These log messages refer to the SYSTEM (System-wide events: startup, shutdown, etc..) category.
2.69.1. demo_mode (ID: 03200021)
- Default Severity
- ALERT
- Log Message
- The unit is running in DEMO mode and will eventually expire. Install a license in order to avoid this
- Explanation
- None
- Firewall Action
- lockdown_soon
- Recommended Action
- Install a license.
- Revision
- 2
- Parameters
- lockdown
time
2.69.2. demo_mode (ID: 03200024)
- Default Severity
- ALERT
- Log Message
- The unit is now running in License Lockdown Mode. Install a license in order to avoid this
- Explanation
- None
- Firewall Action
- license_lockdown
- Recommended Action
- Install a license.
- Revision
- 2
2.69.3. normal_mode (ID: 03200025)
- Default Severity
- NOTICE
- Log Message
- License file successfully loaded.
- Explanation
- The system is now running in normal operation mode.
- Firewall Action
- normal_operation
- Recommended Action
- None
- Revision
- 1
2.69.4. new_firmware_available (ID: 03200030)
- Default Severity
- NOTICE
- Log Message
- New firmware available.
- Explanation
- A new firmware release is available for download.
- Firewall Action
- None
- Recommended Action
- Upgrade_firmware.
- Revision
- 1
2.69.5. linktest_result (ID: 03200060)
- Default Severity
- INFORMATIONAL
- Log Message
- Linktest report
- Explanation
- Linktest finished with the following results for the test protocol and interface.
- Firewall Action
- None
- Recommended Action
- None
- Revision
- 1
- Parameters
- protocol
status
duration
server_ip
interface
clients
iface_sent_bps
iface_received_bps
test_sent_bps
test_received_bps
2.69.6. linktest_error (ID: 03200061)
- Default Severity
- INFORMATIONAL
- Log Message
- Linktest failed
- Explanation
- Linktest detected problems during execution and the test was aborted.
- Firewall Action
- None
- Recommended Action
- None
- Revision
- 1
- Parameters
- protocol
server_ip
interface
duration
error
2.69.7. reset_clock (ID: 03200100)
- Default Severity
- NOTICE
- Log Message
- The clock at <oldtime> was manually reset by <user> to <newtime>
- Explanation
- The clock has manually been reset.
- Firewall Action
- None
- Recommended Action
- None
- Revision
- 1
- Parameters
- oldtime
newtime
user
2.69.8. invalid_ip_match_access_section (ID: 03200110)
- Default Severity
- WARNING
- Log Message
- Failed to verify IP address as per ACCESS section. Dropping
- Explanation
- The IP address was not verified according to the ACCESS section.
- Firewall Action
- drop
- Recommended Action
- None
- Revision
- 1
- Context Parameters
- Rule Name
Packet Buffer
2.69.9. system_in_recovery_mode (ID: 03200118)
- Default Severity
- WARNING
- Log Message
- System is operating in recovery mode
- Explanation
- System encountered a boot failure and has been reverted to recovery mode, operating with constrained memory and/or reduced
functionality.
- Firewall Action
- None
- Recommended Action
- Should the system persist in recovery mode following a reboot, please attach to the serial console (debug) to record and examine
the output generated during the boot process.
- Revision
- 1
2.69.10. hardware_watchdog_initialized (ID: 03200260)
- Default Severity
- NOTICE
- Log Message
- Hardware Watchdog <hardware_watchdog_chip> found and initialized with a timeout of <watchdog_timeout> minutes.
- Explanation
- The system has identified a Hardware Watchdog and initialized it.
- Firewall Action
- None
- Recommended Action
- None
- Revision
- 1
- Parameters
- hardware_watchdog_chip
watchdog_timeout
2.69.11. port_bind_failed (ID: 03200300)
- Default Severity
- ALERT
- Log Message
- Out of memory while tying to allocate dynamic port for local IP <localip> to destination IP <destip>
- Explanation
- The unit failed to allocate a dynamic port, as it is out of memory.
- Firewall Action
- None
- Recommended Action
- None
- Revision
- 1
- Parameters
- reason
localip
destip
2.69.12. port_bind_failed (ID: 03200301)
- Default Severity
- WARNING
- Log Message
- Out of dynamic assigned ports. All ports <port_base>-<port_end> for Local IP <localip> to Destination IP <destip> are in use
- Explanation
- Failed to allocate a dynamic port, as all ports are in use.
