2.69. SYSTEM

These log messages refer to the SYSTEM (System-wide events: startup, shutdown, etc..) category.

2.69.1. demo_mode (ID: 03200021)

Default Severity
ALERT
Log Message
The unit is running in DEMO mode and will eventually expire. Install a license in order to avoid this
Explanation
None
Firewall Action
lockdown_soon
Recommended Action
Install a license.
Revision
2
Parameters
lockdown
time

2.69.2. demo_mode (ID: 03200024)

Default Severity
ALERT
Log Message
The unit is now running in License Lockdown Mode. Install a license in order to avoid this
Explanation
None
Firewall Action
license_lockdown
Recommended Action
Install a license.
Revision
2

2.69.3. normal_mode (ID: 03200025)

Default Severity
NOTICE
Log Message
License file successfully loaded.
Explanation
The system is now running in normal operation mode.
Firewall Action
normal_operation
Recommended Action
None
Revision
1

2.69.4. new_firmware_available (ID: 03200030)

Default Severity
NOTICE
Log Message
New firmware available.
Explanation
A new firmware release is available for download.
Firewall Action
None
Recommended Action
Upgrade_firmware.
Revision
1

2.69.5. linktest_result (ID: 03200060)

Default Severity
INFORMATIONAL
Log Message
Linktest report
Explanation
Linktest finished with the following results for the test protocol and interface.
Firewall Action
None
Recommended Action
None
Revision
1
Parameters
protocol
status
duration
server_ip
interface
clients
iface_sent_bps
iface_received_bps
test_sent_bps
test_received_bps

2.69.6. linktest_error (ID: 03200061)

Default Severity
INFORMATIONAL
Log Message
Linktest failed
Explanation
Linktest detected problems during execution and the test was aborted.
Firewall Action
None
Recommended Action
None
Revision
1
Parameters
protocol
server_ip
interface
duration
error

2.69.7. reset_clock (ID: 03200100)

Default Severity
NOTICE
Log Message
The clock at <oldtime> was manually reset by <user> to <newtime>
Explanation
The clock has manually been reset.
Firewall Action
None
Recommended Action
None
Revision
1
Parameters
oldtime
newtime
user

2.69.8. invalid_ip_match_access_section (ID: 03200110)

Default Severity
WARNING
Log Message
Failed to verify IP address as per ACCESS section. Dropping
Explanation
The IP address was not verified according to the ACCESS section.
Firewall Action
drop
Recommended Action
None
Revision
1
Context Parameters
Rule Name
Packet Buffer

2.69.9. system_in_recovery_mode (ID: 03200118)

Default Severity
WARNING
Log Message
System is operating in recovery mode
Explanation
System encountered a boot failure and has been reverted to recovery mode, operating with constrained memory and/or reduced functionality.
Firewall Action
None
Recommended Action
Should the system persist in recovery mode following a reboot, please attach to the serial console (debug) to record and examine the output generated during the boot process.
Revision
1

2.69.10. hardware_watchdog_initialized (ID: 03200260)

Default Severity
NOTICE
Log Message
Hardware Watchdog <hardware_watchdog_chip> found and initialized with a timeout of <watchdog_timeout> minutes.
Explanation
The system has identified a Hardware Watchdog and initialized it.
Firewall Action
None
Recommended Action
None
Revision
1
Parameters
hardware_watchdog_chip
watchdog_timeout

2.69.11. port_bind_failed (ID: 03200300)

Default Severity
ALERT
Log Message
Out of memory while tying to allocate dynamic port for local IP <localip> to destination IP <destip>
Explanation
The unit failed to allocate a dynamic port, as it is out of memory.
Firewall Action
None
Recommended Action
None
Revision
1
Parameters
reason
localip
destip

2.69.12. port_bind_failed (ID: 03200301)

Default Severity
WARNING
Log Message
Out of dynamic assigned ports. All ports <port_base>-<port_end> for Local IP <localip> to Destination IP <destip> are in use
Explanation
Failed to allocate a dynamic port, as all ports are in use.
Firewall Action
None
Recommended Action
None
Revision
1
Parameters
reason
localip
destip
port_base
port_end

