| Previous | Next |
| ERROR_IPSEC_IKE_DH_FAILURE | ERROR_IPSEC_IKE_ENCRYPT |
ERROR_IPSEC_IKE_INVALID_GROUP
ERROR_IPSEC_IKE_INVALID_GROUP (0x00003629) The peer offered a Diffie-Hellman group that Windows could not use under the active policy. This is a crypto-proposal mismatch, not a general connectivity failure.
What to check
- Review the cryptographic proposals configured on both peers and identify their shared DH group set.
- Check whether a recent hardening baseline disabled the group that an older peer still proposes.
- Prefer updating the peer or aligning supported proposals over re-enabling weak legacy cryptography.
Get-NetIPsecMainModeRule
Microsoft: Get-NetIPsecMainModeRule
Microsoft: Audit IPsec Main Mode
Microsoft: IPsec/IKE system error codes
Looking for a different code? Search another status or error code.