Microsoft-Windows-SharedAccess_NAT

EventTitleChannelSampleRule
30001The DHCP allocator was unable to check whether the IP address param1 is in use …OperationalNN
30002The DHCP allocator was unable to bind to the IP address param1.OperationalNN
30003The DHCP allocator was unable to allocate param1 bytes of memory.OperationalNN
30004The DHCP allocator received a message containing an unrecognized code (param1).OperationalNN
30005The DHCP allocator has detected a DHCP server with IP address param1 on the same …OperationalNN
30006The DHCP allocator encountered a network error while attempting to detect …OperationalNN
30007The DHCP allocator received a message smaller than the minimum message size.OperationalNN
30008The DHCP allocator received a message whose format was invalid.OperationalNN
30009The DHCP allocator encountered a network error while attempting to reply on IP …OperationalNN
30010The DHCP allocator received a DHCP message containing an unrecognized message …OperationalNN
30011The DHCP allocator encountered a network error while attempting to receive …OperationalNN
30012The DHCP allocator detected network address translation (NAT) enabled on the …OperationalNN
30013The DHCP allocator has disabled itself on IP address param1, since the IP …OperationalNN
30999end.OperationalNN
31001The DNS proxy agent detected network address translation (NAT) enabled on the …OperationalNN
31002The DNS proxy agent was unable to bind to the IP address param1.OperationalNN
31003The DNS proxy agent encountered a network error while attempting to receive …OperationalNN
31004The DNS proxy agent was unable to allocate param1 bytes of memory.OperationalNN
31005The DNS proxy agent encountered a network error while attempting to forward a …OperationalNN
31006The DNS proxy agent encountered a network error while attempting to forward a …OperationalNN
31007The DNS proxy agent was unable to register for notification of changes to the …OperationalNN
31008The DNS proxy agent was unable to read the local list of name resolution servers …OperationalNN
31009The DNS proxy agent was unable to resolve a query from param1 after consulting …OperationalNN
31010The DNS proxy agent was unable to initiate a demand dial connection on the …OperationalNN
31011The DNS proxy agent was unable to resolve a query because no list of name …OperationalNN
31012The DNS proxy agent encountered an error while obtaining the local list of name …OperationalNN
31013The DNS proxy agent was unable to register for notification of changes to the …OperationalNN
31014The DNS proxy agent was unable to read the ICS Domain suffix string from the …OperationalNN
31015The DNS proxy agent received a message smaller than the minimum message size.OperationalNN
31999end.OperationalNN
32001The Network Address Translator (NAT) was unable to update the local address …OperationalNN
32002The Network Address Translator (NAT) was unable to allocate param1 bytes.OperationalNN
32003The Network Address Translator (NAT) was unable to request an operation of the …OperationalNN
32004The Network Address Translator (NAT) was unable to load the kernel-mode …OperationalNN
32005The Network Address Translator (NAT) was unable to unload the kernel-mode …OperationalNN
32006The Internet Connection Sharing service could not start because another process …OperationalNN
32007The Connection Sharing component could not start because another process has …OperationalNN
32008The Network Address Translator (NAT) was unable to expand the wildcard mappings.OperationalNN
32999end.OperationalNN
34001The ICS_IPV6 failed to configure IPv6 stack.OperationalNN
34002The ICS_IPV6 was unable to allocate param1 bytes of memory.OperationalNN
34003The ICS_IPV6 was unable to allocate param1 bytes of memory.OperationalNN
34004The ICS_IPV6 was unable to allocate param1 bytes of memory.OperationalNN
34005The ICS_IPV6 was unable to allocate param1 bytes of memory.OperationalNN
34006The ICS_IPV6 was unable to allocate param1 bytes of memory.OperationalNN
34007Failed to create registry key …OperationalNN
34999end.OperationalNN

Event ID 30001: The DHCP allocator was unable to check whether the IP address param1 is in use on the network for local IP address param2.

#
Channel
Operational

Description

The DHCP allocator was unable to check whether the IP address param1 is in use on the network for local IP address param2. This error may indicate lack of support for address-resolution on the network, or an error condition on the local machine. The data is the error code.

Message #

The DHCP allocator was unable to check whether the IP address %1 is in use on the network for local IP address %2. This error may indicate lack of support for address-resolution on the network, or an error condition on the local machine. The data is the error code.

Fields #

NameDescription
param1 UnicodeString
param2 UnicodeString

Event ID 30002: The DHCP allocator was unable to bind to the IP address param1.