2.69.13. port_hlm_conversion (ID: 03200302)

Default Severity
NOTICE
Log Message
Using High Load Mode for Local IP <localip> Destination IP <destip> pair
Explanation
Mode for Local IP - Destination IP pair has changed to High Load because of heavy traffic.
Firewall Action
None
Recommended Action
None
Revision
1
Parameters
localip
destip

2.69.14. port_llm_conversion (ID: 03200303)

Default Severity
NOTICE
Log Message
Using Low Load Mode for Local IP <localip> Destination IP <destip> pair
Explanation
Mode for Local IP - Destination IP pair has changed to Low Load because of low traffic.
Firewall Action
None
Recommended Action
None
Revision
1
Parameters
localip
destip

2.69.15. log_messages_lost_due_to_throttling (ID: 03200400)

Default Severity
WARNING
Log Message
<logcnt> messages lost due to throttling
Explanation
Due to extensive logging, a number of log messages was not sent.
Firewall Action
None
Recommended Action
Examine why the unit sent such a large amount of log messages. If this is normal activity, the "LogSendPerSec" setting might be set too low.
Revision
1
Parameters
logcnt

2.69.16. log_messages_lost_due_to_log_buffer_exhaust (ID: 03200401)

Default Severity
WARNING
Log Message
<logcnt> log messages lost due to log buffer exhaustion
Explanation
Due to extensive logging, a number of log messages was not sent.
Firewall Action
None
Recommended Action
Examine why the unit sent such a large amount of log messages. If this is normal activity, the "LogSendPerSec" setting might be set too low.
Revision
1
Parameters
logcnt

2.69.17. bidir_fail (ID: 03200600)

Default Severity
CRITICAL
Log Message
Failed to establish bi-directional communication with peer in <timeout> seconds
Explanation
The unit failed to establish a connection back to peer, using the new configuration. It will try to revert to the previous configuration file.
Firewall Action
None
Recommended Action
Verify that the new configuration file does not contain errors that would cause bi-directional communication failure.
Revision
2
Parameters
localcfgver
remotecfgver
timeout

2.69.18. file_open_failed (ID: 03200602)

Default Severity
ERROR
Log Message
Failed to open newly uploaded configuration file <new_cfg>
Explanation
The unit failed to open the uploaded configuration file.
Firewall Action
None
Recommended Action
Verify that the disk media is intact.
Revision
1
Parameters
new_cfg

2.69.19. disk_cannot_remove (ID: 03200603)

Default Severity
ERROR
Log Message
Failed to remove <old_cfg>
Explanation
The unit failed to remove the old configuration file.
Firewall Action
None
Recommended Action
Verify that the disk media is intact and that the file is not write protected.
Revision
2
Parameters
old_cfg

2.69.20. disk_cannot_rename (ID: 03200604)

Default Severity
ERROR
Log Message
Failed to rename <cfg_new> to <cfg_real>
Explanation
The unit failed to rename the new configuration file to the real configuration file name.
Firewall Action
None
Recommended Action
Verify that the disk media is intact.
Revision
1
Parameters
cfg_new
cfg_real

2.69.21. cfg_switch_fail (ID: 03200605)

Default Severity
CRITICAL
Log Message
Failed to switch to new configuration
Explanation
For reasons specified in earlier log events, the unit failed to switch to the new configuration and will continue to use the present configuration.
Firewall Action
None
Recommended Action
Consult the recommended action in the previous log message, which contained a more detailed error description.
Revision
1

2.69.22. core_switch_fail (ID: 03200606)

Default Severity
CRITICAL
Log Message
Failed to switch to new core
Explanation
For reasons specified in earlier log events, the unit failed to switch to the new core executable and will continue to use the present core executable.
Firewall Action
None
Recommended Action
Consult the recommended action in the previous log message, which contained a more detailed error description.
Revision
1

