| Previous | Next |
| ERROR_IPSEC_IKE_INVALID_HASH_SIZE | ERROR_IPSEC_IKE_INVALID_AUTH_ALG |
ERROR_IPSEC_IKE_INVALID_ENCRYPT_ALG
ERROR_IPSEC_IKE_INVALID_ENCRYPT_ALG (0x00003631) The encryption algorithm in the IKE proposal is not supported or is disallowed by the local policy. The error must be resolved by finding a mutually supported cryptographic suite.
What to check
- Compare Main Mode encryption proposals on both peers.
- Identify whether a recent policy hardening change disabled the only common algorithm.
- Prefer upgrading or reconfiguring the peer to a supported suite rather than restoring deprecated algorithms globally.
Get-NetIPsecMainModeRule
Microsoft: Get-NetIPsecMainModeRule
Microsoft: Audit IPsec Main Mode
Microsoft: IPsec/IKE system error codes
Looking for a different code? Search another status or error code.