#
Channel
Operational

Description

The DHCP allocator was unable to bind to the IP address param1. This error may indicate a problem with TCP/IP networking. The data is the error code.

Message #

The DHCP allocator was unable to bind to the IP address %1. This error may indicate a problem with TCP/IP networking. The data is the error code.

Fields #

NameDescription
param1 UnicodeString

Event ID 30003: The DHCP allocator was unable to allocate param1 bytes of memory.

#
Channel
Operational

Description

The DHCP allocator was unable to allocate param1 bytes of memory. This may indicate that the system is low on virtual memory, or that the memory-manager has encountered an internal error.

Message #

The DHCP allocator was unable to allocate %1 bytes of memory. This may indicate that the system is low on virtual memory, or that the memory-manager has encountered an internal error.

Fields #

NameDescription
param1 UnicodeString

Event ID 30004: The DHCP allocator received a message containing an unrecognized code (param1).

#
Channel
Operational

Description

The DHCP allocator received a message containing an unrecognized code (param1). The message was neither a BOOTP request nor a BOOTP reply, and was ignored.

Message #

The DHCP allocator received a message containing an unrecognized code (%1). The message was neither a BOOTP request nor a BOOTP reply, and was ignored.

Fields #

NameDescription
param1 UnicodeString

Event ID 30005: The DHCP allocator has detected a DHCP server with IP address param1 on the same network as the interface with IP address param2.

#
Channel
Operational

Description

The DHCP allocator has detected a DHCP server with IP address on the same network as the interface with IP address . The allocator has disabled itself on the interface to avoid confusing DHCP clients.

Message #

The DHCP allocator has detected a DHCP server with IP address %1 on the same network as the interface with IP address %2. The allocator has disabled itself on the interface to avoid confusing DHCP clients.

Fields #

NameDescription
param1 UnicodeString
param2 UnicodeString

Event ID 30006: The DHCP allocator encountered a network error while attempting to detect existing DHCP servers on the network of the interface with IP address param1.

#
Channel
Operational

Description

The DHCP allocator encountered a network error while attempting to detect existing DHCP servers on the network of the interface with IP address param1. The data is the error code.

Message #

The DHCP allocator encountered a network error while attempting to detect existing DHCP servers on the network of the interface with IP address %1. The data is the error code.

Fields #

NameDescription
param1 UnicodeString

Event ID 30007: The DHCP allocator received a message smaller than the minimum message size.

#
Channel
Operational

Description

The DHCP allocator received a message smaller than the minimum message size. The message has been discarded.

Message #

The DHCP allocator received a message smaller than the minimum message size. The message has been discarded.

Event ID 30008: The DHCP allocator received a message whose format was invalid.

#
Channel
Operational

Description

The DHCP allocator received a message whose format was invalid. The message has been discarded.

Message #

The DHCP allocator received a message whose format was invalid. The message has been discarded.

Event ID 30009: The DHCP allocator encountered a network error while attempting to reply on IP address param1 to a request from a client.

#
Channel
Operational

Description

The DHCP allocator encountered a network error while attempting to reply on IP address param1 to a request from a client. The data is the error code.

Message #

The DHCP allocator encountered a network error while attempting to reply on IP address %1 to a request from a client. The data is the error code.

Fields #

NameDescription
param1 UnicodeString

Event ID 30010: The DHCP allocator received a DHCP message containing an unrecognized message type (param1) in the DHCP message type option field.

#
Channel
Operational

Description

The DHCP allocator received a DHCP message containing an unrecognized message type (param1) in the DHCP message type option field. The message has been discarded.

Message #

The DHCP allocator received a DHCP message containing an unrecognized message type (%1) in the DHCP message type option field. The message has been discarded.

Fields #

NameDescription
param1 UnicodeString

Event ID 30011: The DHCP allocator encountered a network error while attempting to receive messages on the interface with IP address param1.

#
Channel
Operational

Description

The DHCP allocator encountered a network error while attempting to receive messages on the interface with IP address param1. The data is the error code.

Message #

The DHCP allocator encountered a network error while attempting to receive messages on the interface with IP address %1. The data is the error code.

Fields #

NameDescription
param1 UnicodeString

Event ID 30012: The DHCP allocator detected network address translation (NAT) enabled on the interface with index 'param1'.

#
Channel
Operational

Description

The DHCP allocator detected network address translation (NAT) enabled on the interface with index 'param1'. The allocator has disabled itself on the interface to avoid confusing DHCP clients.

Message #

The DHCP allocator detected network address translation (NAT) enabled on the interface with index '%1'. The allocator has disabled itself on the interface to avoid confusing DHCP clients.