2.69.23. bidir_ok (ID: 03200607)

Default Severity
NOTICE
Log Message
Configuration <localcfgver><remotecfgver> verified for bi-directional communication
Explanation
The new configuration has been verified for communication back to peer and will now be used as the active configuration.
Firewall Action
None
Recommended Action
None
Revision
2
Parameters
localcfgver
remotecfgver

2.69.24. rules_configuration_changed (ID: 03200641)

Default Severity
INFORMATIONAL
Log Message
IP Rules or Policies were altered by configuration changes made <date>
Explanation
IP Rules or Policies have been altered due to changes in the configuration.
Firewall Action
None
Recommended Action
None
Revision
1
Parameters
date

2.69.25. cms_control_disabled (ID: 03200650)

Default Severity
NOTICE
Log Message
Centralized management control has been disabled.
Explanation
Centralized management control has been disabled and local management has been enabled.
Firewall Action
None
Recommended Action
None
Revision
1

2.69.26. cms_control_enabled (ID: 03200651)

Default Severity
NOTICE
Log Message
Centralized management control has been enabled.
Explanation
Centralized management control has been enabled and local management has been disabled.
Firewall Action
None
Recommended Action
In order enable local management, use the CLI command localconfiguration.
Revision
1

2.69.27. user_blocked (ID: 03200802)

Default Severity
NOTICE
Log Message
Login for user <database>:<username> has failed: currently in blocked state for the next <blockedremaining> seconds. Blocked since: <blockedsince>.
Explanation
Too many failed login attempt for the user.
Firewall Action
None
Recommended Action
None
Revision
1
Parameters
database
username
blockedremaining
blockedsince

2.69.28. shutdown (ID: 03201000)

Default Severity
NOTICE
Log Message
Shutdown <shutdown>. Active in <time> seconds. Reason: <reason>
Explanation
The unit is shutting down.
Firewall Action
shutdown
Recommended Action
None
Revision
1
Parameters
shutdown
time
reason

2.69.29. reconfiguration (ID: 03201001)

Default Severity
NOTICE
Log Message
Initiating reconfiguration. Active in <time> seconds. Reason: <reason>
Explanation
The unit is reconfiguring.
Firewall Action
reconfiguration
Recommended Action
None
Revision
1
Parameters
time
reason

2.69.30. shutdown (ID: 03201011)

Default Severity
NOTICE
Log Message
Shutdown aborted. Core file <core> missing
Explanation
The unit was issued a shutdown command, but no core executable file is seen. The shutdown process is aborted.
Firewall Action
shutdown_gateway_aborted
Recommended Action
Verify that the disk media is intact.
Revision
1
Parameters
shutdown
reason
core

2.69.31. config_activation (ID: 03201020)

Default Severity
NOTICE
Log Message
Reconfiguration requested by <username> from <config_system> <client_ip>.
Explanation
Reconfiguration requested.
Firewall Action
reconfiguration
Recommended Action
None
Revision
2
Parameters
username
userdb"
client_ip
config_system

2.69.32. reconfiguration (ID: 03201021)

Default Severity
NOTICE
Log Message
Reconfiguration will change <change_count> access control rule(s).
Explanation
Number of access control rules changed during the reconfiguration.
Firewall Action
None
Recommended Action
None
Revision
1
Parameters
change_count

2.69.33. startup_normal (ID: 03202000)

Default Severity
NOTICE
Log Message
Firewall starting. Core: <corever>. Build: <build>. Current uptime: <uptime>. Using configuration file <cfgfile>, version <localcfgver> <remotecfgver>. Previous event: <previous_event>
Explanation
The firewall is starting up.
Firewall Action
None
Recommended Action
None
Revision
4
Parameters
corever
build
uptime
cfgfile
localcfgver
remotecfgver
previous_event

2.69.34. startup_echo (ID: 03202001)

