Microsoft-Windows-TunnelDriver

28 events across 1 channel

EventTitleChannelSample
1000Tunnel Driver of type TunnelType successfully initialized with index Index.Microsoft-Windows-TunnelDriverN
1001Tunnel Driver of type TunnelType could not initialize.Microsoft-Windows-TunnelDriverN
1002Tunnel Driver Load: TunnelType.Microsoft-Windows-TunnelDriverN
1003Tunnel Updated flag for Interface with index InterfaceIndex, interface …Microsoft-Windows-TunnelDriverN
1004Tunnel received packet with incomplete inner IP headerMicrosoft-Windows-TunnelDriverN
1005Could not find tunnel interface for packet.Microsoft-Windows-TunnelDriverN
1006Packet filter on tunnel interface InterfaceIndex is off.Microsoft-Windows-TunnelDriverN
1007Packet failed integrity check on interface type TunnelType with index …Microsoft-Windows-TunnelDriverN
1008Non IPv6 Packet received on interface InterfaceIndex.Microsoft-Windows-TunnelDriverN
1009Could not find tunnel interface for truncated ICMP message.Microsoft-Windows-TunnelDriverN
1010Could not find the source of the ICMP message on tunnel interface …Microsoft-Windows-TunnelDriverN
1011Failed to copy Buffer into MDL while generating ICMPv6 message on tunnel …Microsoft-Windows-TunnelDriverN
1012Completing the pause for tunnel interface InterfaceIndex.Microsoft-Windows-TunnelDriverN
1013Completing power notification for tunnel interface InterfaceIndex.Microsoft-Windows-TunnelDriverN
1014Tunnel interface InterfaceIndex has media status set to MediaStatus.Microsoft-Windows-TunnelDriverN
1015Tunnel interface InterfaceIndex ReadError could not be read.Microsoft-Windows-TunnelDriverN
1016Tunnel interface Index has unknown type TunnelType.Microsoft-Windows-TunnelDriverN
1017Tunnel interface of type TunnelType with index Index has been …Microsoft-Windows-TunnelDriverN
1018Teredo Tunnel offload TeredoFlowTuple flow entry freed.Microsoft-Windows-TunnelDriverN
1019Teredo WFP receive path worker has NULL clone list.Microsoft-Windows-TunnelDriverN
1020Skipped offload flow creation for non-Teredo address pair.Microsoft-Windows-TunnelDriverN
1021Teredo Wfp created IPv4 flow with following parameters.Microsoft-Windows-TunnelDriverN
1022Teredo Wfp registration occured with status NTStatus.Microsoft-Windows-TunnelDriverN
1023Teredo Wfp created V6 flow with status NTStatus following parameters.Microsoft-Windows-TunnelDriverN
1024Tunnel type TunnelType with index TunnelInterfaceIndex has IPv4 address …Microsoft-Windows-TunnelDriverN
1025Tunnel type TunnelType offloaded OffloadedNblCount NBLs, Could not offload …Microsoft-Windows-TunnelDriverN
1026Tunnel Type TunnelType with index InterfaceIndex is in an invalid device state …Microsoft-Windows-TunnelDriverN
1027Teredo tunnel callout wasn't allowed to modify a packet.Microsoft-Windows-TunnelDriverN

Event ID 1000: Tunnel Driver of type TunnelType successfully initialized with index Index.

#
Provider
Microsoft-Windows-TunnelDriver
Channel
Microsoft-Windows-TunnelDriver

Description

Tunnel Driver of type TunnelType successfully initialized with index Index.

Message #

Tunnel Driver of type %1 successfully initialized with index %2.

Fields #

NameDescription
TunnelType UInt32
Index UInt32

Event ID 1001: Tunnel Driver of type TunnelType could not initialize.

#
Provider
Microsoft-Windows-TunnelDriver
Channel
Microsoft-Windows-TunnelDriver

Description

Tunnel Driver of type TunnelType could not initialize.

Message #

Tunnel Driver of type %1 could not initialize.
 Windows Status Code %2, Tunnel Status Code %3.

Fields #

NameDescription
TunnelType UInt32
ErrorCode UInt32
TunnelReasonCode UInt32

Event ID 1002: Tunnel Driver Load: TunnelType.