Fields #

NameDescription
param1 UnicodeString

Event ID 30013: The DHCP allocator has disabled itself on IP address param1, since the IP address is outside the param2/param3 scope from which addresses are being allocated t...

#
Channel
Operational

Description

The DHCP allocator has disabled itself on IP address param1, since the IP address is outside the param2/param3 scope from which addresses are being allocated to DHCP clients. To enable the DHCP allocator on this IP address, change the scope to include the IP address, or change the IP address to fall within the scope.

Message #

The DHCP allocator has disabled itself on IP address %1, since the IP address is outside the %2/%3 scope from which addresses are being allocated to DHCP clients. To enable the DHCP allocator on this IP address, change the scope to include the IP address, or change the IP address to fall within the scope.

Fields #

NameDescription
param1 UnicodeString
param2 UnicodeString
param3 UnicodeString

Event ID 30999: end.

#
Channel
Operational

Event ID 31001: The DNS proxy agent detected network address translation (NAT) enabled on the interface with index 'param1'.

#
Channel
Operational

Description

The DNS proxy agent detected network address translation (NAT) enabled on the interface with index 'param1'. The agent has disabled itself on the interface to avoid confusing clients.

Message #

The DNS proxy agent detected network address translation (NAT) enabled on the interface with index '%1'. The agent has disabled itself on the interface to avoid confusing clients.

Fields #

NameDescription
param1 UnicodeString

Event ID 31002: The DNS proxy agent was unable to bind to the IP address param1.

#
Channel
Operational

Description

The DNS proxy agent was unable to bind to the IP address param1. This error may indicate a problem with TCP/IP networking. The data is the error code.

Message #

The DNS proxy agent was unable to bind to the IP address %1. This error may indicate a problem with TCP/IP networking. The data is the error code.

Fields #

NameDescription
param1 UnicodeString

Event ID 31003: The DNS proxy agent encountered a network error while attempting to receive messages on the interface with IP address param1.

#
Channel
Operational

Description

The DNS proxy agent encountered a network error while attempting to receive messages on the interface with IP address param1. The data is the error code.

Message #

The DNS proxy agent encountered a network error while attempting to receive messages on the interface with IP address %1. The data is the error code.

Fields #

NameDescription
param1 UnicodeString

Event ID 31004: The DNS proxy agent was unable to allocate param1 bytes of memory.

#
Channel
Operational

Description

The DNS proxy agent was unable to allocate param1 bytes of memory. This may indicate that the system is low on virtual memory, or that the memory manager has encountered an internal error.

Message #

The DNS proxy agent was unable to allocate %1 bytes of memory. This may indicate that the system is low on virtual memory, or that the memory manager has encountered an internal error.

Fields #

NameDescription
param1 UnicodeString

Event ID 31005: The DNS proxy agent encountered a network error while attempting to forward a response to a client from a name resolution server on the interface w...

#
Channel
Operational

Description

The DNS proxy agent encountered a network error while attempting to forward a response to a client from a name resolution server on the interface with IP address param1. The data is the error code.

Message #

The DNS proxy agent encountered a network error while attempting to forward a response to a client from a name resolution server on the interface with IP address %1. The data is the error code.

Fields #

NameDescription
param1 UnicodeString

Event ID 31006: The DNS proxy agent encountered a network error while attempting to forward a query from the client param1 to the server param2 on the interface with IP ad...

#
Channel
Operational

Description

The DNS proxy agent encountered a network error while attempting to forward a query from the client param1 to the server param2 on the interface with IP address param3. The data is the error code.

Message #

The DNS proxy agent encountered a network error while attempting to forward a query from the client %1 to the server %2 on the interface with IP address %3. The data is the error code.

Fields #

NameDescription
param1 UnicodeString
param2 UnicodeString
param3 UnicodeString

Event ID 31007: The DNS proxy agent was unable to register for notification of changes to the local list of DNS and WINS servers.

#
Channel
Operational

Description

The DNS proxy agent was unable to register for notification of changes to the local list of DNS and WINS servers. This may indicate that system resources are low. The data is the error code.

Message #

The DNS proxy agent was unable to register for notification of changes to the local list of DNS and WINS servers. This may indicate that system resources are low. The data is the error code.

Event ID 31008: The DNS proxy agent was unable to read the local list of name resolution servers from the registry.

#
Channel
Operational

Description

The DNS proxy agent was unable to read the local list of name resolution servers from the registry. The data is the error code.

Message #

The DNS proxy agent was unable to read the local list of name resolution servers from the registry. The data is the error code.

