<div class="content" name="RRPC_FWEnumPhase1SAs" uuid="c97e0735-0754-4e68-8c82-fb3b4275d085"><p>The RRPC_FWEnumPhase1SAs method requests the server to
return all the <span><a href="d891304d-92d8-4f9f-9e60-a1f02b28ae30#gt_67cbf867-7a49-41f3-a68f-37b5f9035acb" data-linktype="relative-path">security associations</a></span>
of the <span><a href="d891304d-92d8-4f9f-9e60-a1f02b28ae30#gt_f8a5b7f0-25e0-4c81-9abf-00b56a580deb" data-linktype="relative-path">IPsec</a></span> first
negotiation phase contained in the store referenced by the <i>hPolicy</i>
handle. The method returns a linked list of all these security associations.</p><dl>
<dd>
<div><pre> unsigned long RRPC_FWEnumPhase1SAs(
   [in] FW_CONN_HANDLE rpcConnHandle,
   [in] FW_POLICY_STORE_HANDLE hPolicy,
   [in, unique] PFW_ENDPOINTS pEndpoints,
   [out, ref] unsigned long* pdwNumSAs,
   [out, size_is(, *pdwNumSAs)] PFW_PHASE1_SA_DETAILS* ppSAs
 );
</pre></div>
</dd></dl><p><b>rpcConnHandle: </b>This parameter is an <span><a href="d891304d-92d8-4f9f-9e60-a1f02b28ae30#gt_8a7f6700-8311-45bc-af10-82e10accd331" data-linktype="relative-path">RPC</a></span>
binding handle that connects to the RPC interface of the Firewall and Advanced
Security Protocol.</p><p><b>hPolicy: </b>This input parameter is an <span><a href="88f6ea4a-a946-4747-bb93-f142f1760752" data-linktype="relative-path">FW_POLICY_STORE_HANDLE</a></span>
data type. The data type MUST contain an opened policy store handle,
successfully opened with the RRPC_FWOpenPolicyStore (Opnum 0) method. This
handle MUST be of the FW_STORE_TYPE_DYNAMIC store.</p><p><b>pEndpoints: </b>This parameter is a pointer to an <span><a href="2318781e-64bc-475d-9975-02cc9d56ef0b" data-linktype="relative-path">FW_ENDPOINTS</a></span>
data type that can hold the addresses of the destination and source host. These
addresses are used to match the security associations that will be returned. If
this parameter is NULL, the method returns all IPsec first-phase security
associations.</p><p><b>pdwNumSAs: </b>This is an output parameter that on
success MUST be equal to the number of security associations returned.</p><p><b>ppSAs: </b>This is an output parameter that on
success contains a linked list of <span><a href="218b010d-ea7f-4b14-b728-aa27dc418236" data-linktype="relative-path">FW_PHASE1_SA_DETAILS</a></span>
data types, each of which represents the first-phase security association.</p><p><b>Return Values: </b>The method returns 0 if
successful; if failed, it returns a nonzero error code. The field can take any
specific error code value, as specified in <span><a href="../ms-erref/1bc92ddf-b79e-413c-bbaa-99a5281a6c90" data-linktype="relative-path">[MS-ERREF]</a></span>.
The following return values are common.</p><dl>
<dd>
<table><thead>
  <tr>
   <th>
   <p>Return value/code</p>
   </th>
   <th>
   <p>Description</p>
   </th>
  </tr>
 </thead><tbody><tr>
  <td>0x00000005 ERROR_ACCESS_DENIED</td>
  <td>The client does not have the required credentials to call the method.</td>
 </tr><tr>
  <td>0x00000032 ERROR_NOT_SUPPORTED</td>
  <td>The store handle is not of the dynamic store.</td>
 </tr><tr>
  <td>0x00000057 ERROR_INVALID_PARAMETER</td>
  <td>One of the parameters of this method is incorrect, or is required and not specified.</td>
 </tr></tbody></table>
</dd></dl><p><b>Exceptions Thrown:</b> No exceptions are thrown
beyond those thrown by the underlying RPC protocol, as specified in <span><a href="../ms-rpce/290c38b1-92fe-4229-91e6-4fc376610c15" data-linktype="relative-path">[MS-RPCE]</a></span>.
If any lower-layer errors are reported by RPC exception, this exception is
converted to an error code and reported to higher-layer protocols via the
return value.</p><p>The server MUST validate that the client is authorized to
perform the requested operation (as defined in section <span><a href="b0c93352-8371-4d63-abca-b0cc8dbcc3d7" data-linktype="relative-path">3.1.4</a></span>)
before executing this method.</p><p>When this method is called, the server looks for the binary
version of the client, which was associated with the <i>hPolicy</i> handle when
the client sent the <span><a href="2157e39a-1bf0-4e0c-abae-0811fd918b11" data-linktype="relative-path">RRPC_FWOpenPolicyStore</a></span>
call. The server compares this binary version parameter with the schema version
that it supports. If the server’s schema version is greater than the binary
version passed by the client, the server removes all FW_PHASE1_SA_DETAILS
objects that contain values that are not valid for an <span><a href="bbec7ab7-0a1d-49a4-9c8e-a4784bbe6f16" data-linktype="relative-path">FW_AUTH_SET</a></span>
(section 2.2.65) structure that has the schema version value passed by the
client.</p></div>