<div class="content"><p>The <b>IKEV2_TUNNEL_CONFIG_PARAMS_3</b> structure<a id="Appendix_A_Target_176"></a><a aria-label="Product behavior note 176" href="3bb906f0-b077-47ab-ad11-d8d807afde26#Appendix_A_176" data-linktype="relative-path">&lt;176&gt;</a> is used to get or set
configured parameters for IKEv2 devices (see <a href="https://go.microsoft.com/fwlink/?LinkId=90469" data-linktype="external">[RFC4306]</a>).</p><table>
 <tbody><tr>
  <th><p><br/>0</p></th>
  <th><p><br/>1</p></th>
  <th><p><br/>2</p></th>
  <th><p><br/>3</p></th>
  <th><p><br/>4</p></th>
  <th><p><br/>5</p></th>
  <th><p><br/>6</p></th>
  <th><p><br/>7</p></th>
  <th><p><br/>8</p></th>
  <th><p><br/>9</p></th>
  <th><p>1<br/>0</p></th>
  <th><p><br/>1</p></th>
  <th><p><br/>2</p></th>
  <th><p><br/>3</p></th>
  <th><p><br/>4</p></th>
  <th><p><br/>5</p></th>
  <th><p><br/>6</p></th>
  <th><p><br/>7</p></th>
  <th><p><br/>8</p></th>
  <th><p><br/>9</p></th>
  <th><p>2<br/>0</p></th>
  <th><p><br/>1</p></th>
  <th><p><br/>2</p></th>
  <th><p><br/>3</p></th>
  <th><p><br/>4</p></th>
  <th><p><br/>5</p></th>
  <th><p><br/>6</p></th>
  <th><p><br/>7</p></th>
  <th><p><br/>8</p></th>
  <th><p><br/>9</p></th>
  <th><p>3<br/>0</p></th>
  <th><p><br/>1</p></th>
 </tr>
 <tr>
  <td colspan="32">
  <p>dwIdleTimeout</p>
  </td>
 </tr>
 <tr>
  <td colspan="32">
  <p>dwNetworkBlackoutTime</p>
  </td>
 </tr>
 <tr>
  <td colspan="32">
  <p>dwSaLifeTime</p>
  </td>
 </tr>
 <tr>
  <td colspan="32">
  <p>dwSaDataSizeForRenegotiation</p>
  </td>
 </tr>
 <tr>
  <td colspan="32">
  <p>dwConfigOptions</p>
  </td>
 </tr>
 <tr>
  <td colspan="32">
  <p>dwTotalCertificates</p>
  </td>
 </tr>
 <tr>
  <td colspan="32">
  <p>certificateNames
  (variable)</p>
  </td>
 </tr>
 <tr>
  <td colspan="32">
  <p>...</p>
  </td>
 </tr>
 <tr>
  <td colspan="32">
  <p>machineCertificateName
  (variable)</p>
  </td>
 </tr>
 <tr>
  <td colspan="32">
  <p>...</p>
  </td>
 </tr>
 <tr>
  <td colspan="32">
  <p>dwEncryptionType</p>
  </td>
 </tr>
 <tr>
  <td colspan="32">
  <p>customPolicy</p>
  </td>
 </tr>
 <tr>
  <td colspan="32">
  <p>...</p>
  </td>
 </tr>
 <tr>
  <td colspan="32">
  <p>dwTotalEkus</p>
  </td>
 </tr>
 <tr>
  <td colspan="32">
  <p>certificateEKUs
  (variable)</p>
  </td>
 </tr>
 <tr>
  <td colspan="32">
  <p>...</p>
  </td>
 </tr>
 <tr>
  <td colspan="32">
  <p>machineCertificateHash
  (variable)</p>
  </td>
 </tr>
 <tr>
  <td colspan="32">
  <p>...</p>
  </td>
 </tr>
</tbody></table><p><b>dwIdleTimeout (4 bytes): </b>Same as <b>dwIdleTimeout</b>