#
Provider
Microsoft-Windows-TunnelDriver
Channel
Microsoft-Windows-TunnelDriver

Description

Tunnel Driver Load: TunnelType. Status ErrorCode.

Message #

Tunnel Driver Load: %1. Status %2

Fields #

NameDescription
TunnelType UInt32
ErrorCode UInt32

Event ID 1003: Tunnel Updated flag for Interface with index InterfaceIndex, interface forwarding isForwardingset, weakhostreceive isWeakHostReceiveset.

#
Provider
Microsoft-Windows-TunnelDriver
Channel
Microsoft-Windows-TunnelDriver

Description

Tunnel Updated flag for Interface with index InterfaceIndex, interface forwarding isForwardingset, weakhostreceive isWeakHostReceiveset.

Message #

Tunnel Updated flag for Interface with index %1, interface forwarding is%2set, weakhostreceive is%3set.

Fields #

NameDescription
InterfaceIndex UInt32
Forwarding UInt32
WeakHostReceive UInt32

Event ID 1004: Tunnel received packet with incomplete inner IP header

#
Provider
Microsoft-Windows-TunnelDriver
Channel
Microsoft-Windows-TunnelDriver

Description

Tunnel received packet with incomplete inner IP header.

Message #

Tunnel received packet with incomplete inner IP header

Event ID 1005: Could not find tunnel interface for packet.

#
Provider
Microsoft-Windows-TunnelDriver
Channel
Microsoft-Windows-TunnelDriver

Description

Could not find tunnel interface for packet.

Message #

Could not find tunnel interface for packet.

Event ID 1006: Packet filter on tunnel interface InterfaceIndex is off.

#
Provider
Microsoft-Windows-TunnelDriver
Channel
Microsoft-Windows-TunnelDriver

Description

Packet filter on tunnel interface InterfaceIndex is off. Dropping Packet.

Message #

Packet filter on tunnel interface %1 is off. Dropping Packet.

Fields #

NameDescription
InterfaceIndex UInt32

Event ID 1007: Packet failed integrity check on interface type TunnelType with index InterfaceIndex.

#
Provider
Microsoft-Windows-TunnelDriver
Channel
Microsoft-Windows-TunnelDriver

Description

Packet failed integrity check on interface type TunnelType with index InterfaceIndex.

Message #

Packet failed integrity check on interface type %1 with index %2.

Fields #

NameDescription
TunnelType UInt32
InterfaceIndex UInt32

Event ID 1008: Non IPv6 Packet received on interface InterfaceIndex.

#
Provider
Microsoft-Windows-TunnelDriver
Channel
Microsoft-Windows-TunnelDriver

Description

Non IPv6 Packet received on interface InterfaceIndex.

Message #

Non IPv6 Packet received on interface %1.

Fields #

NameDescription
InterfaceIndex UInt32

Event ID 1009: Could not find tunnel interface for truncated ICMP message.

#
Provider
Microsoft-Windows-TunnelDriver
Channel
Microsoft-Windows-TunnelDriver

Description

Could not find tunnel interface for truncated ICMP message.

Message #

Could not find tunnel interface for truncated ICMP message.

Event ID 1010: Could not find the source of the ICMP message on tunnel interface InterfaceIndex.

#
Provider
Microsoft-Windows-TunnelDriver
Channel
Microsoft-Windows-TunnelDriver

Description

Could not find the source of the ICMP message on tunnel interface InterfaceIndex.

Message #

Could not find the source of the ICMP message on tunnel interface %1.

Fields #

NameDescription
InterfaceIndex UInt32

Event ID 1011: Failed to copy Buffer into MDL while generating ICMPv6 message on tunnel interface InterfaceIndex.

#
Provider
Microsoft-Windows-TunnelDriver
Channel
Microsoft-Windows-TunnelDriver

Description

Failed to copy Buffer into MDL while generating ICMPv6 message on tunnel interface InterfaceIndex.

Message #

Failed to copy Buffer into MDL while generating ICMPv6 message on tunnel interface %1.

Fields #

NameDescription
InterfaceIndex UInt32

Event ID 1012: Completing the pause for tunnel interface InterfaceIndex.