- Firewall Action
- None
- Recommended Action
- None
- Revision
- 1
- Parameters
- reason
localip
destip
port_base
port_end
2.69.13. port_hlm_conversion (ID: 03200302)
- Default Severity
- NOTICE
- Log Message
- Using High Load Mode for Local IP <localip> Destination IP <destip> pair
- Explanation
- Mode for Local IP - Destination IP pair has changed to High Load because of heavy traffic.
- Firewall Action
- None
- Recommended Action
- None
- Revision
- 1
- Parameters
- localip
destip
2.69.14. port_llm_conversion (ID: 03200303)
- Default Severity
- NOTICE
- Log Message
- Using Low Load Mode for Local IP <localip> Destination IP <destip> pair
- Explanation
- Mode for Local IP - Destination IP pair has changed to Low Load because of low traffic.
- Firewall Action
- None
- Recommended Action
- None
- Revision
- 1
- Parameters
- localip
destip
2.69.15. log_messages_lost_due_to_throttling (ID: 03200400)
- Default Severity
- WARNING
- Log Message
- <logcnt> messages lost due to throttling
- Explanation
- Due to extensive logging, a number of log messages was not sent.
- Firewall Action
- None
- Recommended Action
- Examine why the unit sent such a large amount of log messages. If this is normal activity, the "LogSendPerSec" setting might
be set too low.
- Revision
- 1
- Parameters
- logcnt
2.69.16. log_messages_lost_due_to_log_buffer_exhaust (ID: 03200401)
- Default Severity
- WARNING
- Log Message
- <logcnt> log messages lost due to log buffer exhaustion
- Explanation
- Due to extensive logging, a number of log messages was not sent.
- Firewall Action
- None
- Recommended Action
- Examine why the unit sent such a large amount of log messages. If this is normal activity, the "LogSendPerSec" setting might
be set too low.
- Revision
- 1
- Parameters
- logcnt
2.69.17. bidir_fail (ID: 03200600)
- Default Severity
- CRITICAL
- Log Message
- Failed to establish bi-directional communication with peer in <timeout> seconds
- Explanation
- The unit failed to establish a connection back to peer, using the new configuration. It will try to revert to the previous
configuration file.
- Firewall Action
- None
- Recommended Action
- Verify that the new configuration file does not contain errors that would cause bi-directional communication failure.
- Revision
- 2
- Parameters
- localcfgver
remotecfgver
timeout
2.69.18. file_open_failed (ID: 03200602)
- Default Severity
- ERROR
- Log Message
- Failed to open newly uploaded configuration file <new_cfg>
- Explanation
- The unit failed to open the uploaded configuration file.
- Firewall Action
- None
- Recommended Action
- Verify that the disk media is intact.
- Revision
- 1
- Parameters
- new_cfg
2.69.19. disk_cannot_remove (ID: 03200603)
- Default Severity
- ERROR
- Log Message
- Failed to remove <old_cfg>
- Explanation
- The unit failed to remove the old configuration file.
- Firewall Action
- None
- Recommended Action
- Verify that the disk media is intact and that the file is not write protected.
- Revision
- 2
- Parameters
- old_cfg
2.69.20. disk_cannot_rename (ID: 03200604)
- Default Severity
- ERROR
- Log Message
- Failed to rename <cfg_new> to <cfg_real>
- Explanation
- The unit failed to rename the new configuration file to the real configuration file name.
- Firewall Action
- None
- Recommended Action
- Verify that the disk media is intact.
- Revision
- 1
- Parameters
- cfg_new
cfg_real
2.69.21. cfg_switch_fail (ID: 03200605)
- Default Severity
- CRITICAL
- Log Message
- Failed to switch to new configuration
- Explanation
- For reasons specified in earlier log events, the unit failed to switch to the new configuration and will continue to use the
present configuration.
- Firewall Action
- None
- Recommended Action
- Consult the recommended action in the previous log message, which contained a more detailed error description.
- Revision
- 1
2.69.22. core_switch_fail (ID: 03200606)
- Default Severity
- CRITICAL
- Log Message
- Failed to switch to new core
- Explanation
- For reasons specified in earlier log events, the unit failed to switch to the new core executable and will continue to use
the present core executable.
- Firewall Action
- None
- Recommended Action
- Consult the recommended action in the previous log message, which contained a more detailed error description.
