Microsoft-Windows-TunnelDriver
28 events across 1 channel
Event ID 1000: Tunnel Driver of type TunnelType successfully initialized with index Index.
#Event ID 1001: Tunnel Driver of type TunnelType could not initialize.
#Event ID 1002: Tunnel Driver Load: TunnelType.
#Event ID 1003: Tunnel Updated flag for Interface with index InterfaceIndex, interface forwarding isForwardingset, weakhostreceive isWeakHostReceiveset.
#Event ID 1004: Tunnel received packet with incomplete inner IP header
#Description
Tunnel received packet with incomplete inner IP header.
Message #
Event ID 1005: Could not find tunnel interface for packet.
#Description
Could not find tunnel interface for packet.
Message #
Event ID 1006: Packet filter on tunnel interface InterfaceIndex is off.
#Event ID 1007: Packet failed integrity check on interface type TunnelType with index InterfaceIndex.
#Event ID 1008: Non IPv6 Packet received on interface InterfaceIndex.
#Event ID 1009: Could not find tunnel interface for truncated ICMP message.
#Description
Could not find tunnel interface for truncated ICMP message.
Message #
Event ID 1010: Could not find the source of the ICMP message on tunnel interface InterfaceIndex.
#Event ID 1011: Failed to copy Buffer into MDL while generating ICMPv6 message on tunnel interface InterfaceIndex.
#Event ID 1012: Completing the pause for tunnel interface InterfaceIndex.
#Event ID 1013: Completing power notification for tunnel interface InterfaceIndex.
#Event ID 1014: Tunnel interface InterfaceIndex has media status set to MediaStatus.
#Event ID 1015: Tunnel interface InterfaceIndex ReadError could not be read.
#Event ID 1016: Tunnel interface Index has unknown type TunnelType.
#Event ID 1017: Tunnel interface of type TunnelType with index Index has been InterfaceOperation.
#Event ID 1018: Teredo Tunnel offload TeredoFlowTuple flow entry freed.
#Event ID 1019: Teredo WFP receive path worker has NULL clone list.
#Description
Teredo WFP receive path worker has NULL clone list.
Message #
Event ID 1020: Skipped offload flow creation for non-Teredo address pair.
#Event ID 1021: Teredo Wfp created IPv4 flow with following parameters.
#Event ID 1022: Teredo Wfp registration occured with status NTStatus.
#Description
Teredo Wfp registration occured with status NTStatus.
Message #
Fields #
| Name | Description |
|---|---|
NTStatus UInt32 | NTSTATUS reference |
Event ID 1023: Teredo Wfp created V6 flow with status NTStatus following parameters.
#Description
Teredo Wfp created V6 flow with status NTStatus following parameters.
Message #
Fields #
| Name | Description |
|---|---|
IpAddrV6Length UInt32 | |
LocalIPv4Address UInt32 | |
RemoteIPv4Address UInt32 | |
LocalIPv6 Binary | |
RemoteIPv6 Binary | |
NTStatus UInt32 | NTSTATUS reference |
Event ID 1024: Tunnel type TunnelType with index TunnelInterfaceIndex has IPv4 address IPv4Address now YesorNo associated with physical interface with index InterfaceIndex.
#Event ID 1025: Tunnel type TunnelType offloaded OffloadedNblCount NBLs, Could not offload ReturnedNblCount NBLs.
#Event ID 1026: Tunnel Type TunnelType with index InterfaceIndex is in an invalid device state such as not opened or being closed.
#Event ID 1027: Teredo tunnel callout wasn't allowed to modify a packet.
#Provenance
Where this provider's schema came from, and which Windows build it was observed on. Windows can change a provider's event schema between builds, so use this to judge whether it matches the build you collect from.
ETW provider GUID 4edbe902-9ed3-4cf0-93e8-b8b5fa920299
Defined in tunnel.sys, the binary that emits these events.
Observed on:
- WS2022-20348.4893, schema read from the registered manifest, binary version 10.0.20348.1, captured 2026-06-02
- Win11-26200.6584, schema read from the registered manifest, binary version 10.0.26100.1, captured 2026-06-02