COMPREHENSIVE INTERNET SECURITY™
S o n i c WALL Internet Security Ap p l i a n c e s
Using the SonicOS Log Event
Reference Guide
This reference guide lists and describes SonicOS log event messages. Reference a log event mes-sage by using the alphabetical index of log event mesmes-sages.
This document contains the following sections:
• “SonicOS Log Event Messages Overview” on page 1 • “Configuring SonicOS ‘Log’ > ‘View’” on page 4
• “Referencing the SonicOS ‘Log’ > ‘View ’ Field Display” on page 7 • “Index of Log Event Messages” on page 9
• “Index of Syslog Tag Field Description” on page 63
SonicOS Log Event Messages Overview
During the operation of a SonicWALL security appliance, SonicOS software sends log event mes-sages to the ‘Log’ > ‘View’ page in the SonicWALL management interface.
In Figure 1, the ‘Log’ > ‘View’ page is displayed.
Figure 1 SonicOS Enhanced ‘Log’ > ‘View’ page
Event logging automatically begins when the SonicWALL security appliance is powered on and con-figured. SonicOS supports a traffic log containing entries with multiple fields.
Log event messages provide operational informational and debugging information to help you diag-nose problems with communication lines, internal hardware, or your firmware configuration.
Note: For the SonicOS CLI console display, use the show log command to display log events. Referappliance.
SonicOS Log Entries
Each log entry contains the date and time of the event and a brief message describing the event. The SonicWALL manages log events in the following manner:
• TCP, UDP, or ICMP packets dropped
When IP packets are dropped by the SonicWALL security appliance, dropped TCP, UDP and ICMP messages are displayed. The messages include the source and destination IP addresses of the packet. The TCP or UDP port number or the ICMP code follows the IP address. Log event messages usually include the name of the service in quotation marks.
• Web, FTP, Gopher, or Newsgroup blocked
When a computer attempts to connect to the blocked site or newsgroup, a log event is displayed. Blocked is defined as a Web site, connection, or event that is denied access from the SonicWALL security appliance. The computer’s IP address, Ethernet address, the name of the blocked Web site, and the Content Filter List Code is displayed. Code definitions for the 12 Content Filter List categories are shown below.
• ActiveX, Java, Cookie or Code Archive blocked
When ActiveX, Java or Web cookies are blocked, messages with the source and destination IP addresses of the connection attempt is displayed.
• Ping of Death, IP Spoof, and SYN Flood Attacks
The IP address of the machine under attack and the source of the attack is displayed. In most attacks, the source address shown is fake and does not reflect the real source of the attack.
SonicOS ‘Log View Settings’
The ‘Log View Settings’ section of the ‘Log’ > ‘View’ page provides you the filtering controls to filter log event messages based on your configured log filter logic. It also contains the following log manage-ment buttons:
• Refresh—Renews the ‘Log View’ table with current log event messages. • Clear Log—Empties the entries in the ‘Log View’ table.
• E-mail Log—E-mails log event messages to your configured SMTP server or list of e-mail
addresses.
• Export Log—Exports the log into a plain .txt or .csv file format.
1. Violence 7. Cult
2. Intimate Apparel/Swim-suit
8. Drugs/Illegal Drugs
3. Nudism 9. Criminal Skills/Illegal Skills
4. Adult/Mature Content/ Pornography
10. Sex Education
5. Weapons 11. Gambling
SonicOS ‘Log View’ Display Format
The ‘Log’ > ‘View’ page displays log event messages in following format for alert notification:
• Time—Displays the hour and minute the event occurred. • Priority—Displays the level urgency for the event. • Category—Displays the event type.
• Message—Displays a description of the event.
• Source—Displays the source IP address of incoming IP packet.
• Destination—Displays the destination IP address of incoming IP packet.
• Note—Displays displays additional information specific to a particular event occurrence.
• Rule—Displays the source and destination zones for the access rule. This field provides a link to
the access rule defined in the ‘Firewall’ > ‘Access Rules’ page.
