What does NTSTATUS 0xC0220041 (STATUS_FWP_CONNECTIONS_DISABLED) mean?

 
Previous Next
STATUS_FWP_KEY_DICTATION_INVALID_KEYING_MATERIAL STATUS_FWP_INVALID_DNS_NAME

STATUS_FWP_CONNECTIONS_DISABLED

IPsec connection tracking is disabled in the Base Filtering Engine

These status values come from the Windows Filtering Platform path. For STATUS_FWP_CONNECTIONS_DISABLED, wFP classifies traffic through layers, filters, provider contexts, sublayers, and callouts; IPsec policy is also configured through WFP at IKE/AuthIP-related layers.

The Base Filtering Engine tracks IPsec connection state for policy enforcement. This status means a request depended on that state, but connection tracking was disabled.

For STATUS_FWP_CONNECTIONS_DISABLED, when this appears during IPsec or AuthIP negotiation, compare the Main Mode, Quick Mode, Extended Mode, transform, tunnel endpoint, DNS name, and authentication-method policy actually installed in WFP.

What to inspect

  • Check BFE and IPsec policy settings.
  • Review Filtering Platform Policy Change audit events.
  • Confirm that security software has not disabled IPsec connection tracking.

References for STATUS_FWP_CONNECTIONS_DISABLED


Looking for a different code? Search another status or error code.