Logon Logoff Event: 5452

Active Directory Auditing Tool

The Who, Where and When information is very important for an administrator to have complete knowledge of all activities that occur on their Active Directory. This helps them identify any desired / undesired activity happening. ADAudit Plus assists an administrator with this information in the form of reports. In real-time, ensure critical resources in the network like the Domain Controllers are audited, monitored and reported with the entire information on AD objects - Users, Groups, GPO, Computer, OU, DNS, AD Schema and Configuration changes with 200+ detailed event specific GUI reports and email alerts.

Logon Logoff » Logon Logoff Event: 5452

Event ID 5452 – An IPsec Quick Mode Security Association Ended

Event ID 5452
Category Logon/Logoff
Sub-Category Audit IPsec Quick Mode
Description An IPsec Quick Mode security association ended.

Example of 5452 log:

An IPsec Quick Mode security association ended.

 

Local Endpoint:

Network Address: %1

Port: %2

Tunnel Endpoint: %3

 

Remote Endpoint:

Network Address: %4

Port: %5

Tunnel Endpoint: %6

 

Additional Information:

Protocol: %7

Quick Mode SA ID: %8

Virtual Interface Tunnel ID: %9

Traffic Selector ID: %10

Note: Only computers running Windows 7 or Windows Server 2008 will have Virtual Interface Tunnel ID and Traffic Selctor ID data available in the 5452 logs.

Why does event ID 5452 need to be monitored?

Security events which fall under the Audit IPsec Quick Mode subcategory are monitored primarily for IPsec Quick Mode troubleshooting.

Pro Tip:

Security events which fall under the Audit IPsec Quick Mode subcategory are monitored primarily for IPsec Quick Mode troubleshooting.

Event 5452 applies to the following operating systems:

  • Windows Server 2016
  • Windows 10
  • Windows Server 2008
  • Windows 7