Previous Topic: Protocol Notification ActionNext Topic: Security Association Request Action


Security Association Expiry Action

The Security Association Expiry action deals with the expression of event information pertaining to the expiration of a Security Association that defines an IPSEC connection between two network entities as recorded by a given host. There are two possible results for this action: S for a success and F for a failure.

Information

Level

Source - User Information

Tertiary

Source - Host Information

Primary

Source - Object Information

Primary

Source - Process Information

Tertiary

Source - Group Information

Tertiary

Dest - User Information

Secondary

Dest - Host Information

Primary

Dest - Object Information

Tertiary

Dest - Process Information

Tertiary

Dest - Group Information

Tertiary

Agent - Information

Primary

Agent - Host Information

Primary

Event Source - Host Information

Primary

Event Source - Information

Tertiary

Event - Information

Primary

Result - Information

Primary

The important information for this action is which security association is expiring affecting the connection from which host to which host. The event information was expressed on which host and recorded by which agent on which host.

Result

event_result

event_severity

Success

S

2

Failure

F

3