| Previous | Next |
| ERROR_IPSEC_THROTTLE_DROP | ERROR_IPSEC_DOSP_RECEIVED_MULTICAST |
ERROR_IPSEC_DOSP_BLOCK
The drop is a configured filter decision
ERROR_IPSEC_DOSP_BLOCK records a match against an explicit IPsec DoS Protection block filter. This feature is designed for an edge computer forwarding selected IPv6 traffic between public and internal interfaces; it evaluates negotiation traffic and protected flows before forwarding. The result is not evidence that IKE authentication failed or that ESP integrity verification failed.
Inspect the DoSP address filters and their filtering flags. A block can be scoped by public and private IPv6 address or subnet, and it can intentionally override the normal allowance for established IPsec-protected traffic. Confirm which interface is classified as public and which as internal, because reversing those roles changes the direction in which the policy is applied.
Policy evidence to collect
- The matching public and private IPv6 address filters.
- Whether
FilterBlockrather thanFilterExemptwas configured. - The public and internal interface aliases active on the edge host.
- DoSP statistics and state entries for neighboring flows.
References
- Microsoft: IPsec DoS Protection architecture and filters
- Microsoft: retrieve configured DoSP settings
- Microsoft: tracked IPv6 DoSP flow state
Looking for a different code? Search another status or error code.