| Previous | Next |
| ERROR_IPSEC_IKE_INVALID_AUTH_PAYLOAD | ERROR_IPSEC_IKE_SHUTTING_DOWN |
ERROR_IPSEC_IKE_DOS_COOKIE_SENT
The responder is challenging the initiator before allocating full state
Microsoft IKE extensions define a denial-of-service protection mode in which the responder sends a Notify payload containing a cookie and discards the initial message. The initiator must return the cookie in a later message so the responder can validate it before continuing normal IKE processing. This status records that challenge; it is not itself an authentication failure.
A burst of cookie-sent events can indicate that DoS protection is active or that initiators repeatedly fail to return valid cookies. Packet capture should show the challenge and subsequent message sequence. Do not confuse the Microsoft IKEv1 extension with an ESP anti-replay failure in the IPsec data path.
What to inspect
- Verify the initiator receives the Notify and returns the responder cookie.
- Check for NAT or load-balancing behavior that sends the follow-up packet to different responder state.
- Correlate with audit event 4646, which reports entry into IKE DoS-prevention mode.
References
Looking for a different code? Search another status or error code.
