1 WFPv4 2 WFPv4 3 WFPv4 is the set of Windows Filtering Platform counters that apply to traffic and connections over Internet Protocol version 4. 5 Inbound Packets Discarded/sec 6 Inbound Packets Discarded/sec 7 Inbound Packets Discarded per second is the rate at which inbound packets are discarded by the Windows Filtering Platform. 9 Outbound Packets Discarded/sec 10 Outbound Packets Discarded/sec 11 Outbound Packets Discarded per second is the rate at which outbound packets are discarded by the Windows Filtering Platform. 13 Packets Discarded/sec 14 Packets Discarded/sec 15 Packets Discarded per second is the rate at which the total of inbound and outbound packets are discarded by the Windows Filtering Platform. 17 Blocked Binds 18 Blocked Binds 19 Blocked Binds is the number of network resource assignment requests blocked by the Windows Filtering Platform since the computer was last started. 21 Inbound Connections Blocked/sec 22 Inbound Connections Blocked/sec 23 Inbound Connections Blocked per second is the rate at which inbound connections are being blocked by the Windows Filtering Platform. 25 Outbound Connections Blocked/sec 26 Outbound Connections Blocked/sec 27 Outbound Connections Blocked per second is the rate at which outbound connections are being blocked by the Windows Filtering Platform. 29 Inbound Connections Allowed/sec 30 Inbound Connections Allowed/sec 31 Inbound Connections Allowed per second is the rate at which inbound connections are being allowed by the Windows Filtering Platform. 33 Outbound Connections Allowed/sec 34 Outbound Connections Allowed/sec 35 Outbound Connections Allowed per second is the rate at which outbound connections are being allowed by the Windows Filtering Platform. 37 Inbound Connections 38 Inbound Connections 39 Inbound Connections is the number of inbound connections allowed by the Windows Filtering Platform since the computer was last started. 41 Outbound Connections 42 Outbound Connections 43 Outbound Connections is the number of outbound connections allowed by the Windows Filtering Platform since the computer was last started. 45 Active Inbound Connections 46 Active Inbound Connections 47 Active Inbound Connections is the number of current inbound connections allowed by the Windows Filtering Platform. 49 Active Outbound Connections 50 Active Outbound Connections 51 Active Outbound Connections is the number of current outbound connections allowed by the Windows Filtering Platform. 53 Allowed Classifies/sec 54 Allowed Classifies/sec 55 Allowed Classifies per second is the rate of Windows Filtering Platform security rule evaluations which allow network activity. 57 WFPv6 58 WFPv6 59 WFPv6 is the set of Windows Filtering Platform counters that apply to traffic and connections over Internet Protocol version 6. 61 WFP 62 WFP 63 WFP is the set of Windows Filtering Platform counters that do not apply to any specific Internet Protocol version. 65 Provider Count 66 Provider Count 67 Provider Count is the number of providers registered with the Windows Filtering Platform. 69 IPsec Driver 70 IPsec Driver 71 IPsec Driver is the set of Internet Protocol security (IPsec) driver counters that apply to traffic over Internet Protocol version 4 and Internet Protocol version 6. 73 Active Security Associations 74 Active Security Associations 75 Active Security Associations is the number of active Quick Mode security associations. 77 Pending Security Associations 78 Pending Security Associations 79 Pending Security Associations is the number of pending Quick Mode security associations. 81 Incorrect SPI Packets 82 Incorrect SPI Packets 83 Incorrect SPI packets is the number of packets for which the Security Parameter Index (SPI) was incorrect since the computer was last started. A large number of packets with bad SPIs within a short amount of time might indicate a packet spoofing attack. 