#
Provider
Microsoft-Windows-TunnelDriver
Channel
Microsoft-Windows-TunnelDriver

Description

Completing the pause for tunnel interface InterfaceIndex.

Message #

Completing the pause for tunnel interface %1.

Fields #

NameDescription
InterfaceIndex UInt32

Event ID 1013: Completing power notification for tunnel interface InterfaceIndex.

#
Provider
Microsoft-Windows-TunnelDriver
Channel
Microsoft-Windows-TunnelDriver

Description

Completing power notification for tunnel interface InterfaceIndex.

Message #

Completing power notification for tunnel interface %1.

Fields #

NameDescription
InterfaceIndex UInt32

Event ID 1014: Tunnel interface InterfaceIndex has media status set to MediaStatus.

#
Provider
Microsoft-Windows-TunnelDriver
Channel
Microsoft-Windows-TunnelDriver

Description

Tunnel interface InterfaceIndex has media status set to MediaStatus.

Message #

Tunnel interface %1 has media status set to %2.

Fields #

NameDescription
InterfaceIndex UInt32
MediaStatus UInt32

Event ID 1015: Tunnel interface InterfaceIndex ReadError could not be read.

#
Provider
Microsoft-Windows-TunnelDriver
Channel
Microsoft-Windows-TunnelDriver

Description

Tunnel interface InterfaceIndex ReadError could not be read.

Message #

Tunnel interface %1 %3 could not be read.
NDIS returned status %2.

Fields #

NameDescription
InterfaceIndex UInt32
ErrorCode UInt32
ReadError UInt32

Event ID 1016: Tunnel interface Index has unknown type TunnelType.

#
Provider
Microsoft-Windows-TunnelDriver
Channel
Microsoft-Windows-TunnelDriver

Description

Tunnel interface Index has unknown type TunnelType.

Message #

Tunnel interface %1 has unknown type %2.

Fields #

NameDescription
Index UInt32
TunnelType UInt32

Event ID 1017: Tunnel interface of type TunnelType with index Index has been InterfaceOperation.

#
Provider
Microsoft-Windows-TunnelDriver
Channel
Microsoft-Windows-TunnelDriver

Description

Tunnel interface of type TunnelType with index Index has been InterfaceOperation.

Message #

Tunnel interface of type %1 with index %2 has been %3.

Fields #

NameDescription
TunnelType UInt32
Index UInt32
InterfaceOperation UInt32

Event ID 1018: Teredo Tunnel offload TeredoFlowTuple flow entry freed.

#
Provider
Microsoft-Windows-TunnelDriver
Channel
Microsoft-Windows-TunnelDriver

Description

Teredo Tunnel offload TeredoFlowTuple flow entry freed.

Message #

Teredo Tunnel offload %1 flow entry freed.

Fields #

NameDescription
TeredoFlowTuple UInt32

Event ID 1019: Teredo WFP receive path worker has NULL clone list.

#
Provider
Microsoft-Windows-TunnelDriver
Channel
Microsoft-Windows-TunnelDriver

Description

Teredo WFP receive path worker has NULL clone list.

Message #

Teredo WFP receive path worker has NULL clone list.

Event ID 1020: Skipped offload flow creation for non-Teredo address pair.

#
Provider
Microsoft-Windows-TunnelDriver
Channel
Microsoft-Windows-TunnelDriver

Description

Skipped offload flow creation for non-Teredo address pair.

Message #

Skipped offload flow creation for non-Teredo address pair.
Local %2 Remote %3.

Fields #

NameDescription
IpAddrV6Length UInt32
LocalIpv6Address Binary
RemoteIPv6Address Binary

Event ID 1021: Teredo Wfp created IPv4 flow with following parameters.

#
Provider
Microsoft-Windows-TunnelDriver
Channel
Microsoft-Windows-TunnelDriver

Description

Teredo Wfp created IPv4 flow with following parameters.

Message #

Teredo Wfp created IPv4 flow with following parameters.
LocalV4:%1 RemoteV4:%2 
LocalPort:%3 RemotePort:%4.

Fields #

NameDescription
SourceIPv4Address UInt32
DestinationIPv4Address UInt32
SourcePort UInt16
DestinationPort UInt16

Event ID 1022: Teredo Wfp registration occured with status NTStatus.

