| Previous | Next |
| ERROR_IPSEC_IKE_INVALID_HASH_ALG | ERROR_IPSEC_IKE_INVALID_ENCRYPT_ALG |
ERROR_IPSEC_IKE_INVALID_HASH_SIZE
ERROR_IPSEC_IKE_INVALID_HASH_SIZE (0x00003630) The received hash payload length does not match the selected algorithm or expected IKE message format. This usually indicates a malformed or incompatible peer implementation, not an ordinary network timeout.
What to check
- Verify protocol and algorithm compatibility between the Windows endpoint and the gateway.
- Check for firmware or software defects on the peer when the issue is limited to one vendor or device type.
- Capture the exchange to preserve the exact payload and proposal before opening a vendor support case.
netsh trace start capture=yes scenario=InternetClient
Microsoft: Netsh network tracing
Microsoft: Audit IPsec Main Mode
Microsoft: IPsec/IKE system error codes
Looking for a different code? Search another status or error code.
