What does HRESULT 0x80320031 (FWP_E_INCOMPATIBLE_DH_GROUP) mean?

 
Previous Next
FWP_E_INCOMPATIBLE_AUTH_METHOD FWP_E_EM_NOT_SUPPORTED

FWP_E_INCOMPATIBLE_DH_GROUP

FWP_E_INCOMPATIBLE_DH_GROUP means the configured Diffie-Hellman group cannot be used by the selected IPsec policy type. This is a local policy-construction error before any successful peer negotiation can occur.

What to verify

  • Check the policy type and its allowed key-exchange groups.
  • Keep local and peer proposals aligned, including authentication and cryptographic transforms.
  • Do not interpret this code as a generic VPN routing failure; inspect the IKE/IPsec policy first.

Microsoft: WFP error codes

Microsoft: capture IPsec events with netsh wfp

Microsoft: IKEEXT service guidance


Looking for a different code? Search another status or error code.