Update #19
Following are corresponding RASCLIENT (Windows Event Viewer - Windows Logs - Application) and NORTON HISTORY log entries during testing on April 24.
NOTE: Norton Lifelock 360 version 22.21.2.50 - which is PRIOR to roll out of version 22.21.3.48
SOE in RASCLIENT for an unsuccessful Norton 360 VPN attempt:
1. 4/24/2021 13:14:32 CoId={488B2469-CE67-4B8A-9F45-27DF9D7036C3}: The user SYSTEM has started dialing a VPN connection using a per-user connection profile named NortonSecureVpn. The connection settings are:
Dial-in User =
VpnStrategy = IKEv2
DataEncryption = Require
PrerequisiteEntry =
AutoLogon = No
UseRasCredentials = Yes
Authentication Type = Machine Certificate
Ipv4DefaultGateway = Yes
Ipv4AddressAssignment = By Server
Ipv4DNSServerAssignment = By Server
Ipv6DefaultGateway = Yes
Ipv6AddressAssignment = By Server
Ipv6DNSServerAssignment = By Server
IpDnsFlags =
IpNBTEnabled = Yes
UseFlags = Private Connection
ConnectOnWinlogon = No
Mobility enabled for IKEv2 = Yes.
2. 4/24/2021 13:14:32 CoId={488B2469-CE67-4B8A-9F45-27DF9D7036C3}: The user SYSTEM is trying to establish a link to the Remote Access Server for the connection named NortonSecureVpn using the following device:
Server address/Phone Number = 18.185.116.99
Device = WAN Miniport (IKEv2)
Port = VPN2-1
MediaType = VPN.
3. 4/24/2021 13:14:32 CoId={488B2469-CE67-4B8A-9F45-27DF9D7036C3}: The user SYSTEM has successfully established a link to the Remote Access Server using the following device:
Server address/Phone Number = 18.185.116.99
Device = WAN Miniport (IKEv2)
Port = VPN2-1
MediaType = VPN.
4. 4/24/2021 13:14:32 CoId={488B2469-CE67-4B8A-9F45-27DF9D7036C3}: The link to the Remote Access Server has been established by user SYSTEM.
5. 4/24/2021 13:14:33 CoId={488B2469-CE67-4B8A-9F45-27DF9D7036C3}: The user SYSTEM has dialed a connection named NortonSecureVpn to the Remote Access Server which has successfully connected. The connection parameters are:
TunnelIpAddress = 10.252.0.106
TunnelIpv6Address = None
Dial-in User = .:
6. 4/24/2021 13:14:33 CoId={488B2469-CE67-4B8A-9F45-27DF9D7036C3}: The user SYSTEM dialed a connection named NortonSecureVpn which has terminated. The reason code returned on termination is 631.
Note SOE: 1. Start dial; 2. Try to establish; 3. Successful link server IP; 4. Link established by system; 5. Connection Tunnel IP addr;
However, successful connection was 6. terminated by the program which is what error 631 means.
Corresponding NORTON HISTORY SOE:
1. Category: Firewall - Activities
Date & Time,Risk,Activity,Status,Recommended Action,Category
4/24/2021 13:14:32,Info," Rule \"VPN UDP Rule\" allowed UDP(17) traffic with de.nsv4w.com (18.185.116.99 Port (500) )",Detected,No Action Required,Firewall - Activities
Firewall rule was matched:<br> Rule Name: "VPN UDP Rule"<br> Rule Action: allowed<br> Rule Severity: normal<br> <br> Traffic Details:<br> Protocol: UDP(17) <br> Direction: outbound<br> Local Host: JCVAIO<br> Local IP: 192.168.1.104<br> Local Service: Port (500) <br> Remote Host: de.nsv4w.com<br> Remote IP: 18.185.116.99<br> Remote Service: Port (500) <br> Remote MAC: -- <br> Adapter Index: 19<br> <br> Process Information:<br> Process ID: 4768<br> Process Path: C:\Windows\System32\svchost.exe<br>
2. Category: Firewall - Activities
Date & Time,Risk,Activity,Status,Recommended Action,Category
4/24/2021 13:14:32,Info," Rule \"VPN UDP Rule\" allowed UDP(17) traffic with de.nsv4w.com (18.185.116.99 Port (4500) )",Detected,No Action Required,Firewall - Activities
