255.255
  Port:                      0
  Tunnel Endpoint:           -

Remote Endpoint:
  Network Address:           10.40.1.112
  Network Address Mask:      255.255.255.255
  Port:                      443
  Private Address:           0.0.0.0
  Tunnel Endpoint:           -

  Protocol:                  6
  Keying Module Name:        IKEv1

Cryptographic Information:
  Integrity Algorithm - AH:  -
  Integrity Algorithm - ESP: SHA1
  Encryption Algorithm:      3DES

Security Association Information:
  Lifetime - seconds:        900
  Lifetime - data:           100000
  Lifetime - packets:        2164876353
  Mode:                      Transport
  Role:                      Initiator
  Quick Mode Filter ID:      71719
  Main Mode SA ID:           103
  Quick Mode SA ID:          2511

Additional Information:
  Inbound SPI:               13682941006
  Outbound SPI:              15970807004
  Virtual Interface Tunnel ID:       0
  Traffic Selector ID:               0

Top 10 Windows Security Events to Monitor

Free Tool for Windows Event Collection

 

Additional Resources

    Go To Event ID:

    Security Log
    Quick Reference
    Chart
    Download now!