| Previous | Next |
| FWP_E_INCOMPATIBLE_DH_GROUP | FWP_E_NEVER_MATCH |
FWP_E_EM_NOT_SUPPORTED
FWP_E_EM_NOT_SUPPORTED means the selected IKE policy includes an Extended Mode policy that the WFP IPsec policy model does not allow.
What to check
- Review the policy construction path and remove unsupported legacy-policy combinations.
- Validate the policy model against the Windows IPsec APIs used by the application or deployment tool.
- Capture IKE events only after the local policy can be accepted; this HRESULT occurs before a valid negotiation configuration exists.
Microsoft: capture IPsec events with netsh wfp
Looking for a different code? Search another status or error code.