Default Severity
NOTICE
Log Message
Firewall starting echo (<delay> seconds). Core: <corever>. Build: <build>. Current uptime: <uptime>. Using configuration file <cfgfile>, localcfgver <localcfgver>, remotecfgver <remotecfgver>. Previous event: <previous_event>
Explanation
The firewall is starting up, echo.
Firewall Action
None
Recommended Action
None
Revision
4
Parameters
delay
corever
build
uptime
cfgfile
localcfgver
remotecfgver
previous_event

2.69.35. shutdown (ID: 03202500)

Default Severity
NOTICE
Log Message
Event <event>
Explanation
The firewall is shutting down.
Firewall Action
shutdown
Recommended Action
None
Revision
2
Parameters
event

2.69.36. reconfiguration (ID: 03202501)

Default Severity
NOTICE
Log Message
Event <event>
Explanation
The firewall is reconfiguring.
Firewall Action
reconfiguration
Recommended Action
None
Revision
2
Parameters
event

2.69.37. admin_login (ID: 03203000)

Default Severity
NOTICE
Log Message
Administrative user <username> logged in via <authsystem>. Access level: <access_level>
Explanation
An administrative user has logged in to the configuration system.
Firewall Action
None
Recommended Action
None
Revision
2
Parameters
authsystem
username
access_level
[interface]
[usergroups]
[authsource]
[userdb]
[server_ip]
[server_port]
[client_ip]
[client_port]

2.69.38. admin_logout (ID: 03203001)

Default Severity
NOTICE
Log Message
Administrative user <username> logged out, via <authsystem>. Access level: <access_level>
Explanation
An administrative user has logged out from the configuration system.
Firewall Action
None
Recommended Action
None
Revision
3
Parameters
authsystem
username
access_level
[userdb]
[client_ip]

2.69.39. admin_login_failed (ID: 03203002)

Default Severity
WARNING
Log Message
Administrative user <username> failed to log in via <authsystem>, because of bad credentials
Explanation
An administrative user failed to log in to configuration system. This is most likely due to an invalid entered username or password.
Firewall Action
disallow_admin_access
Recommended Action
None
Revision
3
Parameters
authsystem
username
[interface]
[server_ip]
[server_port]
[client_ip]
[client_port]

2.69.40. admin_authorization_failed (ID: 03203003)

Default Severity
WARNING
Log Message
Administrative user <username> successfully logged in via <authsystem>, but is not authorized to access the system.
Explanation
An administrative user successfully authenticated but is not authorized to access the system.
Firewall Action
disallow_admin_access
Recommended Action
If the user should have access to the system, increase the access level of the user or one the user's groups.
Revision
1
Parameters
authsystem
interface
username
usergroups
authsource
userdb
server_ip
server_port
client_ip
client_port

2.69.41. sslvpnuser_login (ID: 03203004)

Default Severity
NOTICE
Log Message
SSL VPN user <username> logged in via <authsystem>.
Explanation
An SSL VPN user has logged in to the SSL VPN user page.
Firewall Action
None
Recommended Action
None
Revision
2
Parameters
authsystem
username
userdb
server_ip
server_port
client_ip
client_port

2.69.42. activate_changes_failed (ID: 03204000)

Default Severity
NOTICE
Log Message
Bidirectional confirmation of the new configuration failed, previous configuration will be used
Explanation
The unit failed to establish a connection back to peer, using the new configuration. The previous configuration will still be used.
Firewall Action
using_prev_config
Recommended Action
Make sure that the new configuration allows the unit to establish a connection with the administration interface.
Revision
1
Parameters
authsystem

2.69.43. accept_configuration (ID: 03204001)

Default Severity
NOTICE
Log Message
New configuration activated by user <username> from <config_system> <client_ip>.
Explanation
The new configuration has been successfully activated.
Firewall Action
using_new_config
Recommended Action
None
Revision
2
Parameters
username
userdb"
client_ip
config_system

2.69.44. reject_configuration (ID: 03204002)

Default Severity
NOTICE
Log Message
New configuration rejected by user <username> from <config_system> <client_ip>.
Explanation
The new configuration has been rejected.
Firewall Action
reconfiguration_using_old_config
Recommended Action
None
Revision
1
Parameters
username
userdb"
client_ip
config_system