Event ID 31009: The DNS proxy agent was unable to resolve a query from param1 after consulting all entries in the local list of name resolution servers.

#
Channel
Operational

Message #

The DNS proxy agent was unable to resolve a query from %1 after consulting all entries in the local list of name resolution servers.

Fields #

NameDescription
param1 UnicodeString

Event ID 31010: The DNS proxy agent was unable to initiate a demand dial connection on the default interface while trying to resolve a query from param1.

#
Channel
Operational

Message #

The DNS proxy agent was unable to initiate a demand dial connection on the default interface while trying to resolve a query from %1.

Fields #

NameDescription
param1 UnicodeString

Event ID 31011: The DNS proxy agent was unable to resolve a query because no list of name resolution servers is configured locally and no interface is configured a...

#
Channel
Operational

Description

The DNS proxy agent was unable to resolve a query because no list of name resolution servers is configured locally and no interface is configured as the default for name resolution.

Message #

The DNS proxy agent was unable to resolve a query because no list of name resolution servers is configured locally and no interface is configured as the default for name resolution.

Event ID 31012: The DNS proxy agent encountered an error while obtaining the local list of name resolution servers.

#
Channel
Operational

Description

The DNS proxy agent encountered an error while obtaining the local list of name resolution servers. Some DNS or WINS servers may be inaccessible to clients on the local network. The data is the error code.

Message #

The DNS proxy agent encountered an error while obtaining the local list of name resolution servers. Some DNS or WINS servers may be inaccessible to clients on the local network. The data is the error code.

Event ID 31013: The DNS proxy agent was unable to register for notification of changes to the ICS Domain suffix string.

#
Channel
Operational

Description

The DNS proxy agent was unable to register for notification of changes to the ICS Domain suffix string. This may indicate that system resources are low. The data is the error code.

Message #

The DNS proxy agent was unable to register for notification of changes to the ICS Domain suffix string. This may indicate that system resources are low. The data is the error code.

Event ID 31014: The DNS proxy agent was unable to read the ICS Domain suffix string from the registry.

#
Channel
Operational

Description

The DNS proxy agent was unable to read the ICS Domain suffix string from the registry. The data is the error code.

Message #

The DNS proxy agent was unable to read the ICS Domain suffix string from the registry. The data is the error code.

Event ID 31015: The DNS proxy agent received a message smaller than the minimum message size.

#
Channel
Operational

Description

The DNS proxy agent received a message smaller than the minimum message size. The message has been discarded.

Message #

The DNS proxy agent received a message smaller than the minimum message size. The message has been discarded.

Event ID 31999: end.

#
Channel
Operational

Event ID 32001: The Network Address Translator (NAT) was unable to update the local address resolution table to respond to requests for IP address param1 and mask param2.

#
Channel
Operational

Description

The Network Address Translator (NAT) was unable to update the local address resolution table to respond to requests for IP address param1 and mask param2. Address resolution may fail to operate for addresses in the given range. This error may indicate a problem with TCP/IP networking, or it may indicate lack of support for address resolution in the underlying network interface. The data is the error code.

Message #

The Network Address Translator (NAT) was unable to update the local address resolution table to respond to requests for IP address %1 and mask %2. Address resolution may fail to operate for addresses in the given range. This error may indicate a problem with TCP/IP networking, or it may indicate lack of support for address resolution in the underlying network interface. The data is the error code.

Fields #

NameDescription
param1 UnicodeString
param2 UnicodeString

Event ID 32002: The Network Address Translator (NAT) was unable to allocate param1 bytes.

#
Channel
Operational

Description

The Network Address Translator (NAT) was unable to allocate param1 bytes. This may indicate that the system is low on virtual memory, or that the memory manager has encountered an internal error.

Message #

The Network Address Translator (NAT) was unable to allocate %1 bytes. This may indicate that the system is low on virtual memory, or that the memory manager has encountered an internal error.

Fields #

NameDescription
param1 UnicodeString

Event ID 32003: The Network Address Translator (NAT) was unable to request an operation of the kernel-mode translation module.

#
Channel
Operational

Description

The Network Address Translator (NAT) was unable to request an operation of the kernel-mode translation module. This may indicate misconfiguration, insufficient resources, or an internal error. The data is the error code.

Message #

The Network Address Translator (NAT) was unable to request an operation of the kernel-mode translation module. This may indicate misconfiguration, insufficient resources, or an internal error. The data is the error code.

Event ID 32004: The Network Address Translator (NAT) was unable to load the kernel-mode translation module.

