What does Windows error code 13870 (ERROR_IPSEC_IKE_INVALID_HASH) mean?

 
Previous Next
ERROR_IPSEC_IKE_UNSUPPORTED_ID ERROR_IPSEC_IKE_INVALID_HASH_ALG

ERROR_IPSEC_IKE_INVALID_HASH

ERROR_IPSEC_IKE_INVALID_HASH (0x0000362E) A cryptographic hash in the IKE exchange did not validate. This can indicate incompatible negotiated state, a wrong pre-shared secret or authentication context, packet corruption, or an implementation mismatch at the peer.

What to check

  • Confirm that both peers use the same authentication method and compatible integrity algorithms.
  • Check for stale IKE state after policy changes, rekeying, or gateway failover.
  • Use traces and Main Mode audit events to identify the first authentication or proposal mismatch.
Get-NetIPsecMainModeSA

Microsoft: Get-NetIPsecMainModeSA

Microsoft: Audit IPsec Main Mode

Microsoft: IPsec/IKE system error codes


Looking for a different code? Search another status or error code.