ANAVEM
Languagefr

#ipsec-security

5 articles

Windows Events5

Network operations center monitoring IPsec VPN connections and security events on multiple displays
Event 4978
Security
Windows EventWarning

Windows Event ID 4978 – Security: IPsec Main Mode Negotiation Failed

Event ID 4978 indicates that IPsec Main Mode negotiation failed during the establishment of a secure connection. This security event occurs when two endpoints cannot agree on cryptographic parameters or authentication methods.

March 1812 min
Network security operations center showing IPsec tunnel monitoring and Windows security event logs
Event 4977
Microsoft-Windows-Security-Auditing
Windows EventInformation

Windows Event ID 4977 – Microsoft-Windows-Security-Auditing: IPsec Main Mode Security Association Established

Event ID 4977 indicates successful establishment of an IPsec Main Mode security association between two endpoints, confirming secure tunnel creation for encrypted network communication.

March 189 min
Windows security monitoring dashboard displaying IPsec network connection logs and security events
Event 4962
Microsoft-Windows-Security-Auditing
Windows EventInformation

Windows Event ID 4962 – Microsoft-Windows-Security-Auditing: IPsec Main Mode Security Association Established

Event ID 4962 logs when Windows successfully establishes an IPsec Main Mode security association between two endpoints, indicating secure tunnel creation for network communications.

March 1812 min
Windows security monitoring dashboard showing IPsec event logs and network connection status
Event 4948
Microsoft-Windows-Security-Auditing
Windows EventInformation

Windows Event ID 4948 – Microsoft-Windows-Security-Auditing: IPsec Main Mode Security Association Established

Event ID 4948 indicates successful establishment of an IPsec Main Mode security association between two endpoints, confirming secure tunnel creation for encrypted network communications.

March 1812 min
Windows security monitoring dashboard displaying Event Viewer with IPsec policy and security audit logs
Event 4947
Microsoft-Windows-Security-Auditing
Windows EventInformation

Windows Event ID 4947 – Microsoft-Windows-Security-Auditing: IPsec Policy Agent Service Started

Event ID 4947 indicates the IPsec Policy Agent service has successfully started on the system. This security audit event confirms IPsec policy enforcement is active and ready to secure network communications.

March 189 min