What does Windows error code 13868 (ERROR_IPSEC_IKE_POLICY_MATCH) mean?

 
Previous Next
ERROR_IPSEC_IKE_DECRYPT ERROR_IPSEC_IKE_UNSUPPORTED_ID

ERROR_IPSEC_IKE_POLICY_MATCH

ERROR_IPSEC_IKE_POLICY_MATCH (0x0000362C) The local and remote configuration did not produce a compatible policy match. The mismatch may involve peer identity, protected traffic selectors, authentication, algorithms, or rule scope.

What to check for ERROR_IPSEC_IKE_POLICY_MATCH

  • Compare both peers’ Main Mode authentication and crypto proposals.
  • Compare Quick Mode selectors, including local and remote subnets, ports, and protocols.
  • Check which active connection-security rule Windows selected rather than assuming the intended rule won precedence.
Get-NetIPsecMainModeRule; Get-NetIPsecQuickModeRule

Microsoft: Get-NetIPsecMainModeRule

Microsoft: Get-NetIPsecQuickModeRule

Microsoft: IPsec/IKE system error codes

Where the result is returned

This result is Win32 system error 13868 (0x0000362C) from winerror.h. AllStat describes it as “Policy match error”.


Looking for a different code? Search another status or error code.