Firewall rule was matched:<br> Rule Name: "VPN UDP Rule"<br> Rule Action: allowed<br> Rule Severity: normal<br> <br> Traffic Details:<br> Protocol: UDP(17) <br> Direction: outbound<br> Local Host: JCVAIO<br> Local IP: 192.168.1.104<br> Local Service: Port (4500) <br> Remote Host: de.nsv4w.com<br> Remote IP: 18.185.116.99<br> Remote Service: Port (4500) <br> Remote MAC: -- <br> Adapter Index: 19<br> <br> Process Information:<br> Process ID: 4768<br> Process Path: C:\Windows\System32\svchost.exe<br>
3. Category: Firewall - Activities
Date & Time,Risk,Activity,Status,Recommended Action,Category
4/24/2021 13:14:33,Info," Rule \"Default Block Windows File Sharing \" rejected TCP(6) traffic with (0.0.0.0 Port (0) )",Detected,No Action Required,Firewall - Activities
Firewall rule was matched:<br> Rule Name: "Default Block Windows File Sharing "<br> Rule Action: rejected<br> Rule Severity: normal<br> <br> Traffic Details:<br> Protocol: TCP(6) <br> Direction: inbound<br> Local Host: <br> Local IP: 10.252.0.106<br> Local Service: Port (139) <br> Remote Host: <br> Remote IP: 0.0.0.0<br> Remote Service: Port (0) <br> Remote MAC: -- <br> Adapter Index: 0<br> <br> Process Information:<br> Process ID: 4<br> Process Path: System<br>
4. Category: Firewall - Network and Connections
Date & Time,Risk,Activity,Status,Recommended Action,Category
4/24/2021 13:14:33,Info,"Protecting your connection to a newly detected network on adapter \"NortonSecureVpn\" (IP address: 10.252.0.106).",Detected,No Action Required,Firewall - Network and Connections
Protecting your connection to a newly detected network on adapter "NortonSecureVpn" (IP address: 10.252.0.106).
5. Category: Firewall - Network and Connections
Date & Time,Risk,Activity,Status,Recommended Action,Category
4/24/2021 13:14:33,Info,IP address has disappeared from adapter NortonSecureVpn (IP address: 10.252.0.106).,Detected,No Action Required,Firewall - Network and Connections
IP address has disappeared from adapter NortonSecureVpn (IP address: 10.252.0.106).
Note SOE: 1. Firewall UDP 500; 2. Firewall UDP 4500; 3. Default BLOCK file sharing 0.0.0.0; 4. Protecting connection; 5. IP has disappeared from adapter NortonSecureVPN.
SOE in RASCLIENT for an successful Norton Standalone VPN attempt:
1. 4/24/2021 13:23:27 CoId={857B88E3-D6F1-4E7B-9A9E-4DFA8FDFD3CC}: The user SYSTEM has started dialing a VPN connection using a per-user connection profile named NortonSecureVpn. The connection settings are:
Dial-in User =
VpnStrategy = IKEv2
DataEncryption = Require
PrerequisiteEntry =
AutoLogon = No
UseRasCredentials = Yes
Authentication Type = Machine Certificate
Ipv4DefaultGateway = Yes
Ipv4AddressAssignment = By Server
Ipv4DNSServerAssignment = By Server
Ipv6DefaultGateway = Yes
Ipv6AddressAssignment = By Server
Ipv6DNSServerAssignment = By Server
IpDnsFlags =
IpNBTEnabled = Yes
UseFlags = Private Connection
ConnectOnWinlogon = No
Mobility enabled for IKEv2 = Yes.
2. 4/24/2021 13:23:27 CoId={857B88E3-D6F1-4E7B-9A9E-4DFA8FDFD3CC}: The user SYSTEM is trying to establish a link to the Remote Access Server for the connection named NortonSecureVpn using the following device:
Server address/Phone Number = 185.94.193.186
Device = WAN Miniport (IKEv2)
Port = VPN2-1
MediaType = VPN.
3. 4/24/2021 13:23:27 CoId={857B88E3-D6F1-4E7B-9A9E-4DFA8FDFD3CC}: The user SYSTEM has successfully established a link to the Remote Access Server using the following device:
Server address/Phone Number = 185.94.193.186
Device = WAN Miniport (IKEv2)
Port = VPN2-1
MediaType = VPN.
4. 4/24/2021 13:23:27 CoId={857B88E3-D6F1-4E7B-9A9E-4DFA8FDFD3CC}: The link to the Remote Access Server has been established by user SYSTEM.
5. 4/24/2021 13:23:27 CoId={857B88E3-D6F1-4E7B-9A9E-4DFA8FDFD3CC}: The user SYSTEM has dialed a connection named NortonSecureVpn to the Remote Access Server which has successfully connected. The connection parameters are:
TunnelIpAddress = 10.252.1.164
TunnelIpv6Address = None
Dial-in User = .