Configuring SonicOS ‘Log’ > ‘View’
The ‘Log’ > ‘View” page in the Web-based SonicWALL management interface allows you to export log reports, e-mail log reports, and monitor real-time Syslog data. As soon as you power on your Son-icWALL security appliance, SonicOS software sends Syslog data to your log. In the SonSon-icWALL man-agement interface, you can navigate through the subcategories of the ‘Log’ setting for reporting and customizing log reports.
In Figure 2, the ‘Log’ > ‘View’ page is displayed.
Setting the Log Filter Logic
By default, the SonicOS filter logic is set to “Priority && Category && Source && Destination.” The double ampersand symbols (&&) indicate the boolean expression “and.” The default SonicOS filter logic displays all log events.
In Figure 3, the ‘Log’ > ‘View’ > ‘Log View Settings’ page is displayed.
Figure 3 SonicOS ‘Log View Settings’
Applying Custom Log Event Message Filters
This section provides examples on using the ‘Log View Settings’ to filter log event messages dis-played in the ‘Log View’ page.
Configuration Example: Filtering Log Event Messages by Priority Value
To set the log filter logic to display only log event messages with a priority level of Emergency: 1. Select Emergency from the filter-Priority Value pull-down menu.
2. Click on the Apply Filters button.
Configuration Example: Filtering Log Event Messages by Category Value
To set the log filter logic to display only log event messages with a category event type of Attacks: 1. Select Attacks from the filter-Category Value pull-down menu.
2. Click on the Apply Filters button.
Apply filters
Reset filters
Export logs Default filter logic
Group filters Default filter logic value
Configuration Example: Filtering Log Event Messages by Source Value
To set the log filter logic to display only log event messages associated to a source IP address: 1. Enter the source IP address or select an interface from the filter-Source Value pull-down menu. 2. Click on the Apply Filters button.
Configuration Example: Filtering Log Event Messages by Destination Value
To set the log filter logic to display only log event messages associated to a destination IP address: 1. Enter the destination IP address or select an interface from the filter-Source Value pull-down
menu.
2. Click on the Apply Filters button.
Using Group Filters
Use Group filters to change the default SonicOS filter logic (Priority && Category && Source && Des-tination) from double ampersand symbols (&&) to double pipe symbols (||) to indicate the boolean expression “or.” When using group filters, select two or more Group Filters checkboxes.
Note: If you select only one Group Filter checkbox, the filter logic will remain the same. Selecting onlythe Priority-Group Filter checkbox provides you with the following filter logic:
(Priority) && Category && Source && Destination
Configuration Example: Using the ‘Priority’ Group Filter and ‘Category Group’ Filter
To set the log filter logic to display log event messages with a priority level of Emergency or a category event type of Attack:
1. Select the ‘Priority’ group filter checkbox. 2. Select the ‘Category’ group filter checkbox.
3. Select Emergency from the filter-Priority Value pull-down menu. 4. Select Attacks from the filter-Category Value pull-down menu. Figure 4 illustrates the SonicOS filter logic updated as follows:
(Priority || Category) && Source && Destination
Figure 4 SonicOS Log Group Filters
Exporting the Logs to a File
This section provides instructions to export your log to a file. To export the log to a file:
1. Click on the Export Log button. You will be prompted to select a export file format type as illustrated in Figure 5.
Figure 5 SonicOS Export Log
2. Select a file format:
Plain text format used in log and alert e-mail—Saves the log file as plain text, which can be
used for alert e-mails.
Comma-Separated Value (CSV) format—Saves the log file for importing into Microsoft Excel or
other presentation development application. 3. Click on the Export button.
4. Save the exported log file to a location on your personal computer’s hard drive.
Note: You can export a log to a file with applied filter settings.Referencing the SonicOS ‘Log’ > ‘View ’
Field Display
SonicOS 2.5 Enhanced and Standard releases and greater provide the SonicOS ‘Log’ > ‘View’ field display as illustrated in Figure 6.
Figure 6 SonicOS ‘Log’ > ‘View’ Field Display
Time and DateStamp Priority
Category
MessageDescrition
Source IPAddress
Destination IP
Referencing the SonicWALL Firmware ‘Log’ > ‘View Log’ Field Display
SonicWALL Firmware 6.6.0.0 release and greater provide the SonicWALL Firmware ‘Log’ > ‘View Log’ field display as illustrated in Figure 7.
