| Previous | Next |
| DNS_ERROR_ZONESCOPE_IS_REFERENCED | DNS_ERROR_POLICY_INVALID_CRITERIA_TRANSPORT_PROTOCOL |
DNS_ERROR_POLICY_INVALID_CRITERIA_CLIENT_SUBNET
DNS_ERROR_POLICY_INVALID_CRITERIA_CLIENT_SUBNET means the policy cannot use the supplied client-subnet criterion. The referenced name, operator, or criterion format is not valid.
What to verify for DNS_ERROR_POLICY_INVALID_CRITERIA_CLIENT_SUBNET
- List client subnets and verify the exact name exists on the target server.
- Check the policy criterion syntax and logical operator.
- Confirm that the client IP ranges are expressed as the intended IPv4 or IPv6 prefixes.
Get-DnsServerClientSubnet
Get-DnsServerQueryResolutionPolicy -ZoneName "example.com"
Microsoft: Add-DnsServerClientSubnet
Microsoft: Get-DnsServerClientSubnet
Microsoft: Add-DnsServerQueryResolutionPolicy
Where the result is returned
This result is Win32 system error 9990 (0x00002706) from winerror.h. AllStat describes it as “The criterion client subnet provided in the policy is invalid.”. The code is useful only together with the API that failed, because multiple Windows components can reuse system-error values while imposing different retry and cleanup rules.
Diagnostic sequence
- Call GetLastError immediately after the failing API and save this result, the function name, all relevant flags, and the target path, handle, service, device, account, or policy object.
- Capture the component log that owns the dns / policy / criteria / client / subnet operation and retain the original numeric value before a framework converts it to an HRESULT or exception.
- compare preconditions with the API documentation and reproduce with a minimal request before changing system-wide configuration.
Retry this result only after the resource or state named in “The criterion client subnet provided in the policy is invalid.” has changed. For invalid parameters, unsupported formats, missing objects, policy restrictions, and access failures, correct the input or configuration instead of immediately repeating the same call.
Looking for a different code? Search another status or error code.