Note SOE: 1. Start dial; 2. Try to establish; 3. Successful link server IP; 4. Link established by system; 5. Connection Tunnel IP addr;
Corresponding NORTON HISTORY SOE:
1. Category: Firewall - Activities
Date & Time,Risk,Activity,Status,Recommended Action,Category
4/24/2021 13:23:27,Info," Rule \"VPN UDP Rule\" allowed UDP(17) traffic with ipsec.nsv4w.com (185.94.193.186 Port (500) )",Detected,No Action Required,Firewall - Activities
Firewall rule was matched:<br> Rule Name: "VPN UDP Rule"<br> Rule Action: allowed<br> Rule Severity: normal<br> <br> Traffic Details:<br> Protocol: UDP(17) <br> Direction: outbound<br> Local Host: JCVAIO<br> Local IP: 192.168.1.104<br> Local Service: Port (500) <br> Remote Host: ipsec.nsv4w.com<br> Remote IP: 185.94.193.186<br> Remote Service: Port (500) <br> Remote MAC: -- <br> Adapter Index: 19<br> <br> Process Information:<br> Process ID: 4768<br> Process Path: C:\Windows\System32\svchost.exe<br>
2. Category: Firewall - Activities
Date & Time,Risk,Activity,Status,Recommended Action,Category
4/24/2021 13:23:27,Info," Rule \"VPN UDP Rule\" allowed UDP(17) traffic with ipsec.nsv4w.com (185.94.193.186 Port (4500) )",Detected,No Action Required,Firewall - Activities
Firewall rule was matched:<br> Rule Name: "VPN UDP Rule"<br> Rule Action: allowed<br> Rule Severity: normal<br> <br> Traffic Details:<br> Protocol: UDP(17) <br> Direction: outbound<br> Local Host: JCVAIO<br> Local IP: 192.168.1.104<br> Local Service: Port (4500) <br> Remote Host: ipsec.nsv4w.com<br> Remote IP: 185.94.193.186<br> Remote Service: Port (4500) <br> Remote MAC: -- <br> Adapter Index: 19<br> <br> Process Information:<br> Process ID: 4768<br> Process Path: C:\Windows\System32\svchost.exe<br>
3. Category: Firewall - Activities
Date & Time,Risk,Activity,Status,Recommended Action,Category
4/24/2021 13:23:27,Info," Rule \"Default Block Windows File Sharing \" rejected TCP(6) traffic with (0.0.0.0 Port (0) )",Detected,No Action Required,Firewall - Activities
Firewall rule was matched:<br> Rule Name: "Default Block Windows File Sharing "<br> Rule Action: rejected<br> Rule Severity: normal<br> <br> Traffic Details:<br> Protocol: TCP(6) <br> Direction: inbound<br> Local Host: <br> Local IP: 10.252.1.164<br> Local Service: Port (139) <br> Remote Host: <br> Remote IP: 0.0.0.0<br> Remote Service: Port (0) <br> Remote MAC: -- <br> Adapter Index: 0<br> <br> Process Information:<br> Process ID: 4<br> Process Path: System<br>
4. Category: Firewall - Network and Connections
Date & Time,Risk,Activity,Status,Recommended Action,Category
4/24/2021 13:23:27,Info,"Protecting your connection to a newly detected network on adapter \"NortonSecureVpn\" (IP address: 10.252.1.164).",Detected,No Action Required,Firewall - Network and Connections
Protecting your connection to a newly detected network on adapter "NortonSecureVpn" (IP address: 10.252.1.164).
5. Category: Firewall - Network and Connections
Date & Time,Risk,Activity,Status,Recommended Action,Gateway IP Address
4/24/2021 13:23:30,Info,Connected to a public network. (0.0.0.0),Protected,No Action Required,0.0.0.0
Your computer is currently protected from the local network. To allow all the computers on this network to communicate with your computer, in the <b>Actions</b> panel, click <b>Trust</b>. To block all the computers on this network from communicating with your computer, in the <b>Actions</b> panel, click <b>Restrict</b>. This will not interfere with your other online communications.
Note SOE: 1. Firewall UDP 500; 2. Firewall UDP 4500; 3. Default BLOCK file sharing 0.0.0.0; 4. Protecting connection;
In the unsuccessful connection the IP addr disappears, it does not here. Instead 5. a connection to 0.0.0.0 local network.