#
Channel
Operational

Description

The Network Address Translator (NAT) was unable to load the kernel-mode translation module. The data is the error code.

Message #

The Network Address Translator (NAT) was unable to load the kernel-mode translation module. The data is the error code.

Event ID 32005: The Network Address Translator (NAT) was unable to unload the kernel-mode translation module.

#
Channel
Operational

Description

The Network Address Translator (NAT) was unable to unload the kernel-mode translation module. The data is the error code.

Message #

The Network Address Translator (NAT) was unable to unload the kernel-mode translation module. The data is the error code.

Event ID 32006: The Internet Connection Sharing service could not start because another process has taken control of the kernel-mode translation module.

#
Channel
Operational

Event ID 32007: The Connection Sharing component could not start because another process has taken control of the kernel-mode translation module.

#
Channel
Operational

Event ID 32008: The Network Address Translator (NAT) was unable to expand the wildcard mappings.

#
Channel
Operational

Description

The Network Address Translator (NAT) was unable to expand the wildcard mappings. This may indicate misconfiguration, insufficient resources, or an internal error. The data is the error code.

Message #

The Network Address Translator (NAT) was unable to expand the wildcard  mappings. This may indicate misconfiguration, insufficient resources, or an internal error. The data is the error code.

Event ID 32999: end.

#
Channel
Operational

Event ID 34001: The ICS_IPV6 failed to configure IPv6 stack.

#
Channel
Operational

Event ID 34002: The ICS_IPV6 was unable to allocate param1 bytes of memory.

#
Channel
Operational

Description

The ICS_IPV6 was unable to allocate param1 bytes of memory. This may indicate that the system is low on virtual memory, or that the memory manager has encountered an internal error.

Message #

The ICS_IPV6 was unable to allocate %1 bytes of memory. This may indicate that the system is low on virtual memory, or that the memory manager has encountered an internal error.

Fields #

NameDescription
param1 UnicodeString

Event ID 34003: The ICS_IPV6 was unable to allocate param1 bytes of memory.

#
Channel
Operational

Description

The ICS_IPV6 was unable to allocate param1 bytes of memory. This may indicate that the system is low on virtual memory, or that the memory manager has encountered an internal error.

Message #

The ICS_IPV6 was unable to allocate %1 bytes of memory. This may indicate that the system is low on virtual memory, or that the memory manager has encountered an internal error.

Fields #

NameDescription
param1 UnicodeString

Event ID 34004: The ICS_IPV6 was unable to allocate param1 bytes of memory.

#
Channel
Operational

Description

The ICS_IPV6 was unable to allocate param1 bytes of memory. This may indicate that the system is low on virtual memory, or that the memory manager has encountered an internal error.

Message #

The ICS_IPV6 was unable to allocate %1 bytes of memory. This may indicate that the system is low on virtual memory, or that the memory manager has encountered an internal error.

Fields #

NameDescription
param1 UnicodeString

Event ID 34005: The ICS_IPV6 was unable to allocate param1 bytes of memory.

#
Channel
Operational

Description

The ICS_IPV6 was unable to allocate param1 bytes of memory. This may indicate that the system is low on virtual memory, or that the memory manager has encountered an internal error.

Message #

The ICS_IPV6 was unable to allocate %1 bytes of memory. This may indicate that the system is low on virtual memory, or that the memory manager has encountered an internal error.

Fields #

NameDescription
param1 UnicodeString

Event ID 34006: The ICS_IPV6 was unable to allocate param1 bytes of memory.

#
Channel
Operational

Description

The ICS_IPV6 was unable to allocate param1 bytes of memory. This may indicate that the system is low on virtual memory, or that the memory manager has encountered an internal error.

Message #

The ICS_IPV6 was unable to allocate %1 bytes of memory. This may indicate that the system is low on virtual memory, or that the memory manager has encountered an internal error.

Fields #

NameDescription
param1 UnicodeString

Event ID 34007: Failed to create registry key "System\\CurrentControlSet\\Services\\Tcpip6\\Parameters".

#
Channel
Operational

Event ID 34999: end.

#
Channel
Operational

Provenance

ETW provider GUID a6f32731-9a38-4159-a220-3d9b7fc5fe5d

Defined in ipnathlp.dll, which carries the event manifest.

  • WS2022-20348.4893, schema read from the registered manifest, binary version 10.0.20348.1, captured 2026-06-02 — Manifest XML pack, 1.9 MB
  • Win11-26200.6584, schema read from the registered manifest, binary version 10.0.26100.1, captured 2026-06-02 — Manifest XML pack, 2.0 MB