Windows Security Log Event ID 4654
        
        
        
        
        
    
    
    
        
	
		| Operating Systems | 
                            Windows 2008 R2 and 7 
                        
                            Windows 2012 R2 and 8.1 
                        
                            Windows 2016 and 10 
                        
                            Windows Server 2019 and 2022 
                        
                            Windows Server 2025 
                         | 
	
		
                    Category  • Subcategory | Logon/Logoff                    • IPsec Quick Mode | 
	
		| 
                    Type
                 | 
                            Failure    
                         | 
	
		
                    Corresponding events 
                    in Windows
                    2003  and before | 
                     
                 | 
	
     
    
        4654: An IPsec Quick Mode negotiation failed
    
    
    
        On this page
    
    
    An IPsec Quick Mode negotiation failed
See Fields for differences in R2.
Free Security Log Resources by Randy 
    
    
        
                    The following two fields appear only in Server 2008 R2 and Windows 7:
	- Virtual Interface Tunnel ID: %20
 
	- Traffic Selector ID: %21
 
        
            
                Supercharger Free Edition
                
                
             
        
    
 
    
    
        
        An IPsec Quick Mode negotiation failed.
Local Endpoint:
   Network Address: %1
   Network Address mask: %2
   Port:   %3
   Tunnel Endpoint:  %4
Remote Endpoint:
   Network Address: %5
   Address Mask:  %6
   Port:   %7
   Tunnel Endpoint:  %8
   Private Address:  %10
Additional Information:
   Protocol:  %9
   Keying Module Name: %11
   Mode:   %14
   Role:   %16
   Quick Mode Filter ID: %18
   Main Mode SA ID: %19
Failure Information:
   State:   %15
   Message ID:  %17
   Failure Point:  %12
   Failure Reason:  %13
Server 2008 R2:
An IPsec quick mode negotiation failed.
Local Endpoint:
 Network Address: %1
 Network Address mask: %2
 Port:   %3
 Tunnel Endpoint:  %4
Remote Endpoint:
 Network Address: %5
 Address Mask:  %6
 Port:   %7
 Tunnel Endpoint:  %8
 Private Address:  %10
Additional Information:
 Protocol:  %9
 Keying Module Name: %11
 Virtual Interface Tunnel ID: %20
 Traffic Selector ID: %21
 Mode:   %14
 Role:   %16
 Quick Mode Filter ID: %18
 Main Mode SA ID: %19
Failure Information:
 State:   %15
 Message ID:  %17
 Failure Point:  %12
 Failure Reason:  %13
        
            Top 10 Windows Security Events to Monitor
        
        
            Free Tool for Windows Event Collection