| Previous | Next |
| ERROR_IPSEC_IKE_NO_PEER_CERT | ERROR_IPSEC_IKE_POLICY_CHANGE |
ERROR_IPSEC_IKE_PEER_CRL_FAILED
ERROR_IPSEC_IKE_PEER_CRL_FAILED (0x00003618) Windows could not complete certificate-revocation checking for the peer certificate during IKE authentication. The certificate may be valid, but the CRL or OCSP information required by policy was unavailable or could not be verified.
What to check
- Verify that the CRL distribution point or OCSP responder is reachable from the device performing IKE authentication.
- Check proxy, firewall, DNS, and time settings that can prevent revocation retrieval or validation.
- Do not disable revocation checking as a workaround; fix the PKI publication or network reachability problem.
certutil -store my
Microsoft: Remote Access and Always On VPN troubleshooting
Microsoft: IPsec/IKE system error codes
Looking for a different code? Search another status or error code.