Windows Security Log Event ID 615

Operating Systems Windows Server 2000
Windows 2003 and XP
CategoryPolicy Change
Type Success
Failure
Corresponding events
in Windows 2008
and Vista
 

615: IPSEC PolicyAgent Service

On this page

This event varies depending on the OS.

Win2000

General purpose event for IPSEC Policy Agent events. "IPSEC Policy Agent" becomes "IPSEC Services" in w3. Also this event switches categories to Policy Change.

If you assign an IP Security Policy in a GPO in AD, event ID 615's description specifies IPSEC PolicyAgent Service: Using the Active Directory Storage policy. If you assign the IPSec policy through the local GPO, event ID 615's description specifies IPSEC Policy-Agent Service: Using the Active Local Registry policy, as (i) there's no Active Directory Storage policy or (ii) the Active Directory Storage policy couldn't be applied successfully and there's no Cached policy. If Win2K encounters a problem applying the policy, the OS logs event ID 616 (IPSec policy agent encountered a potentially serious failure).

Win2003

This is an all purpose event for Windows to log any events regarding IPSec. The three example events below show three consecutive events that were logged on a computer when applying group policy after a relavant group policy object's IPSecurity policy had been modified. The first two events identify the name of the IP Security Policy that was assigned.

IPSec Services: PAStore Engine loaded directory storage IPSec policy "Client (Respond Only)" on the machine.

IPSec Services: PAStore Engine applied Active Directory storage IPSec policy "Client (Respond Only)" on the machine.

IPSec Services: PAStore Engine polled for changes to the active IPSec policy and detected no changes.

IPSec Services: IPSec Services has shut down successfully. Stopping IPSec Services can be a potential security hazard to the machine.

IPSec Services: IPSec Services has started successfully.

Free Security Log Resources by Randy

Description Fields in 615

  • IPSec Services:  %1

Setup PowerShell Audit Log Forwarding in 4 Minutes

 

Examples of 615

Win2000

IPSEC PolicyAgent Service: Service is shutting down.


Win2000

IPSEC PolicyAgent Service:  Using the Active Local Registry policy, as (i) there's no Active Directory Storage policy or (ii) the Active Directory Storage policy couldn't be applied successfully and there's no Cached policy.


Win2003

IPSec Services: IPSec Services has started successfully.

Top 10 Windows Security Events to Monitor

Free Tool for Windows Event Collection

 

Upcoming Webinars
    Additional Resources

      Go To Event ID:

      Security Log
      Quick Reference
      Chart
      Download now!