IPSec auditing

From: Michael Buchardt (jumihen@image.dk)
Date: 10/31/02


From: "Michael Buchardt" <jumihen@image.dk>
Date: Thu, 31 Oct 2002 14:03:04 +0100


Hi

I am trying to audit the IPSec communication between two clients in domain.

When I ping one the client the first time I get informed that it is
negotiating IPSec and the second time I ping the echo reply comes through.
Not problems there. If I startup isecmon.exe I can see that the traffic is
encrypted.
I have turned on auding on both client machines (Logon events + object
access - failure and success). But I doesn´t get any event ID 541 which
should state successful establishment of an IPSec Security Association (SA).
I have tryed all that I can think of - am I doing something wrong here?!

Kind Regards

Michael Buchardt



Relevant Pages

  • Re: VPN & W2k
    ... Also gehe ich mal davon aus das du auch pptp nutzt und nicht etwa IPSEC ... Versuche mal ping mit größeren Daten ob die auch alle durchgehen ... Es könnte mit dem MTU Wert auf dem CLient zusammenhängen. ... ebenfalls Christian G. ...
    (microsoft.public.de.german.win2000.networking)
  • Re: IPSec auditing
    ... If you have some questions about auditing ... >> When I ping one the client the first time I get informed that it is ... >> negotiating IPSec and the second time I ping the echo reply comes ...
    (microsoft.public.win2000.security)
  • Re: User authentication IPsec
    ... View Output Logs for details ... Ping Diagnosis: ... NAP Client Diagnosis: ... IPsec Service Diagnosis: ...
    (microsoft.public.windows.server.active_directory)
  • Re: ISA Problem
    ... is the machine you are physically sitting at when you ping. ... Microsoft Internet Security & Acceleration Server: ... Original Client IP Client IP Client Username Client Agent Authenticated ... Client Service Server Name Referring Server Destination Host Name ...
    (microsoft.public.isa)
  • RE: Microsoft IPSec via group policy
    ... IPsec could accomplish this. ... Microsoft IPSec via group policy ... Requiring ipsec between a client and a DC via GPO is problematic. ...
    (Security-Basics)