2.69.45. date_time_modified (ID: 03205000)

Default Severity
NOTICE
Log Message
The local Date and Time has been modified by <user>. Time and Date before change: <pre_change_date_time>. Time and Date after change: <post_change_date_time>
Explanation
The local Date and Time of the unit has been changed.
Firewall Action
using_new_date_time
Recommended Action
None
Revision
2
Parameters
authsystem
user
pre_change_date_time
post_change_date_time

2.69.46. admin_timeout (ID: 03206000)

Default Severity
NOTICE
Log Message
Administrative user <username> timed out from <authsystem>
Explanation
The administrative user has been inactive for too long and has been automatically logged out.
Firewall Action
None
Recommended Action
None
Revision
2
Parameters
authsystem
username
userdb
client_ip
access_level

2.69.47. admin_login_group_mismatch (ID: 03206001)

Default Severity
WARNING
Log Message
Administrative user <username> not allowed access via <authsystem>
Explanation
The user does not have proper administration access to the configuration system.
Firewall Action
disallow_admin_access
Recommended Action
None
Revision
2
Parameters
authsystem
username
server_ip
server_port
client_ip
client_port

2.69.48. admin_login_internal_error (ID: 03206002)

Default Severity
WARNING
Log Message
Internal error occured when administrative user <username> tried to login, not allowed access via <authsystem>
Explanation
An internal error occured when the user tried to log in and as a result has not been given administration access.
Firewall Action
disallow_admin_access
Recommended Action
Please contact the support and report this issue.
Revision
2
Parameters
authsystem
username
server_ip
server_port
client_ip
client_port

2.69.49. admin_authsource_timeout (ID: 03206003)

Default Severity
ERROR
Log Message
Remote <authsource> server(s) could not be reached when attempting to authenticate administrative user <username>.
Explanation
The unit did not receive a response from the authentication servers and the authentication process failed.
Firewall Action
None
Recommended Action
Investigate why the configured servers are not responding to authentication requests.
Revision
1
Parameters
authsystem
interface
username
authsource
server_ip
server_port
client_ip
client_port

2.69.50. user_post_token_invalid (ID: 03206004)

Default Severity
WARNING
Log Message
<username> has provided an invalid token when attempting a POST request.
Explanation
All POST requests are required to provide a valid token for authentication.
Firewall Action
refused_post_request
Recommended Action
Please contact the support and report this issue.
Revision
1
Parameters
client_ip
username
client_port

2.69.51. valid_rest_api_call (ID: 03207000)

Default Severity
NOTICE
Log Message
REST API call
Explanation
.
Firewall Action
None
Recommended Action
None
Revision
1
Parameters
URI
Method
Context Parameters
User Authentication

2.69.52. bad_user_credentials (ID: 03207010)

Default Severity
NOTICE
Log Message
Unknown user or invalid password
Explanation
REST API call failed. The entered username or password was invalid.
Firewall Action
None
Recommended Action
None
Revision
1
Parameters
URI
Method
Context Parameters
User Authentication

2.69.53. bad_user_credentials (ID: 03207011)

Default Severity
NOTICE
Log Message
Unable to decode authentication
Explanation
REST API call failed. Unable to decode authentication.
Firewall Action
None
Recommended Action
None
Revision
1
Parameters
URI
Method
Context Parameters
User Authentication

2.69.54. method_not_allowed (ID: 03207012)

Default Severity
NOTICE
Log Message
Method not allowed
Explanation
REST API call failed. Method not allowed.
Firewall Action
None
Recommended Action
None
Revision
1
Parameters
URI
Method
Context Parameters
User Authentication

2.69.55. unknown_api_call (ID: 03207013)

Default Severity
NOTICE
Log Message
No such API PATH
Explanation
REST API call failed. No such path.
Firewall Action
None
Recommended Action
None
Revision
1
Parameters
URI
Method
Context Parameters
User Authentication