Figure 7 SonicWALL Firmware Log’ > ‘View Log’ Field Display
Time and Date Stamp
Event Message
Source IP Address
Destination IP Address
Additional Information
Index of Log Event Messages
This section contains a list of log event messages for all SonicWALL Firmware and SonicOS Software Releases, ordered alphabetically. Use your web browser’s Find function to search for a command.
Log Event Message Symbols Key
TCP IP Layered-Data Packet Processing and SonicOS Log Event Handling
In specific cases of multi-layer packet processing, a TCP connection initially logged as "open," will be rejected by a deeper layer of packet processing. In these cases, the connection request has not been forwarded by the SonicWALL security appliance, and the initial Connection Open SonicOS log event message should be ignored in favor of the TCP Connection Dropped log event message.
Each log event message described in the following table provides the following log event details:
• SonicOS Category—Displays the SonicOS Software category event type.
• Legacy Category—Displays the SonicWALL Firmware Software category event type. • Priority Level—Displays the level of urgency of the log event message.
• Log Message ID Number—Displays the ID number of the log event message. • SNMP Trap Type—Displays the SNMP Trap ID number of the log event message. Log Event Message Symbol Description Context
%s Ethernet Port Down Represents a character string. [WAN | LAN | DMZ] Ethernet Port Down
The cache is full; %u open connections; some will be dropped
Represents a numerical string. The cache is full; [40,000] open connections; some will be dropped
Log Event Message SonicOS Category Legacy Category Priority Level Log Message ID Number SNMP Trap Type Log Event Type
#Web site hit Network Traffic Connection Traffic Information 97 --- Standard HTTP Traffic Report
%s VPN IKE User Activity Information 171 --- Standard
Message String
%s ARS --- Information 840 --- Standard
Message String
%s ARS --- Notice 841 --- Standard
Message String
%s ARS --- Debug 842 --- Standard
%s Ethernet Port Down
Firewall Event System Error Error 333 641 Standard
String Service
%s Ethernet Port Up
Firewall Event System Error Warning 332 640 Standard
String Service
%s-payload processing error
VPN IKE Debug Error 616 --- Standard
Message String SonicWALL Registration Update Needed: Restore your existing security service subscriptions by clicking here. Security Services
Maintenance Warning 496 --- Simple
802.11b Management Wireless 802.11b Management Information 518 --- Simple Destination A prior version of preferences was loaded because the most recent preferences file was inaccessible
Firewall Event System Error Warning 572 648 Simple
A SonicOS Standard to
Enhanced Upgrade was performed
Firewall Event Maintenance Information 611 --- Simple
Access attempt from host out of compliance with GSC policy
Security Services
Maintenance Information 761 --- Standard
Access attempt from host without Anti-Virus agent installed
Security Services
Maintenance Information 123 --- Standard
Access attempt from host without GSC installed
Security Services
Maintenance Information 763 524 Standard
Access rule added Firewall Rule User Activity Information 440 --- Simple Rule
Access rule deleted
Firewall Rule User Activity Information 442 --- Simple
Access rule modified
Firewall Rule User Activity Information 441 --- Simple
Rule
Access to proxy server denied
Network Access
Blocked Sites Notice 60 705 Standard
Note Blocked ActiveX access denied Network Access
Blocked Code Notice 18 --- Standard
Note Blocked ActiveX or Java archive access denied Network Access
Blocked Code Notice 20 --- Standard
Note Blocked AD agent %s is not responding MS AD --- Error 769 --- Standard Message String Add an attack message
Firewall Event Attack Error 143 525 Simple
String
Adding Dynamic Entry for Bound MAC Address
Network --- Information 813 --- Standard
Note ENET
Adding L2TP IP pool Address object Failed
L2TP Server System Error Error 603 661 Simple
Adding to multicast policyList, interface: %s
Multicast --- Debug 697 --- Standard
Message String
Adding to Multicast policyList, VPN SPI: %s
Multicast --- Debug 699 --- Standard
Message String
Administrator logged out
Authentication User Activity Information 261 --- Standard
Administrator logged
out - inactivity timer expired
Authentication User Activity Information 262 --- Standard
Administrator login allowed
Authentication User Activity Information 29 --- Standard
Administrator login denied due to bad credentials
Administrator login denied from %s; logins disabled from this interface
Authentication Attack Alert 35 506 Standard
Message String
Adminstrator name changed
