Audit Policy: Logon-Logoff: IPsec Quick Mode
|ID: oval:org.secpod.oval:def:22758||Date: (C)2015-01-07 (M)2017-10-31|
|Class: COMPLIANCE||Family: windows|
This subcategory reports the results of IKE protocol and AuthIP during Quick Mode negotiations.
? 4654: An IPsec Quick Mode negotiation failed. Events for this subcategory include:
? 4977: During Quick Mode negotiation, IPsec received an invalid negotiation packet. If this problem persists, it could indicate a network issue or an attempt to modify or replay this negotiation.
? 5451: An IPsec Quick Mode security association was established.
? 5452: An IPsec Quick Mode security association ended.
Refer to the Microsoft Knowledgebase article ?Description of security events in Windows Vista and in Windows Server 2008? for the most recent information about this setting: http://support.microsoft.com/default.aspx/kb/947226.
(1) GPO: Computer Configuration\Windows Settings\Security Settings\Advanced Audit Policy Configuration\Audit Policies\Logon/Logoff!Audit Policy: Logon-Logoff: IPsec Quick Mode
(2) REG: NO REGISTRY INFO
|Microsoft Windows Server 2012 R2|