#network-security
4 articles
Windows Events4
Windows Event ID 6272 – Microsoft-Windows-Security-Auditing: Network Policy Server Granted Access
Event ID 6272 indicates that Network Policy Server (NPS) has granted network access to a user or device after successful authentication and authorization through RADIUS protocols.
Windows Event ID 5157 – Windows Filtering Platform: Network Connection Blocked by Firewall
Event ID 5157 indicates Windows Filtering Platform blocked a network connection attempt. This security audit event helps administrators track blocked network traffic and firewall rule effectiveness.
Windows Event ID 5152 – Windows Filtering Platform: Network Packet Blocked by Firewall
Event ID 5152 indicates Windows Filtering Platform blocked a network packet. This security audit event helps track firewall activity and identify blocked connection attempts on Windows systems.
Windows Event ID 5024 – Windows Filtering Platform: Filter Engine Initialization Failed
Event ID 5024 indicates the Windows Filtering Platform (WFP) filter engine failed to initialize or encountered a critical error during startup, potentially affecting network security and firewall functionality.