Authentication Maintenance Information 328 --- Standard
All DDNS
associations have been deleted
DDNS Maintenance Information 783 --- Simple
All preference values have been set to factory default values
Firewall Event System Error Warning 574 650 Simple
Allowed LDAP server certificate with wrong host name
RADIUS User Activity Warning 752 --- Standard
Note String
Anti-Spyware Detection Alert: %s
Intrusion Detection
Attack Alert 795 576 Standard
Anti-Spy Message String Anti-Spyware Prevention Alert: %s Intrusion Detection
Attack Alert 794 575 Standard
Anti-Spy Message String Anti-Spyware Service Expired Security Services
Maintenance Warning 796 577 Simple
Anti-Virus agent out-of-date on host
Security Services
Maintenance Information 124 --- Standard
Anti-Virus
Licenses Exceeded
Security Services
Maintenance Information 408 --- Standard
Arp request packet received
Network --- Information 717 --- Standard
Note ENET
Arp request packet sent
Network --- Information 715 --- Standard
Note ENET
Arp response packet received
Network --- Information 716 --- Standard
Note ENET
Arp response packet sent
Network --- Information 718 --- Standard
Note ENET
ARP timeout Network Debug Debug 45 --- Standard
Association Flood from wlan station
WLAN IDS WLAN IDS Alert 548 903 Simple
Authentication timeout during Remotely
Triggered Dial-out session
Authentication User Activity Information 821 --- Simple
Back Orifice attack dropped
Intrusion Detection
Attack Alert 73 512 Standard
Backup active High Avaiability
System Error Information 825 --- Simple
Backup firewall being preempted by Primary
High Availability
System Error Error 152 619 Simple
Backup firewall has transitioned to Active
High Availability
Maintenance Information 145 --- Simple
Backup firewall has transitioned to Idle
High Availability
Maintenance Information 147 --- Simple
Backup going Active in preempt mode after reboot
High Availability
System Error Error 170 622 Simple
Backup missed heartbeats from Primary
High Availability
System Error Error 149 616 Simple
Backup received error signal from Primary
High Availability
System Error Error 151 618 Simple
Backup received reboot signal from Primary
High Availability
System Error Error 672 666 Simple
Backup shut down because license is expired
High Availability
System Error Error 824 --- Simple
Backup will be shut down in %s minutes
High Availability
System Error Error 823 --- Standard
String Service
Bad CRL format VPN PKI User Activity Alert 277 --- Simple Destination
Blocked Quick Mode for Client using Default KeyId
BOOTP Client IP address on LAN conflicts with remote device IP, deleting IP address from remote table
BOOTP Maintenance Information 619 --- Standard
Destination
BOOTP reply relayed to local device
BOOTP Maintenance Information 620 --- Standard
Destination
BOOTP Request received from remote device
BOOTP Debug Debug 621 --- Standard
Destination
BOOTP server response relayed to remote device
BOOTP Debug Debug 618 --- Standard
Destination
Broadcast packet dropped
Network Access
Debug Debug 46 --- Standard
Note Protocol
Cannot connect to the CRL server
VPN PKI User Activity Alert 274 --- Simple
Destination
Cannot Validate Issuer Path
VPN PKI User Activity Alert 878 --- Simple
Destination
Certificate on Revoked list (CRL)
VPN PKI User Activity Alert 279 --- Simple
Destination CFL auto-download disabled, time problem detected Security Services
Maintenance Information 268 --- Simple
CLI administrator logged out
Authentication User Activity Information 520 --- Simple
CLI administrator login allowed
Authentication User Activity Information 199 --- Simple
CLI administrator login denied due to bad credentials
Authentication User Activity Warning 200 --- Simple
Computed hash does not match hash received from peer
VPN IKE User Activity Warning 410 --- Standard
Connection Closed
Note: In specific cases of
multi-layer packet processing, a TCP connection initially logged as "open," will be rejected by a deeper layer of packet processing. In these cases, the connection request has not been forwarded by the SonicWALL security appliance, and the initial Connection Open SonicOS log event message should be ignored in favor of the TCP Connection Dropped log event message. Network Traffic Connection Traffic Information 537 --- Standard Traffic Report Connection Opened
Note: In specific cases of
multi-layer packet processing, a TCP connection initially logged as "open," will be rejected by a deeper layer of packet processing. In these cases, the connection request has not been forwarded by the SonicWALL security appliance, and the initial Connection Open SonicOS log event message should be ignored in favor of the TCP Connection Dropped log event message.