85 Bytes Received in Tunnel Mode/sec 86 Bytes Received in Tunnel Mode/sec 87 Bytes Received in Tunnel Mode per second is the rate of bytes received using Tunnel Mode. 89 Bytes Sent in Tunnel Mode/sec 90 Bytes Sent in Tunnel Mode/sec 91 Bytes Sent in Tunnel Mode per second is the rate of bytes sent using Tunnel Mode. 93 Bytes Received in Transport Mode/sec 94 Bytes Received in Transport Mode/sec 95 Bytes Received in Transport Mode per second is the rate of bytes received using Transport Mode. 97 Bytes Sent in Transport Mode/sec 98 Bytes Sent in Transport Mode/sec 99 Bytes Sent in Transport Mode per second is the rate of bytes sent using Transport Mode. 101 Offloaded Security Associations 102 Offloaded Security Associations 103 Offloaded Security Associations is the number of active Quick Mode security associations offloaded to hardware. Certain network adapters can accelerate IPsec processing by performing hardware offload of IPsec cryptographic functions. 105 Offloaded Bytes Received/sec 106 Offloaded Bytes Received/sec 107 Offloaded Bytes Received per second is the rate of bytes received using IPsec hardware offload. Certain network adapters can accelerate IPsec processing by performing hardware offload of IPsec cryptographic functions. 109 Offloaded Bytes Sent/sec 110 Offloaded Bytes Sent/sec 111 Offloaded Bytes Sent per second is the rate of bytes sent using IPsec hardware offload. Certain network adapters can accelerate IPsec processing by performing hardware offload of IPsec cryptographic functions. 113 Packets That Failed Replay Detection 114 Packets That Failed Replay Detection 115 Packets That Failed Replay Detection is the number of packets that contained an invalid sequence number since the computer was last started. Increases in this counter might indicate a network problem or replay attack. 117 Packets Not Authenticated 118 Packets Not Authenticated 119 Packets Not Authenticated is the number of packets for which data could not be verified (for which the integrity hash verification failed) since the computer was last started. Increases in this counter might indicate an IPsec packet spoofing or modification attack, or packet corruption by network devices. 121 Packets Not Decrypted 122 Packets Not Decrypted 123 Packets Not Decrypted is the number of packets that could not be decrypted since the computer was last started. A packet might not be decrypted if it fails a validation check. 125 SA Rekeys 126 SA Rekeys 127 SA Rekeys is the number of successful rekey operations for Quick Mode security associations since the computer was last started. 129 Security Associations Added 130 Security Associations Added 131 Security Associations Added is the number of security associations added since the computer was last started. 133 Packets That Failed ESP Validation 134 Packets That Failed ESP Validation 135 Packets That Failed ESP Validation is the number of packets received that failed ESP validation since the computer was last started. 137 Packets That Failed UDP-ESP Validation 138 Packets That Failed UDP-ESP Validation 139 Packets That Failed UDP-ESP Validation is the number of packets received that failed UDP-ESP validation (used for NAT traversal) since the computer was last started. 141 Packets Received Over Wrong SA 142 Packets Received Over Wrong SA 143 Packets Received Over Wrong SA is the number of packets received over the wrong security association since the computer was last started. 145 Plaintext Packets Received 146 Plaintext Packets Received 147 Plaintext Packets Received is the number of clear text packets received since the computer was last started. 149 IPsec IKEv4 150 IPsec IKEv4 151 IPsec IKEv4 is the set of Internet Protocol security (IPsec) Internet Key Exchange (IKE) counters that apply to traffic and connections over Internet Protocol version 4. 153 Active Main Mode SAs 154 Active Main Mode SAs 155 Active Main Mode SAs is the number of currently active Main Mode security associations. 157 Pending Main Mode Negotiations 158 Pending Main Mode Negotiations 159 Pending Main Mode Negotiations is the number of pending Main Mode negotiations. 161 Main Mode Negotiations 162 Main Mode Negotiations 163 Main Mode Negotiations is the number of Main Mode negotiations attempted since IPsec was last started. 