| Previous | Next |
| WARNING_IPSEC_MM_POLICY_PRUNED | ERROR_IPSEC_IKE_NEG_STATUS_BEGIN |
WARNING_IPSEC_QM_POLICY_PRUNED
The Quick Mode policy was successfully added, but some of the requested offers are not supported.
WARNING_IPSEC_QM_POLICY_PRUNED is Win32 error 13025 (0x000032E1) in Windows IPsec, IKE, and AuthIP policy processing.
Likely impact: Traffic can be protected successfully while the effective cryptographic choices differ from the requested policy.
Typical causes
- unsupported ESP or AH proposals were requested.
- algorithm policy differs between systems.
- invalid lifetime or PFS combinations are pruned.
- an old template targets obsolete capabilities.
Troubleshooting steps
- Verify that the effective Quick Mode offer set still contains acceptable data-protection algorithms and lifetimes.
- Collect requested and effective Quick Mode offers and ESP/AH algorithms and lifetimes.
- Correlate PFS settings with IKEEXT operational events, Windows Filtering Platform events, IPsec security audits, policy export, peer configuration, and packet capture.
Useful evidence
- Collect OS and provider capabilities.
- Collect test Security Association parameters.
Recovery and retry
Compare the installed offers with the intended security baseline and replace unsupported combinations; do not treat the warning as a complete rollback.
Related errors
WARNING_IPSEC_MM_POLICY_PRUNED concerns Main Mode negotiation; this warning concerns traffic-protection offers after peer establishment
Example
A template requests three Quick Mode suites, one unsupported. The remaining two install, and a test SA confirms which suite peers actually negotiate.
References
Looking for a different code? Search another status or error code.