Network Traffic
Connection Information 98 --- Standard
Note Protocol
Connection timed out
VPN PKI User Activity Alert 273 --- Simple
Destination
Cookie removed Network Access
Blocked Code Notice 21 --- Standard
String Service
CRL has expired VPN PKI User Activity Alert 874 --- Simple Destination
CRL loaded from VPN PKI User Activity Information 270 --- Simple Destination
CRL
missing - Issuer requires CRL checking
VPN PKI User Activity Alert 876 --- Simple
Destination
CRL validation failure for Root Certificate
VPN PKI User Activity Alert 877 --- Simple
Destination
Crypto DES test failed
Crypto Test Maintenance Error 360 --- Simple
Crypto DH test failed
Crypto Hardware 3Des test failed
Crypto Test Maintenance Error 367 --- Simple
Crypto Hardware 3DES with SHA test failed
Crypto Test Maintenance Error 369 --- Simple
Crypto Hardware AES test failed
Crypto Test Maintenance Error 610 --- Standard
Crypto hardware DES test failed
Crypto Test Maintenance Error 366 --- Simple
Crypto Haredware DES with SHA test failed
Crypto Test Maintenance Error 368 --- Simple
Crypto Hmac-MD5 fest failed
Crypto Test Maintenance Error 362 --- Simple
Crypto Hmac-Sha1 test failed
Crypto Test Maintenance Error 363 --- Simple
Crypto MD5 test failed
Crypto Test Maintenance Error 370 --- Simple
Crypto RSA test failed
Crypto Test Maintenance Error 364 --- Simple
Crypto Sha1 test failed
Crypto Test Maintenance Error 365 --- Simple
DDNS association %s disabled
DDNS Maintenance Information 781 --- Simple
Message String
DDNS association %s enabled
DDNS Maintenance Information 780 --- Simple
Message String
DDNS association %s added
DDNS Maintenance Information 779 --- Simple
Message String
DDNS association %s deactivated
DDNS Maintenance Information 784 --- Simple
Message String
DDNS association %s deleted
DDNS Maintenance Information 785 --- Simple
Message String
DDNS Association %s put on line
DDNS Maintenance Information 782 --- Simple
DDNS association %s taken Offline locally
DDNS Maintenance Information 778 --- Simple
Message String
DDNS Failure: Provider %s
DDNS System Error Error 774 --- Simple
Message String
DDNS Failure: Provider %s
DDNS System Error Error 775 --- Simple
Message String
DDNS Failure: Provider %s
DDNS System Error Error 773 --- Simple
Message String
DDNS Update success for domain %s
DDNS Maintenance Information 776 --- Standard
Message String
DDNS Warning: Provider %s
DDNS System Error Warning 777 --- Simple
Message String
Deleting from Multicast policy list, interface : %s
Multicast --- Debug 698 --- Standard
Message String
Deleting from Multicast policy list, VPN SPI : %s
Multicast --- Debug 700 --- Standard
Message String
Deleting IPSec SA VPN IKE User Activity Information 92 --- Standard Note SPI
DHCP client enabled but not ready
DHCP Client Maintenance Information 504 --- Simple
DHCP Client did not get DHCP ACK
DHCP Client Maintenance Information 109 --- Standard
DHCP Client failed to verify and lease has expired. Go to INIT state.
DHCP Client Maintenance Information 119 --- Standard
DHCP Client got a new IP address lease.
DHCP Client Maintenance Information 121 --- Standard
Destination
DHCP Client got ACK from server
DHCP Client Maintenance Information 111 --- Standard
Destination
DHCP Client got NACK
DHCP Client is declining address offered by the server.
