| Previous | Next |
| STATUS_FWP_KEY_DICTATION_INVALID_KEYING_MATERIAL | STATUS_FWP_INVALID_DNS_NAME |
STATUS_FWP_CONNECTIONS_DISABLED
IPsec connection tracking is disabled in the Base Filtering Engine
These status values come from the Windows Filtering Platform path. For STATUS_FWP_CONNECTIONS_DISABLED, wFP classifies traffic through layers, filters, provider contexts, sublayers, and callouts; IPsec policy is also configured through WFP at IKE/AuthIP-related layers.
The Base Filtering Engine tracks IPsec connection state for policy enforcement. This status means a request depended on that state, but connection tracking was disabled.
For STATUS_FWP_CONNECTIONS_DISABLED, when this appears during IPsec or AuthIP negotiation, compare the Main Mode, Quick Mode, Extended Mode, transform, tunnel endpoint, DNS name, and authentication-method policy actually installed in WFP.
What to inspect
- Check BFE and IPsec policy settings.
- Review Filtering Platform Policy Change audit events.
- Confirm that security software has not disabled IPsec connection tracking.
References for STATUS_FWP_CONNECTIONS_DISABLED
- Microsoft Open Specifications: NTSTATUS values
- Microsoft: WFP error codes
- Microsoft: IPsec configuration through WFP
- Microsoft: Audit Filtering Platform Policy Change
Looking for a different code? Search another status or error code.