Site icon EfmSoft

What does Windows error code 13025 (WARNING_IPSEC_QM_POLICY_PRUNED) mean?

 
Previous Next
WARNING_IPSEC_MM_POLICY_PRUNED ERROR_IPSEC_IKE_NEG_STATUS_BEGIN

WARNING_IPSEC_QM_POLICY_PRUNED

The Quick Mode policy was successfully added, but some of the requested offers are not supported.

WARNING_IPSEC_QM_POLICY_PRUNED is Win32 error 13025 (0x000032E1) in Windows IPsec, IKE, and AuthIP policy processing.

Likely impact: Traffic can be protected successfully while the effective cryptographic choices differ from the requested policy.

Typical causes

  • unsupported ESP or AH proposals were requested.
  • algorithm policy differs between systems.
  • invalid lifetime or PFS combinations are pruned.
  • an old template targets obsolete capabilities.

Troubleshooting steps

  1. Verify that the effective Quick Mode offer set still contains acceptable data-protection algorithms and lifetimes.
  2. Collect requested and effective Quick Mode offers and ESP/AH algorithms and lifetimes.
  3. Correlate PFS settings with IKEEXT operational events, Windows Filtering Platform events, IPsec security audits, policy export, peer configuration, and packet capture.

Useful evidence

  • Collect OS and provider capabilities.
  • Collect test Security Association parameters.

Recovery and retry

Compare the installed offers with the intended security baseline and replace unsupported combinations; do not treat the warning as a complete rollback.

Related errors

WARNING_IPSEC_MM_POLICY_PRUNED concerns Main Mode negotiation; this warning concerns traffic-protection offers after peer establishment

Example

A template requests three Quick Mode suites, one unsupported. The remaining two install, and a test SA confirms which suite peers actually negotiate.

References


Looking for a different code? Search another status or error code.

Exit mobile version