Home

/

Knowledge Base

/

DoIP Routing Activation Failure: Response Codes, Packet Evidence, and Root-Cause Analysis

Knowledge Base

Last Updated: 2026-07-30

DoIP Routing Activation Failure: Response Codes, Packet Evidence, and Root-Cause Analysis

Routing Activation analysis starts with the response and TCP stream state. A rejection before UDS, a confirmation-required state, and later session instability are different branches that require different evidence.

Evidence Scope

This page uses controlled-simulator evidence for its rejection and confirmation cases. It does not identify BMW, another OEM, or production gateway behavior.

Response-code wording must remain scoped to the applicable Evidence Record and implementation profile.

Read the Boundary First

A rejected 0x0006 response with no UDS on that TCP stream is pre-UDS Routing Activation rejection.

A 0x11 response requires follow-up confirmation and socket-state evidence; do not treat it as equivalent to either immediate usability or a final failure.

Final Diagnosis

Routing Activation branch classified from control response and stream continuation

Confidence

High for the observed controlled sequences

Likely Root Cause

Not determined from these public-safe controlled windows

Primary Evidence

EVID-ROUTING-REJECT-00-01, EVID-ROUTING-REJECT-03-01, EVID-ROUTING-REJECT-06-01, EVID-RA-CONFIRMATION-POLL-SUCCESS-01, EVID-RA-CONFIRMATION-PENDING-FIN-01

Recommended Next Check

Confirm the ISO edition, implementation profile, and full TCP stream before assigning a deployment cause.

Capture-Backed Evidence

Each example identifies whether it is a controlled simulator observation or a redacted field-evidence window. The evidence record bounds what the sequence can and cannot establish.

Controlled source-address rejection

Pre-UDS response code 0x00

Evidence reference: EVID-ROUTING-REJECT-00-01

A controlled simulator rejects the attempted routing activation before UDS begins.

Evidence signals

  • Routing Activation Response code 0x00 is observed.
  • The rejected stream contains no UDS diagnostic message.

Real Timeline

  • activation | tester | Routing Activation Request | Control handshake starts.
  • response | DoIP entity | 0x0006 code 0x00 | Configured simulator rejects before UDS.

It identifies a control-layer rejection without assigning an ISO/OEM root cause.

Controlled duplicate-source rejection

Pre-UDS response code 0x03

Evidence reference: EVID-ROUTING-REJECT-03-01

A later connection reuses an active tester source role and is rejected before UDS.

Evidence signals

  • An earlier controlled session is accepted.
  • Later connections receive code 0x03 and carry no UDS.

Real Timeline

  • earlier | session | Routing activation accepted | Source role is active.
  • later | DoIP entity | 0x0006 code 0x03 | Later connection is rejected before UDS.

The capture does not identify which production client lifecycle would create duplicate use.

Controlled capacity branch

Pre-UDS response code 0x06

Evidence reference: EVID-ROUTING-REJECT-06-01

The configured simulator emits 0x06 while its configured capacity branch is occupied.

Evidence signals

  • One controlled routed session remains active.
  • Later activation attempts receive 0x06 before UDS.

Real Timeline

  • active session | tester / DoIP entity | Routing remains active | Configured capacity branch is occupied.
  • later attempts | DoIP entity | 0x0006 code 0x06 | Configured simulator rejects before UDS.

This is not a normative ISO/OEM interpretation of 0x06.

Confirmation-required controlled sequence

0x11 followed by 0x10 on the same TCP stream

Evidence reference: EVID-RA-CONFIRMATION-POLL-SUCCESS-01

A controlled version-0x02 sequence receives 0x11, later receives 0x10, then completes a positive diagnostic exchange.

Evidence signals

  • 0x11 is not treated as diagnostic usability.
  • A later 0x10 precedes the DoIP acknowledgement and positive UDS reply.

Real Timeline

  • initial | DoIP entity | 0x0006 code 0x11 | Confirmation remains required.
  • later | same TCP stream | 0x0006 code 0x10 | Controlled route becomes active.

It documents only the configured simulator confirmation branch, not a universal OEM procedure.

Confirmation timeout branch

0x11 retained until entity-initiated FIN

Evidence reference: EVID-RA-CONFIRMATION-PENDING-FIN-01

A configured simulator retains the confirmation-required state and later closes the TCP session without a 0x10 or UDS exchange.

Evidence signals

  • 0x11 is observed in the selected stream.
  • No later 0x10 or UDS payload occurs before the entity FIN.

Real Timeline

  • initial | DoIP entity | 0x0006 code 0x11 | Confirmation remains required.
  • timeout | DoIP entity | TCP FIN | Configured confirmation branch closes the session.

This confirms only the simulator timeout behavior, not a universal confirmation timer or production cause.

Timeline

A visual sequence helps confirm whether the session actually progressed, stalled, or broke after the visible tool symptom.

Tester

Routing Activation Request

DoIP entity

Response code or confirmation state

Session

UDS allowed or rejected

Packet Evidence

These packet-level checkpoints are the smallest proof units behind the article narrative.

Control response

DoIP entity -> tester

0x0006 response establishes the observed control branch.

Read it with the source scope and following TCP stream.

Rejected stream

tester -> DoIP entity

No UDS appears after the rejection.

Places the observed failure before UDS.

Confirmation sequence

same TCP stream

0x11 may later transition to 0x10.

Diagnostic usability is not assumed before the final active state.

Analyzer Conclusion

This is the condensed engineering verdict the analyzer would put in front of the operator.

Classify the response code and TCP stream first.

Classify the response code and TCP stream first.

Keep simulator configuration separate from ISO/OEM claims.

Keep simulator configuration separate from ISO/OEM claims.

False Positives

These are cases where the tool symptom can point in the wrong direction unless the packet timeline is checked.

Symptom: 0x11 is called a final failure.

Packet truth: The controlled sequence later reaches 0x10.

Risk: The tester may stop before confirmation completes.

Symptom: 0x06 is presented as universal socket exhaustion.

Packet truth: Only the configured simulator capacity branch is observed.

Risk: A protocol decoder label is mistaken for a production root cause.

Decision Tree

Use this order in real troubleshooting so packet evidence narrows the branch before repair effort expands.

  • 1. Confirm a 0x0006 Routing Activation Response exists.
  • 2. For a rejection, confirm no UDS appears on the rejected TCP stream.
  • 3. For 0x11, follow the later response and socket state.
  • 4. For 0x10, move to downstream diagnostic or transport analysis.

Common Misreads

These are the interpretation traps that real packet evidence helps avoid.

  • A response code alone is not a downstream ECU diagnosis.
  • A capture-observed simulator branch is not an OEM behavior claim.

Related Diagnostic Guides

Use nearby guides to move from protocol filtering to root-cause troubleshooting without leaving the knowledge base.

Wireshark Filter for Port 13400 and DoIP TrafficBMW DoIP Routing Activation Request TroubleshootingRouting Activation Succeeded but ECU Does Not Respond

Frequently Asked Questions

Does 0x10 prove the ECU will respond?

No. It proves routing activation completed at the DoIP control layer, not downstream forwarding or ECU response.

What does 0x11 prove?

Only the configured confirmation-required state in its evidence window; inspect the later response and TCP state.

Upload a DoIP capture and reconstruct Routing Activation

Use the complete TCP stream to separate control-layer rejection from later diagnostic failure.

Browse all seeded guides