Failure to add route [network/mask] prevented phase 2 completion

This error applies to IPsec VPN connections only. The troubleshooting steps below are for Windows only.


After the Phase 2 Security Association (SA) is established, a route can't be added to the remote network. This may be because the strongSwan service crashed while the tunnel was active.


  1. Turn off the TAP adapter then turn it on.
  2. Open the command prompt as an administrator and enter the following commands: net stop scvpn then net start scvpn