165 Main Mode Negotiations/sec 166 Main Mode Negotiations/sec 167 Main Mode Negotiations per second is the rate at which Main Mode negotiations are being attempted. 169 Successful Main Mode Negotiations 170 Successful Main Mode Negotiations 171 Successful Main Mode Negotiations is the number of Main Mode negotiations completed since IPsec was last started. 173 Successful Main Mode Negotiations/sec 174 Successful Main Mode Negotiations/sec 175 Successful Main Mode Negotiations per second is the rate of Main Mode negotiations completed. 177 Failed Main Mode Negotiations 178 Failed Main Mode Negotiations 179 Failed Main Mode Negotiations is the number of failed Main Mode negotiations since IPsec was last started. 181 Failed Main Mode Negotiations/sec 182 Failed Main Mode Negotiations/sec 183 Failed Main Mode Negotiations per second is the rate of failed Main Mode negotiations. 185 Main Mode Negotiation Requests Received 186 Main Mode Negotiation Requests Received 187 Main Mode Negotiation Requests Received is the number of Main Mode negotiations initiated by a peer since IPsec was last started. 189 Main Mode Negotiation Requests Received/sec 190 Main Mode Negotiation Requests Received/sec 191 Main Mode Negotiation Requests Received per second is the rate of Main Mode negotiations initiated by a peer. 193 Active Quick Mode SAs 194 Active Quick Mode SAs 195 Active Quick Mode SAs is the number of currently active Quick Mode security associations. 197 Pending Quick Mode Negotiations 198 Pending Quick Mode Negotiations 199 Pending Quick Mode Negotiations is the number of pending Quick Mode negotiations. 201 Quick Mode Negotiations 202 Quick Mode Negotiations 203 Quick Mode Negotiations is the number of Quick Mode negotiations attempted since IPsec was last started. 205 Quick Mode Negotiations/sec 206 Quick Mode Negotiations/sec 207 Quick Mode Negotiations per second is the rate at which Quick Mode negotiations are being attempted. 209 Successful Quick Mode Negotiations 210 Successful Quick Mode Negotiations 211 Successful Quick Mode Negotiations is the number of Quick Mode negotiations completed since IPsec was last started. 213 Successful Quick Mode Negotiations/sec 214 Successful Quick Mode Negotiations/sec 215 Successful Quick Mode Negotiations per second is the rate of Quick Mode negotiations completed. 217 Failed Quick Mode Negotiations 218 Failed Quick Mode Negotiations 219 Failed Quick Mode Negotiations is the number of failed Quick Mode negotiations since IPsec was last started. 221 Failed Quick Mode Negotiations/sec 222 Failed Quick Mode Negotiations/sec 223 Failed Quick Mode Negotiations per second is the rate of failed Quick Mode negotiations. 225 IPsec IKEv6 226 IPsec IKEv6 227 IPsec IKEv6 is the set of Internet Protocol security (IPsec) Internet Key Exchange (IKE) counters that apply to traffic and connections over Internet Protocol version 6. 229 IPsec AuthIPv4 230 IPsec AuthIPv4 231 IPsec AuthIPv4 is the set of Internet Protocol security (IPsec) Authenticated IP (AuthIP) counters that apply to traffic and connections over Internet Protocol version 4. 233 Main Mode SAs That Used Impersonation 234 Main Mode SAs That Used Impersonation 235 Main Mode SAs That Used Impersonation is the number of Main Mode security associations completed using impersonation since IPsec was last started. 237 Main Mode SAs That Used Impersonation/sec 238 Main Mode SAs That Used Impersonation/sec 239 Main Mode SAs That Used Impersonation per second is the rate of Main Mode security associations completed using impersonation. 241 Active Extended Mode SAs 242 Active Extended Mode SAs 243 Active Extended Mode SAs is the number of currently active Extended Mode security associations. 245 Pending Extended Mode Negotiations 246 Pending Extended Mode Negotiations 247 Pending Extended Mode Negotiations is the number of pending Extended Mode negotiations. 