WinSecWiki > Security Settings > Advanced Audit Policies > System > IPsec Driver

Audit IPsec Driver

This category tracks activity related to the operation of the IPSec system service. For events related to IPSec network traffic see the IPSec subcategories in the Logon/Logoff category. To configure this on Server 2008 and Vista you must use auditpol. Windows 7 and Server 2008 R2 and later can use Group Policy.

Coverage on events generated by this category are currently in the Security Log Encyclopedia:

Event IDTitle
5478 IPsec Services has started successfully.
5479 IPsec Services has been shut down successfully
5480 IPsec Services failed to get the complete list of network interfaces on the computer.
5483 IPsec Services failed to initialize RPC server. IPsec Services could not be started..
5484 IPsec Services has experienced a critical failure and has been shut down.
5485 IPsec Services failed to process some IPsec filters on a plug-and-play event for network interfaces.

Back to top


Additional Resources