CCE-37619-4Platform: cpe:/o:microsoft:windows_server_2012::r2 | Date: (C)2015-10-08 (M)2023-07-04 |
Audit Policy: Logon-Logoff: IPsec Quick Mode
This subcategory reports the results of IKE protocol and AuthIP during Quick Mode negotiations.
? 4654: An IPsec Quick Mode negotiation failed. Events for this subcategory include:
? 4977: During Quick Mode negotiation, IPsec received an invalid negotiation packet. If this problem persists, it could indicate a network issue or an attempt to modify or replay this negotiation.
? 5451: An IPsec Quick Mode security association was established.
? 5452: An IPsec Quick Mode security association ended.
Refer to the Microsoft Knowledgebase article ?Description of security events in Windows Vista and in Windows Server 2008? for the most recent information about this setting: http://support.microsoft.com/default.aspx/kb/947226.
Parameter:
[success/failure/success_failure/none]
Technical Mechanism:
(1) GPO: Computer ConfigurationWindows SettingsSecurity SettingsAdvanced Audit Policy ConfigurationAudit PoliciesLogon/Logoff!Audit Policy: Logon-Logoff: IPsec Quick Mode
(2) WMI: ###
CCSS Severity: | CCSS Metrics: |
CCSS Score : 6.1 | Attack Vector: LOCAL |
Exploit Score: 1.8 | Attack Complexity: LOW |
Impact Score: 4.2 | Privileges Required: LOW |
Severity: MEDIUM | User Interaction: NONE |
Vector: AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N | Scope: UNCHANGED |
| Confidentiality: HIGH |
| Integrity: LOW |
| Availability: NONE |
| |
References: Resource Id | Reference |
---|
SCAP Repo OVAL Definition | oval:org.secpod.oval:def:22758 |