249 Extended Mode Negotiations 250 Extended Mode Negotiations 251 Extended Mode Negotiations is the number of Extended Mode negotiations attempted since IPsec was last started. 253 Extended Mode Negotiations/sec 254 Extended Mode Negotiations/sec 255 Extended Mode Negotiations per second is the rate at which Extended Mode negotiations are being attempted. 257 Successful Extended Mode Negotiations 258 Successful Extended Mode Negotiations 259 Successful Extended Mode Negotiations is the number of Extended Mode negotiations completed since IPsec was last started. 261 Successful Extended Mode Negotiations/sec 262 Successful Extended Mode Negotiations/sec 263 Successful Extended Mode Negotiations per second is the rate of Extended Mode negotiations completed. 265 Failed Extended Mode Negotiations 266 Failed Extended Mode Negotiations 267 Failed Extended Mode Negotiations is the number of failed Extended Mode negotiations since IPsec was last started. 269 Failed Extended Mode Negotiations/sec 270 Failed Extended Mode Negotiations/sec 271 Failed Extended Mode Negotiations per second is the rate of failed Extended Mode negotiations. 273 Extended Mode SAs That Used Impersonation 274 Extended Mode SAs That Used Impersonation 275 Extended Mode SAs That Used Impersonation is the number of Extended Mode security associations completed using impersonation since IPsec was last started. 277 IPsec AuthIPv6 278 IPsec AuthIPv6 279 IPsec AuthIPv6 is the set of Internet Protocol security (IPsec) Authenticated IP (AuthIP) counters that apply to traffic and connections over Internet Protocol version 6. 281 Generic IKE and AuthIP 282 Generic IKE and AuthIP 283 Generic IKE and AuthIP is the set of Internet Protocol security (IPsec) Internet Key Exchange (IKE) and Authenticated IP (AuthIP) counters that are generic and do not apply to a specific Internet Protocol version. 285 IKE Main Mode Negotiation Time 286 IKE Main Mode Negotiation Time 287 IKE Main Mode Negotiation Time is the number of milliseconds taken for the last IKE Main Mode security association negotiated. 289 AuthIP Main Mode Negotiation Time 290 AuthIP Main Mode Negotiation Time 291 AuthIP Main Mode Negotiation Time is the number of milliseconds taken for the last Authenticated IP Main Mode security association negotiated. 293 IKE Quick Mode Negotiation Time 294 IKE Quick Mode Negotiation Time 295 IKE Quick Mode Negotiation Time is the number of milliseconds taken for the last IKE Quick Mode security association negotiated. 297 AuthIP Quick Mode Negotiation Time 298 AuthIP Quick Mode Negotiation Time 299 AuthIP Quick Mode Negotiation Time is the number of milliseconds taken for the last Authenticated IP Quick Mode security association negotiated. 301 Extended Mode Negotiation Time 302 Extended Mode Negotiation Time 303 Extended Mode Negotiation Time is the number of milliseconds taken for the last Extended Mode security association negotiated. 305 Packets Received/sec 306 Packets Received/sec 307 Packets Received per second is the rate at which validated IPsec packets are being received. 309 Invalid Packets Received/sec 310 Invalid Packets Received/sec 311 Invalid Packets Received per second is the rate at which invalid IPsec packets are being received. 313 Successful Negotiations 314 Successful Negotiations 315 Successful Negotiations is the number of negotiations completed for IKE and AuthIP since IPsec was last started. 317 Successful Negotiations/sec 318 Successful Negotiations/sec 319 Successful Negotiations per second is the rate of negotiations completed for IKE and AuthIP. 321 Failed Negotiations 322 Failed Negotiations 323 Failed Negotiations is the number of failed negotiations for IKE and AuthIP since IPsec was last started. 325 Failed Negotiations/sec 326 Failed Negotiations/sec 327 Failed Negotiations per second is the rate of failed negotiations attempted for IKE and AuthIP. 329 Windows Filtering Platform 331 BFE_POLICY_KEY_SDDL 333 Default SDDL for BFE Policy registry key 335 WRP_FILE_DEFAULT_SDDL 337 Default SDDL for Windows Resource Protected file 339 WFP_DIRECTORY_SDDL 341 Default SDDL for System32\wfp directory