Windows Security Log Event ID 5452

Operating Systems Windows 2008 R2 and 7
Windows 2012 R2 and 8.1
Windows 2016 and 10
Windows Server 2019 and 2022
 • Subcategory
 • IPsec Quick Mode
Type Success
Corresponding events
in Windows 2003
and before

5452: An IPsec Quick Mode security association ended

On this page

I haven't been able to produce this event. Have you? If so, please start a discussion (see above) and post a sample along with any comments you may have! Don't forget to sanitize any private information.

Free Security Log Resources by Randy

Supercharger Free Edition

Supercharger's built-in Xpath filters leave the noise behind.



Examples of 5452

An IPsec quick mode security association ended.
Local Endpoint:
    Network Address:
    Network Address mask:
    Port:                    0
    Tunnel Endpoint:         -

Remote Endpoint:
    Network Address:
    Network Address mask:
    Port:                    3389
    Tunnel Endpoint:         -

Additional Information:
    Protocol:                6
    Quick Mode SA ID:        59
    Virtual Interface Tunnel ID:    0
    Traffic Selector ID:            0

Top 10 Windows Security Events to Monitor

Free Tool for Windows Event Collection


Upcoming Webinars
    Additional Resources