in <a href="de7aef9f-4865-4281-b800-db5142bf7a45" data-linktype="relative-path"><b>IKEV2_TUNNEL_CONFIG_PARAMS_1
(section</b></a><span><b> </b></span>2.2.1.2.136).  </p><p><b>dwNetworkBlackoutTime (4 bytes): </b>Same as <b>dwNetworkBlackoutTime</b>
in <b>IKEV2_TUNNEL_CONFIG_PARAMS_1</b>. </p><p><b>dwSaLifeTime (4 bytes): </b>Same as <b>dwSaLifeTime</b>
in <b>IKEV2_TUNNEL_CONFIG_PARAMS_1</b>. </p><p><b>dwSaDataSizeForRenegotiation (4 bytes): </b>Same
as <b>dwSaDataSizeForRenegotiation</b> in <b>IKEV2_TUNNEL_CONFIG_PARAMS_1</b>. </p><p><b>dwConfigOptions (4 bytes): </b>Same as <b>dwConfigOptions</b>
in <b>IKEV2_TUNNEL_CONFIG_PARAMS_1</b>. </p><p><b>dwTotalCertificates (4 bytes): </b>Same as <b>dwTotalCertificates</b>
in <b>IKEV2_TUNNEL_CONFIG_PARAMS_1</b>. </p><p><b>certificateNames (variable): </b>Same as <b>certificateNames</b>
in <b>IKEV2_TUNNEL_CONFIG_PARAMS_1</b>. </p><p><b>machineCertificateName (variable): </b>Same as
machineCertificateName in <b>IKEV2_TUNNEL_CONFIG_PARAMS_2</b> (section <a href="0351b688-0da2-4a6f-bd92-f24a22840f1a" data-linktype="relative-path">2.2.1.2.238</a>).</p><p><b>dwEncryptionType (4 bytes): </b>Same as <b>dwEncryptionType</b>
in <b>IKEV2_TUNNEL_CONFIG_PARAMS_2</b>. </p><p><b>customPolicy (8 bytes): </b>Same as customPolicy
in <b>IKEV2_TUNNEL_CONFIG_PARAMS_2</b>. </p><p><b>dwTotalEkus (4 bytes): </b>Total number of <a href="fc2dfae9-0d04-4e1d-97c9-c51c2dc06c3b#gt_06beeb29-6e93-4472-a53d-bbd51eca5759" data-linktype="relative-path">EKUs</a> in member variable
certificateEKUs.</p><p><b>certificateEKUs (variable): </b>An array of <a href="427c6983-c599-40c9-bdf6-52792d1ee160" data-linktype="relative-path"><b>CERT_EKU_1 (section
2.2.1.2.246)</b></a> that specifies the EKU parameter of the certificates that
are accepted by the RemoteAccess server for IKEv2 tunnel-based VPN
connections.  </p><p><b>machineCertificateHash (variable): </b>This MUST
be a <a href="b44c33b9-607a-4fee-894c-8af13f86ac5a" data-linktype="relative-path"><b>CERT_BLOB_1
(section</b></a><span><b> </b></span>2.2.1.2.135). This
member specifies the hash of the X.509 <a href="fc2dfae9-0d04-4e1d-97c9-c51c2dc06c3b#gt_7a0f4b71-23ba-434f-b781-28053ed64879" data-linktype="relative-path">certificate</a> that is
configured to be sent to the peer for authentication during the <a href="fc2dfae9-0d04-4e1d-97c9-c51c2dc06c3b#gt_d334f339-380f-4f63-9e8a-04b4226653df" data-linktype="relative-path">MM SA</a> negotiation [RFC4306]
for the IKE2 tunnel-based VPN connections. A zero (0) value for the <b>cbData</b>
member of <b>CERT_BLOB_1</b> indicates that no certificate is configured.  </p></div>