- Revision
- 1
2.69.23. bidir_ok (ID: 03200607)
- Default Severity
- NOTICE
- Log Message
- Configuration <localcfgver><remotecfgver> verified for bi-directional communication
- Explanation
- The new configuration has been verified for communication back to peer and will now be used as the active configuration.
- Firewall Action
- None
- Recommended Action
- None
- Revision
- 2
- Parameters
- localcfgver
remotecfgver
2.69.24. rules_configuration_changed (ID: 03200641)
- Default Severity
- INFORMATIONAL
- Log Message
- IP Rules or Policies were altered by configuration changes made <date>
- Explanation
- IP Rules or Policies have been altered due to changes in the configuration.
- Firewall Action
- None
- Recommended Action
- None
- Revision
- 1
- Parameters
- date
2.69.25. cms_control_disabled (ID: 03200650)
- Default Severity
- NOTICE
- Log Message
- Centralized management control has been disabled.
- Explanation
- Centralized management control has been disabled and local management has been enabled.
- Firewall Action
- None
- Recommended Action
- None
- Revision
- 1
2.69.26. cms_control_enabled (ID: 03200651)
- Default Severity
- NOTICE
- Log Message
- Centralized management control has been enabled.
- Explanation
- Centralized management control has been enabled and local management has been disabled.
- Firewall Action
- None
- Recommended Action
- In order enable local management, use the CLI command localconfiguration.
- Revision
- 1
2.69.27. user_blocked (ID: 03200802)
- Default Severity
- NOTICE
- Log Message
- Login for user <database>:<username> has failed: currently in blocked state for the next <blockedremaining> seconds. Blocked
since: <blockedsince>.
- Explanation
- Too many failed login attempt for the user.
- Firewall Action
- None
- Recommended Action
- None
- Revision
- 1
- Parameters
- database
username
blockedremaining
blockedsince
2.69.28. shutdown (ID: 03201000)
- Default Severity
- NOTICE
- Log Message
- Shutdown <shutdown>. Active in <time> seconds. Reason: <reason>
- Explanation
- The unit is shutting down.
- Firewall Action
- shutdown
- Recommended Action
- None
- Revision
- 1
- Parameters
- shutdown
time
reason
2.69.29. reconfiguration (ID: 03201001)
- Default Severity
- NOTICE
- Log Message
- Initiating reconfiguration. Active in <time> seconds. Reason: <reason>
- Explanation
- The unit is reconfiguring.
- Firewall Action
- reconfiguration
- Recommended Action
- None
- Revision
- 1
- Parameters
- time
reason
2.69.30. shutdown (ID: 03201011)
- Default Severity
- NOTICE
- Log Message
- Shutdown aborted. Core file <core> missing
- Explanation
- The unit was issued a shutdown command, but no core executable file is seen. The shutdown process is aborted.
- Firewall Action
- shutdown_gateway_aborted
- Recommended Action
- Verify that the disk media is intact.
- Revision
- 1
- Parameters
- shutdown
reason
core
2.69.31. config_activation (ID: 03201020)
- Default Severity
- NOTICE
- Log Message
- Reconfiguration requested by <username> from <config_system> <client_ip>.
- Explanation
- Reconfiguration requested.
- Firewall Action
- reconfiguration
- Recommended Action
- None
- Revision
- 2
- Parameters
- username
userdb"
client_ip
config_system
2.69.32. reconfiguration (ID: 03201021)
- Default Severity
- NOTICE
- Log Message
- Reconfiguration will change <change_count> access control rule(s).
- Explanation
- Number of access control rules changed during the reconfiguration.
- Firewall Action
- None
- Recommended Action
- None
- Revision
- 1
- Parameters
- change_count
2.69.33. startup_normal (ID: 03202000)
- Default Severity
- NOTICE
- Log Message
- Firewall starting. Core: <corever>. Build: <build>. Current uptime: <uptime>. Using configuration file <cfgfile>, version
<localcfgver> <remotecfgver>. Previous event: <previous_event>
- Explanation
- The firewall is starting up.
- Firewall Action
- None
- Recommended Action
- None
- Revision
- 4
- Parameters
- corever
build
uptime
cfgfile
localcfgver
remotecfgver
previous_event
2.69.34. startup_echo (ID: 03202001)
- Default Severity
- NOTICE
- Log Message
- Firewall starting echo (<delay> seconds). Core: <corever>. Build: <build>. Current uptime: <uptime>. Using configuration file
<cfgfile>, localcfgver <localcfgver>, remotecfgver <remotecfgver>. Previous event: <previous_event>
- Explanation
- The firewall is starting up, echo.
