Article ID: 946887 - Last Review: September 18, 2008 - Revision: 1.0
A Windows Vista or Windows Server 2008-based computer cannot negotiate the security mode with the partner if you use a subnet address as a source address or as a destination filter address when you configure IPsec policy to use tunnel mode
In a
network environment, you configure the Internet
Protocol security
(IPsec) policy to use the tunnel mode.
In
the IP Filter Properties dialog box of the IPsec policy, you
use a subnet address for the Source Address or for
the Destination Address.
You try to establish the IPsec tunnel-mode connection to
a partner computer from a Windows Vista-based computer or
from a Windows Server 2008-based computer.
In this scenario, the computer cannot
negotiate the security mode with the partner computer. Therefore, you cannot
use IPsec to secure the connection.
A
supported hotfix is available from Microsoft. However, this hotfix is intended
to correct only the problem that is described in this article. Apply this
hotfix only to systems that are experiencing this specific problem. This hotfix
might receive additional testing. Therefore, if you are not severely affected
by this problem, we recommend that you wait for the next software update that
contains this hotfix.
If the hotfix is available for download, there
is a "Hotfix download available" section at the top of this Knowledge Base
article. If this section does not appear, contact Microsoft Customer Service
and Support to obtain the hotfix.
Note If additional issues occur or if any troubleshooting is required,
you might have to create a separate service request. The usual support costs
will apply to additional support questions and issues that do not qualify for
this specific hotfix. For a complete list of Microsoft Customer Service and
Support telephone numbers or to create a separate service request, visit the
following Microsoft Web site:
Note The "Hotfix download available" form displays the languages for
which the hotfix is available. If you do not see your language, it is because a
hotfix is not available for that language.
Prerequisites
To apply this hotfix on Windows Vista-based computer, you must
have Windows Vista SP1 installed.
For more information, click the following
article number to view the article in the Microsoft Knowledge Base:
935791
(http://support.microsoft.com/kb/935791/
)
How to obtain the latest Windows Vista service pack
No prerequisites are required for Windows
Server 2008-based computers.
Restart requirement
You have to restart the computer after you apply this hotfix.
Hotfix replacement information
This hotfix does not replace a previously released hotfix.
File information
The English version of this hotfix has the file attributes (or later file attributes) that are listed in the following table. The dates and times for these files are listed in Coordinated Universal Time (UTC). When you view the file information, it is converted to local time. To find the difference between UTC and local time, use the Time Zone tab in the Date and Time item in Control Panel.
Windows Vista and Windows Server 2008 file information notes
The .manifest files and the .mum files that are installed in each environment are listed separately in the "Additional file information for Windows Server 2008 and for Windows Vista" section. These files and their associated .cat (security catalog) files are critical to maintaining the state of the updated component. The .cat files are signed with a Microsoft digital signature. The attributes of these security files are not listed.
For all supported x86-based versions of Windows Server 2008 and of Windows Vista
Collapse this tableExpand this table
File name
File version
File
size
Date
Time
Platform
Fwremotesvr.dll
6.0.6001.22122
28,672
26-Feb-2008
05:26
x86
Ipsecsvc.dll
6.0.6001.22122
361,984
26-Feb-2008
05:27
x86
Ipsecsvc.mof
Not
Applicable
1,278
18-Dec-2007
21:07
Not
Applicable
Polstore.dll
6.0.6001.22122
272,896
26-Feb-2008
05:30
x86
Polstore.mof
Not
Applicable
1,275
18-Dec-2007
21:07
Not
Applicable
Winipsec.dll
6.0.6001.22122
61,440
26-Feb-2008
05:31
x86
Winipsec.mof
Not
Applicable
1,270
18-Dec-2007
21:07
Not
Applicable
For all supported x64-based versions of Windows Server 2008 and of Windows Vista
Collapse this tableExpand this table
File name
File version
File
size
Date
Time
Platform
Fwremotesvr.dll
6.0.6001.22122
50,176
26-Feb-2008
05:55
x64
Ipsecsvc.dll
6.0.6001.22122
530,944
26-Feb-2008
05:56
x64
Ipsecsvc.mof
Not
Applicable
1,278
18-Dec-2007
21:07
Not
Applicable
Polstore.dll
6.0.6001.22122
380,928
26-Feb-2008
05:59
x64
Polstore.mof
Not
Applicable
1,275
18-Dec-2007
21:07
Not
Applicable
Winipsec.dll
6.0.6001.22122
100,864
26-Feb-2008
06:00
x64
Winipsec.mof
Not
Applicable
1,270
18-Dec-2007
21:07
Not
Applicable
Fwremotesvr.dll
6.0.6001.22122
28,672
26-Feb-2008
05:26
x86
Ipsecsvc.mof
Not
Applicable
1,278
18-Dec-2007
21:07
Not
Applicable
Polstore.dll
6.0.6001.22122
272,896
26-Feb-2008
05:30
x86
Polstore.mof
Not
Applicable
1,275
18-Dec-2007
21:07
Not
Applicable
Winipsec.dll
6.0.6001.22122
61,440
26-Feb-2008
05:31
x86
Winipsec.mof
Not
Applicable
1,270
18-Dec-2007
21:07
Not
Applicable
For all supported IA-64-based versions of Windows Server 2008