Site icon EfmSoft

What does Windows error code 13907 (ERROR_IPSEC_IKE_AUTHORIZATION_FAILURE_WITH_OPTIONAL_RETRY) mean?

 
Previous Next
ERROR_IPSEC_IKE_STRONG_CRED_AUTHORIZATION_FAILURE ERROR_IPSEC_IKE_STRONG_CRED_AUTHORIZATION_AND_CERTMAP_FAILURE

ERROR_IPSEC_IKE_AUTHORIZATION_FAILURE_WITH_OPTIONAL_RETRY

ERROR_IPSEC_IKE_AUTHORIZATION_FAILURE_WITH_OPTIONAL_RETRY is an authorization denial with a useful qualification: the failure may be resolved by presenting updated or different credentials, such as a smart-card credential. It is not a recommendation to retry the same handshake repeatedly.

A meaningful retry follows a change in evidence available to the authentication stack: a smart card is inserted and unlocked, a renewed certificate and its private key become available, the correct account is selected, or the directory and certificate-mapping policy has propagated. An automatic retry loop with unchanged credentials can instead create noisy IKE traffic and trigger admission controls.

Before retrying

Do not treat this code as a generic network timeout. The practical evidence is the selected credential and the authorization decision on the VPN or IPsec endpoint, supported by the corresponding event records and IKE trace.

References


Looking for a different code? Search another status or error code.

Exit mobile version