- Firewall Action
- None
- Recommended Action
- None
- Revision
- 4
- Parameters
- delay
corever
build
uptime
cfgfile
localcfgver
remotecfgver
previous_event
2.69.35. shutdown (ID: 03202500)
- Default Severity
- NOTICE
- Log Message
- Event <event>
- Explanation
- The firewall is shutting down.
- Firewall Action
- shutdown
- Recommended Action
- None
- Revision
- 2
- Parameters
- event
2.69.36. reconfiguration (ID: 03202501)
- Default Severity
- NOTICE
- Log Message
- Event <event>
- Explanation
- The firewall is reconfiguring.
- Firewall Action
- reconfiguration
- Recommended Action
- None
- Revision
- 2
- Parameters
- event
2.69.37. admin_login (ID: 03203000)
- Default Severity
- NOTICE
- Log Message
- Administrative user <username> logged in via <authsystem>. Access level: <access_level>
- Explanation
- An administrative user has logged in to the configuration system.
- Firewall Action
- None
- Recommended Action
- None
- Revision
- 2
- Parameters
- authsystem
username
access_level
[interface]
[usergroups]
[authsource]
[userdb]
[server_ip]
[server_port]
[client_ip]
[client_port]
2.69.38. admin_logout (ID: 03203001)
- Default Severity
- NOTICE
- Log Message
- Administrative user <username> logged out, via <authsystem>. Access level: <access_level>
- Explanation
- An administrative user has logged out from the configuration system.
- Firewall Action
- None
- Recommended Action
- None
- Revision
- 3
- Parameters
- authsystem
username
access_level
[userdb]
[client_ip]
2.69.39. admin_login_failed (ID: 03203002)
- Default Severity
- WARNING
- Log Message
- Administrative user <username> failed to log in via <authsystem>, because of bad credentials
- Explanation
- An administrative user failed to log in to configuration system. This is most likely due to an invalid entered username or
password.
- Firewall Action
- disallow_admin_access
- Recommended Action
- None
- Revision
- 3
- Parameters
- authsystem
username
[interface]
[server_ip]
[server_port]
[client_ip]
[client_port]
2.69.40. admin_authorization_failed (ID: 03203003)
- Default Severity
- WARNING
- Log Message
- Administrative user <username> successfully logged in via <authsystem>, but is not authorized to access the system.
- Explanation
- An administrative user successfully authenticated but is not authorized to access the system.
- Firewall Action
- disallow_admin_access
- Recommended Action
- If the user should have access to the system, increase the access level of the user or one the user's groups.
- Revision
- 1
- Parameters
- authsystem
interface
username
usergroups
authsource
userdb
server_ip
server_port
client_ip
client_port
2.69.41. sslvpnuser_login (ID: 03203004)
- Default Severity
- NOTICE
- Log Message
- SSL VPN user <username> logged in via <authsystem>.
- Explanation
- An SSL VPN user has logged in to the SSL VPN user page.
- Firewall Action
- None
- Recommended Action
- None
- Revision
- 2
- Parameters
- authsystem
username
userdb
server_ip
server_port
client_ip
client_port
2.69.42. activate_changes_failed (ID: 03204000)
- Default Severity
- NOTICE
- Log Message
- Bidirectional confirmation of the new configuration failed, previous configuration will be used
- Explanation
- The unit failed to establish a connection back to peer, using the new configuration. The previous configuration will still
be used.
- Firewall Action
- using_prev_config
- Recommended Action
- Make sure that the new configuration allows the unit to establish a connection with the administration interface.
- Revision
- 1
- Parameters
- authsystem
2.69.43. accept_configuration (ID: 03204001)
- Default Severity
- NOTICE
- Log Message
- New configuration activated by user <username> from <config_system> <client_ip>.
- Explanation
- The new configuration has been successfully activated.
- Firewall Action
- using_new_config
- Recommended Action
- None
- Revision
- 2
- Parameters
- username
userdb"
client_ip
config_system
2.69.44. reject_configuration (ID: 03204002)
- Default Severity
- NOTICE
- Log Message
- New configuration rejected by user <username> from <config_system> <client_ip>.
- Explanation
- The new configuration has been rejected.
