Skip to main content

Remote Access (RRAS / VPN / DirectAccess)

Log NameEvent IDSeverityDescription
Security20271InfoUser connected successfully to VPN
Security20275InfoUser disconnected from VPN
Security20276HighVPN authentication failed
Security20277HighVPN connection attempt rejected
Security20278HighConnection failed due to invalid credentials
Security20279MediumConnection failed due to network error
Security20283HighL2TP/IPSec negotiation failed
Security20286HighSSTP tunnel failed to establish
Security20291MediumUser authentication method changed
Security20292HighUser account locked out
Security6272InfoNPS granted access (VPN via RADIUS)
Security6273HighNPS denied access (VPN via RADIUS)
RemoteAccess/Admin20255InfoVPN client assigned IP
RemoteAccess/Admin20268MediumConnection failed (timeout)
RemoteAccess/Admin20271InfoConnection succeeded
RemoteAccess/Admin20276HighAuthentication failed
System7031HighRRAS service terminated unexpectedly
Security4100–4104CriticalVPN configuration changed
RemoteAccess/Admin1000InfoRemote Access service started
RemoteAccess/Admin1001WarningRemote Access service stopped
RemoteAccess/Admin1002HighRouting component failed to initialize
RemoteAccess/Admin20001InfoVPN server started successfully
RemoteAccess/Admin20002WarningVPN server stopped
RemoteAccess/Admin20200HighUnable to allocate IP address to VPN client
RemoteAccess/Admin20223MediumPPP connection failure
RemoteAccess/Admin20224HighRouting table update failed
System7031HighRemote Access service terminated unexpectedly
System20234MediumInterface disconnected unexpectedly
Security4100HighVPN configuration modified
Security4101HighVPN authentication policy updated
Security4102MediumRouting table or static route modified
Security4103MediumIP address assignment pool changed
Security4104CriticalVPN certificate binding modified
Security4719CriticalSystem audit policy changed
Security4732HighUser added to “Network Configuration Operators” group
Security4799MediumSecurity group membership enumerated
Microsoft-Windows-RemoteAccess-Server1000InfoRemote Access service (RRAS) started successfully
Microsoft-Windows-RemoteAccess-Server1001HighRemote Access service stopped or crashed
System7024HighRRAS terminated unexpectedly
Microsoft-Windows-RemoteAccess-Server1005InfoConfiguration store updated
Microsoft-Windows-RemoteAccess-Server1010MediumIPv6 routing component failed to initialize
Microsoft-Windows-RemoteAccess-RemoteAccessServer20220InfoVPN connection established successfully
Microsoft-Windows-RemoteAccess-RemoteAccessServer20226InfoVPN user disconnected
Microsoft-Windows-RemoteAccess-RemoteAccessServer20271HighAuthentication failed for VPN user
Microsoft-Windows-RemoteAccess-RemoteAccessServer20274HighConnection refused — authentication error
Security6272InfoNetwork Policy Server granted access
Security6273HighNetwork Policy Server denied access
Microsoft-Windows-RemoteAccess-DA3000InfoDirectAccess tunnel established
Microsoft-Windows-RemoteAccess-DA3001InfoDirectAccess tunnel terminated
Microsoft-Windows-RemoteAccess-DA3003MediumDNS64/NAT64 translation failure
Microsoft-Windows-RemoteAccess-DA3004HighIP-HTTPS listener failed
Microsoft-Windows-RemoteAccess-DA3010CriticalDirectAccess server unreachable
Microsoft-Windows-RemoteAccess-RoutingDomain4001MediumStatic route added or changed
Microsoft-Windows-RemoteAccess-RoutingDomain4002InfoRouting protocol update received
Microsoft-Windows-RemoteAccess-RoutingDomain4005MediumNAT mapping failed for client
Microsoft-Windows-RemoteAccess-RoutingDomain4006HighPacket dropped due to policy
Microsoft-Windows-RemoteAccess-RoutingDomain4010HighRRAS detected duplicate IP address
Security4648InfoLogon attempt using explicit credentials (VPN)
Security6278InfoNPS granted access with certain policy
Security6279HighNPS denied access due to certificate issue
Microsoft-Windows-RemoteAccess-Server5000InfoIPsec negotiation succeeded
Microsoft-Windows-RemoteAccess-Server5001HighIPsec negotiation failed
Microsoft-Windows-RemoteAccess-Server5002HighCertificate revocation check failed