| Previous | Next |
| ERROR_IPSEC_IKE_INVALID_COOKIE | ERROR_IPSEC_IKE_PEER_CRL_FAILED |
ERROR_IPSEC_IKE_NO_PEER_CERT
ERROR_IPSEC_IKE_NO_PEER_CERT (0x00003617) The VPN or connection-security peer did not send a machine certificate that Windows could use for IKE authentication. This differs from a generic trust error: the expected certificate was missing or unusable at the peer-authentication step.
What to check
- Verify that the peer has a machine certificate with a private key and the EKU required by the IPsec or VPN policy.
- Confirm that both sides selected certificate authentication rather than different methods such as Kerberos or preshared key.
- Check the certificate chain, validity period, and certificate-selection rules on the VPN server or connection-security endpoint.
certutil -store my
Microsoft: Remote Access and Always On VPN troubleshooting
Microsoft: IKE authentication method types
Microsoft: IPsec/IKE system error codes
Looking for a different code? Search another status or error code.