- Firewall Action
- reconfiguration_using_old_config
- Recommended Action
- None
- Revision
- 1
- Parameters
- username
userdb"
client_ip
config_system
2.69.45. date_time_modified (ID: 03205000)
- Default Severity
- NOTICE
- Log Message
- The local Date and Time has been modified by <user>. Time and Date before change: <pre_change_date_time>. Time and Date after
change: <post_change_date_time>
- Explanation
- The local Date and Time of the unit has been changed.
- Firewall Action
- using_new_date_time
- Recommended Action
- None
- Revision
- 2
- Parameters
- authsystem
user
pre_change_date_time
post_change_date_time
2.69.46. admin_timeout (ID: 03206000)
- Default Severity
- NOTICE
- Log Message
- Administrative user <username> timed out from <authsystem>
- Explanation
- The administrative user has been inactive for too long and has been automatically logged out.
- Firewall Action
- None
- Recommended Action
- None
- Revision
- 2
- Parameters
- authsystem
username
userdb
client_ip
access_level
2.69.47. admin_login_group_mismatch (ID: 03206001)
- Default Severity
- WARNING
- Log Message
- Administrative user <username> not allowed access via <authsystem>
- Explanation
- The user does not have proper administration access to the configuration system.
- Firewall Action
- disallow_admin_access
- Recommended Action
- None
- Revision
- 2
- Parameters
- authsystem
username
server_ip
server_port
client_ip
client_port
2.69.48. admin_login_internal_error (ID: 03206002)
- Default Severity
- WARNING
- Log Message
- Internal error occured when administrative user <username> tried to login, not allowed access via <authsystem>
- Explanation
- An internal error occured when the user tried to log in and as a result has not been given administration access.
- Firewall Action
- disallow_admin_access
- Recommended Action
- Please contact the support and report this issue.
- Revision
- 2
- Parameters
- authsystem
username
server_ip
server_port
client_ip
client_port
2.69.49. admin_authsource_timeout (ID: 03206003)
- Default Severity
- ERROR
- Log Message
- Remote <authsource> server(s) could not be reached when attempting to authenticate administrative user <username>.
- Explanation
- The unit did not receive a response from the authentication servers and the authentication process failed.
- Firewall Action
- None
- Recommended Action
- Investigate why the configured servers are not responding to authentication requests.
- Revision
- 1
- Parameters
- authsystem
interface
username
authsource
server_ip
server_port
client_ip
client_port
2.69.50. user_post_token_invalid (ID: 03206004)
- Default Severity
- WARNING
- Log Message
- <username> has provided an invalid token when attempting a POST request.
- Explanation
- All POST requests are required to provide a valid token for authentication.
- Firewall Action
- refused_post_request
- Recommended Action
- Please contact the support and report this issue.
- Revision
- 1
- Parameters
- client_ip
username
client_port
2.69.51. valid_rest_api_call (ID: 03207000)
- Default Severity
- NOTICE
- Log Message
- REST API call
- Explanation
- .
- Firewall Action
- None
- Recommended Action
- None
- Revision
- 1
- Parameters
- URI
Method
- Context Parameters
- User Authentication
2.69.52. bad_user_credentials (ID: 03207010)
- Default Severity
- NOTICE
- Log Message
- Unknown user or invalid password
- Explanation
- REST API call failed. The entered username or password was invalid.
- Firewall Action
- None
- Recommended Action
- None
- Revision
- 1
- Parameters
- URI
Method
- Context Parameters
- User Authentication
2.69.53. bad_user_credentials (ID: 03207011)
- Default Severity
- NOTICE
- Log Message
- Unable to decode authentication
- Explanation
- REST API call failed. Unable to decode authentication.
- Firewall Action
- None
- Recommended Action
- None
- Revision
- 1
- Parameters
- URI
Method
- Context Parameters
- User Authentication
2.69.54. method_not_allowed (ID: 03207012)
- Default Severity
- NOTICE
- Log Message
- Method not allowed
- Explanation
- REST API call failed. Method not allowed.
- Firewall Action
- None
- Recommended Action
- None
- Revision
- 1
- Parameters
- URI
Method
- Context Parameters
- User Authentication
2.69.55. unknown_api_call (ID: 03207013)
- Default Severity
- NOTICE
- Log Message
- No such API PATH
- Explanation
- REST API call failed. No such path.
- Firewall Action
- None
- Recommended Action
- None
- Revision
- 1
- Parameters
- URI
Method
- Context Parameters
- User Authentication