IPsec Policy Agent Service Initialization

Applies To: Windows Server 2008 R2

The IPsec Policy Agent service must be running to receive and process Internet Protocol security (IPsec) policies that were made by using earlier versions of Windows.

Note: This service provides compatibility with Internet Protocol security (IPsec) policies used in earlier versions of Windows. New deployments of Windows Vista and Windows Server 2008 should not use the policies supported by the IPsec Policy Agent service since those policies support only a subset of the features supported by Windows Firewall with Advanced Security. Instead, new deployments should use policies created by using Windows Firewall with Advanced Security to take full advantage of the additional security and features.

When appropriate auditing events are enabled (https://go.microsoft.com/fwlink/?linkid=92666), Windows reports successes and failures in starting the service, or when the service stops operating due to a failure.

Events

Event ID Source Message

4709

Microsoft-Windows-Security-Auditing

IPsec Services was started.

%1

Policy Source: %t%2

%3

4710

Microsoft-Windows-Security-Auditing

IPsec Services was disabled.

%1
%2

5478

Microsoft-Windows-Security-Auditing

IPsec Services has started successfully.

5479

Microsoft-Windows-Security-Auditing

IPsec Services has been shut down successfully. The shutdown of IPsec Services can put the computer at greater risk of network attack or expose the computer to potential security risks.

5483

Microsoft-Windows-Security-Auditing

IPsec Services failed to initialize RPC server. IPsec Services could not be started.

Error Code:%t%t%1

5484

Microsoft-Windows-Security-Auditing

IPsec Services has experienced a critical failure and has been shut down. The shutdown of IPsec Services can put the computer at greater risk of network attack or expose the computer to potential security risks.

Error Code:%t%t%1

IPsec Policy Agent (Legacy) Service

Windows Firewall with Advanced Security