Re: IPSec auditing

From: Daniel Angelucci (angelucc@nospam.duke.edu)
Date: 10/31/02


Date: Thu, 31 Oct 2002 08:56:15 -0500
From: Daniel Angelucci <angelucc@nospam.duke.edu>


Let's see... a quick look at my log and auditing policy would suggest
the following....

Audit system events should be set to success, failure.

I am glad to see someone else doing this. Could you email me privately?
  I have some experiences that I wanted to confirm.

Thanks!
Dan

Michael Buchardt wrote:
> Hi
>
> I am trying to audit the IPSec communication between two clients in domain.
>
> When I ping one the client the first time I get informed that it is
> negotiating IPSec and the second time I ping the echo reply comes through.
> Not problems there. If I startup isecmon.exe I can see that the traffic is
> encrypted.
> I have turned on auding on both client machines (Logon events + object
> access - failure and success). But I doesn´t get any event ID 541 which
> should state successful establishment of an IPSec Security Association (SA).
> I have tryed all that I can think of - am I doing something wrong here?!
>
> Kind Regards
>
>
> Michael Buchardt
>
>



Relevant Pages

  • Re: Rule blocks OutLook Mail
    ... I'm running the ISA Client on a workstation. ... Firewall Client for ISA Server 2004 support tool ... Locating WSPAD URL in DHCP Server ... What's interesting about the above information is that both display success ...
    (microsoft.public.isa)
  • Business Development Manager to Develop New Business
    ... Our direct Client has an excellent and urget Job opening for Business ... developers. ... The ideal candidate will have extensive experience of shaping, ... Demonstrable success in identifying, developing and closing projects ...
    (uk.jobs.offered)
  • Re: I think Delphi 9 Win32 could be huge success...
    ... > than a huge success would mean failure. ... > any money, considering that their marketing ... it's more that our customers are trained by MS ... Why would a client wish to know what tools you are using? ...
    (borland.public.delphi.non-technical)
  • Re: ports/security/vpnc vs built-in IPSec?
    ... I used ports/security/vpnc with some success some time ago, ... VPNC started in background ... the kernel, because the kernel gets to the esp ... Is there any way to disable kernel IPSEC in 6-STABLE? ...
    (freebsd-stable)
  • Re: Missing Inventory
    ... I will add the domain to the search suffix order on the workstation and kick ... As I say the inventory logfile reports a success in sending to the MP, ... generated at the client and sent to the MP does not appear in the MP_hinv.log ...
    (microsoft.public.sms.inventory)