#
Provider
Microsoft-Windows-TunnelDriver
Channel
Microsoft-Windows-TunnelDriver

Description

Teredo Wfp registration occured with status NTStatus.

Message #

Teredo Wfp registration occured with status %1.

Fields #

NameDescription
NTStatus UInt32NTSTATUS reference

Event ID 1023: Teredo Wfp created V6 flow with status NTStatus following parameters.

#
Provider
Microsoft-Windows-TunnelDriver
Channel
Microsoft-Windows-TunnelDriver

Description

Teredo Wfp created V6 flow with status NTStatus following parameters.

Message #

Teredo Wfp created V6 flow with status %6 following parameters.
LocalV4:%2 RemoteV4:%3 
LocalV6:%4 RemoteV6:%5.

Fields #

NameDescription
IpAddrV6Length UInt32
LocalIPv4Address UInt32
RemoteIPv4Address UInt32
LocalIPv6 Binary
RemoteIPv6 Binary
NTStatus UInt32NTSTATUS reference

Event ID 1024: Tunnel type TunnelType with index TunnelInterfaceIndex has IPv4 address IPv4Address now YesorNo associated with physical interface with index InterfaceIndex.

#
Provider
Microsoft-Windows-TunnelDriver
Channel
Microsoft-Windows-TunnelDriver

Description

Tunnel type TunnelType with index TunnelInterfaceIndex has IPv4 address IPv4Address now YesorNo associated with physical interface with index InterfaceIndex.

Message #

Tunnel type %1 with index %2 has IPv4 address %3 now %4 associated with physical interface with index %5.

Fields #

NameDescription
TunnelType UInt32
TunnelInterfaceIndex UInt32
IPv4Address UInt32
YesorNo UInt32
InterfaceIndex UInt32

Event ID 1025: Tunnel type TunnelType offloaded OffloadedNblCount NBLs, Could not offload ReturnedNblCount NBLs.

#
Provider
Microsoft-Windows-TunnelDriver
Channel
Microsoft-Windows-TunnelDriver

Description

Tunnel type TunnelType offloaded OffloadedNblCount NBLs, Could not offload ReturnedNblCount NBLs.

Message #

Tunnel type %1 offloaded %2 NBLs, Could not offload %3 NBLs

Fields #

NameDescription
TunnelType UInt32
OffloadedNblCount UInt32
ReturnedNblCount UInt32

Event ID 1026: Tunnel Type TunnelType with index InterfaceIndex is in an invalid device state such as not opened or being closed.

#
Provider
Microsoft-Windows-TunnelDriver
Channel
Microsoft-Windows-TunnelDriver

Description

Tunnel Type TunnelType with index InterfaceIndex is in an invalid device state such as not opened or being closed.

Message #

Tunnel Type %1 with index %2 is in an invalid device state such as not opened or being closed.
%3 NBLs could not be sent.

Fields #

NameDescription
TunnelType UInt32
InterfaceIndex UInt32
DroppedNblCount UInt32

Event ID 1027: Teredo tunnel callout wasn't allowed to modify a packet.

#
Provider
Microsoft-Windows-TunnelDriver
Channel
Microsoft-Windows-TunnelDriver

Description

Teredo tunnel callout wasn't allowed to modify a packet. PID: ProcessID. FilterID: FilterID. Flow handle FlowHandle.

Message #

Teredo tunnel callout wasn't allowed to modify a packet. PID: %1. FilterID: %2. Flow handle %3.

Fields #

NameDescription
ProcessID UInt64
FilterID UInt64
FlowHandle UInt64

Provenance

Where this provider's schema came from, and which Windows build it was observed on. Windows can change a provider's event schema between builds, so use this to judge whether it matches the build you collect from.

ETW provider GUID 4edbe902-9ed3-4cf0-93e8-b8b5fa920299

Defined in tunnel.sys, the binary that emits these events.

Observed on:

  • WS2022-20348.4893, schema read from the registered manifest, binary version 10.0.20348.1, captured 2026-06-02
  • Win11-26200.6584, schema read from the registered manifest, binary version 10.0.26100.1, captured 2026-06-02

Downloads