Article ID: 917025 - Last Review: December 4, 2007 - Revision: 1.4 Error message when you configure an IPsec VPN on a computer that is running ISA Server 2004 and Forefront Threat Management Gateway, Medium Business Edition or Windows Essential Business Server 2008: "0xc0040014 FWX_E_FWE_SPOOFING_PACKET_DROPPED"Important This article contains information about how to modify the registry. Make sure to back up the registry before you modify it. Make sure that you know how to restore the registry if a problem occurs. For more information about how to back up, restore, and modify the registry, click the following article number to view the article in the Microsoft Knowledge Base: 256986
(http://support.microsoft.com/kb/256986/
)
Description of the Microsoft Windows registry SYMPTOMSConsider the following scenario:
0xc0040014 FWX_E_FWE_SPOOFING_PACKET_DROPPED
838114
(http://support.microsoft.com/kb/838114/
)
How to disable the IP Spoof Detection feature in Microsoft ISA Server 2004
CAUSEThis problem occurs because the firewall engine kernel-mode driver checks all IPsec tunnel mode connections for IP address spoofing. During Internet Key Exchange (IKE) negotiation, the IPSec driver blocks all packets from the IPsec tunnel and then queues the packets. After a successful IKE negotiation, the IPSec driver sets a special flag on these packets and then puts the packets in the IP stack. Then, the firewall engine kernel-mode driver does not read the flags correctly and treats the packets as spoofed. WORKAROUNDWarning Serious problems might occur if you modify the registry incorrectly by using Registry Editor or by using another method. These problems might require that you reinstall your operating system. Microsoft cannot guarantee that these problems can be solved. Modify the registry at your own risk. To work around this problem, you must increase the time-out value for IPSec Security Association Idle Timer. To do this, follow these steps:
APPLIES TO
| Article Translations
|

Back to the top
