Modifier

Partager via


IPsecSaContextCreate1 function (fwpmk.h)

The IPsecSaContextCreate1 function creates an IPsec security association (SA) context.

Syntax

NTSTATUS IPsecSaContextCreate1(
  [in]            HANDLE                              engineHandle,
  [in]            const IPSEC_TRAFFIC1                *outboundTraffic,
  [in, optional]  const IPSEC_VIRTUAL_IF_TUNNEL_INFO0 *virtualIfTunnelInfo,
  [out, optional] UINT64                              *inboundFilterId,
  [out]           UINT64                              *id
);

Parameters

[in] engineHandle

Handle for an open session to the filter engine. Call FwpmEngineOpen0 to open a session to the filter engine.

[in] outboundTraffic

The outbound traffic of the SA.

[in, optional] virtualIfTunnelInfo

Details related to virtual interface tunneling.

[out, optional] inboundFilterId

Optional filter identifier of the cached inbound filter corresponding to the outboundTraffic parameter specified by the caller. Base filtering engine (BFE) may cache the inbound filter identifier and return the cached value, if available. Caller must handle the case when BFE does not have a cached value, in which case this parameter will be set to 0.

[out] id

The identifier of the IPsec SA context.

Return value

Return code/value Description
ERROR_SUCCESS
0
The IPsec SA context was created successfully.
FWP_E_* error code
0x80320001—0x80320039
A Windows Filtering Platform (WFP) specific error. See WFP Error Codes for details.
RPC_* error code
0x80010001—0x80010122
Failure to communicate with the remote or local firewall engine.
Other NTSTATUS codes An error occurred.

Remarks

This function cannot be called from within a transaction, it fails with FWP_E_TXN_IN_PROGRESS. See Object Management for more information about transactions.

This function cannot be called from within a dynamic session. The call fails with FWP_E_DYNAMIC_SESSION_IN_PROGRESS. See Object Management for more information about dynamic sessions.

The caller needs FWPM_ACTRL_ADD access to the IPsec security associations database. See Access Control for more information.

IPsecSaContextCreate1 is a specific implementation of IPsecSaContextCreate. See WFP Version-Independent Names and Targeting Specific Versions of Windows for more information.

Requirements

Requirement Value
Minimum supported client Available starting with Windows Vista.
Target Platform Universal
Header fwpmk.h
Library fwpkclnt.lib
IRQL <= PASSIVE_LEVEL

See also