| Previous | Next |
| STATUS_FWP_INCOMPATIBLE_DH_GROUP | STATUS_FWP_NEVER_MATCH |
STATUS_FWP_EM_NOT_SUPPORTED
The IKE policy cannot contain an Extended Mode policy
These status values come from the Windows Filtering Platform path. For STATUS_FWP_EM_NOT_SUPPORTED, wFP classifies traffic through layers, filters, provider contexts, sublayers, and callouts; IPsec policy is also configured through WFP at IKE/AuthIP-related layers.
Extended Mode is an additional IPsec/AuthIP policy component. This status reports a policy-construction error: the selected IKE policy type does not accept Extended Mode settings.
For STATUS_FWP_EM_NOT_SUPPORTED, when this appears during IPsec or AuthIP negotiation, compare the Main Mode, Quick Mode, Extended Mode, transform, tunnel endpoint, DNS name, and authentication-method policy actually installed in WFP.
What to inspect
- Remove Extended Mode from policy types that cannot carry it.
- Check whether the policy was intended for AuthIP rather than plain IKE.
- Record the exact policy provider and layer where the policy was added.
References for STATUS_FWP_EM_NOT_SUPPORTED
- Microsoft Open Specifications: NTSTATUS values
- Microsoft: WFP error codes
- Microsoft: IPsec configuration through WFP
Looking for a different code? Search another status or error code.