DHCP Client Maintenance Information 112 --- Standard
Destination
DHCP Client sending REQUEST and going to REBIND state
DHCP Client Maintenance Information 113 --- Standard
Destination
DHCP Client sending REQUEST and going to RENEW state
DHCP Client Maintenance Information 114 --- Standard
Destination
DHCP DISCOVER received from remote device
DHCP Relay Debug Information 474 --- Standard
Destination DHCP lease dropped. Lease from Central Gateway conflicts with Relay IP
DHCP Relay Maintenance Warning 228 --- Standard
Destination DHCP lease dropped. Lease from Central Gateway conflicts with Remote Management IP
DHCP Relay Maintenance Warning 484 --- Standard
Destination
DHCP lease relayed to local device
DHCP Relay Maintenance Information 223 --- Standard
Destination
DHCP lease relayed to remote device
DHCP Relay Debug Information 225 --- Standard
Destination
DHCP lease to LAN device conflicts with remote device, deleting remote IP entry
DHCP Relay Maintenance Information 226 --- Standard
Destination
DHCP NAK received from server
DHCP Relay Debug Information 477 --- Standard
Destination
DHCP OFFER received from server
DHCP Relay Debug Information 476 --- Standard
DHCP Ranges altered automatically due to change in network settings for interface %s
Firewall Event --- Information 832 --- Standard
String Service
DHCP RELEASE received from remote device
DHCP Relay Debug Information 224 --- Standard
Destination
DHCP RELEASE relayed to Central Gateway
DHCP Relay Maintenance Information 222 --- Standard
Destination
DHCP REQUEST received from remote device
DHCP Relay Debug Information 473 --- Standard
Destination
DHCP Server not available. Did not get any DHCP OFFER.
DHCP Client Maintenance Information 106 --- Standard
Diagnostic Code A Firewall Hardware
System Error Error 93 611 Simple
Note String
Diagnostic Code B Firewall Hardware
System Error Error 94 612 Simple
Note String
Diagnostic Code C Firewall Hardware
System Error Error 95 613 Simple
Note String
Diagnostic Code D Firewall Hardware
System Error Error 64 610 Standard
Note Code
Diagnostic Code D Firewall Hardware
System Error Error 517 642 Simple
Note String
Diagnostic Code E VPN IPSec System Error Error 61 609 Standard Note Code
Diagnostic Code F Firewall Hardware
System Error Error 164 621 Simple
Note String
Diagnostic Code G Firewall Hardware
System Error Error 599 655 Simple
Note String
Diagnostic Code H Firewall Hardware
System Error Error 600 656 Simple
Note String
Diagnostic Code I Firewall Hardware
System Error Error 601 657 Simple
Note String
Disconnecting L2TP Tunnel due to traffic timeout
Disconnecting PPPoE due to traffic timeout
PPPoE Maintenance Information 168 --- Simple
Disconnecting PPTP Tunnel due to traffic timeout
PPTP Maintenance Information 389 --- Simple
Discovered HA Backup Firewall
High Availability
Maintenance Information 156 --- Simple
DNS packet allowed
Network Access
Debug Information 602 --- Standard
Policy
Drop Wlan traffic from non
SonicPoint devcies
Intrusion Detection
Attack Error 662 572 Standard
Dynamic IPSec client connected
VPN IPSec User Activity Information 62 --- Standard
Destination
EIGRP packet dropped
Network Access
Debug Notice 714 --- Standard
Note String
E-Mail fragment dropped
Intrusion Detection
Attack Error 437 550 Standard
Error initializing Hardware acceleration for VPN Firewall Hardware
Maintenance Error 374 --- Simple
Error Rebooting HA Peer Firewall
High Availability
System Error Error 669 663 Simple
Error setting the IP address of the backup, please manually set to backup LAN IP High Availability
System Error Error 191 629 Simple
Error
Synchronizing HA Peer Firewall
High Availability
System Error Error 158 662 Simple
Exceeded Max multicast address limit
Multicast --- Warning 703 --- Standard
Failed payload validation
VPN IKE User Activity Warning 405 --- Standard
Failed payload verification after decryption.
Possible preshared key mismatch.
Failed to find certificate
VPN PKI User Activity Alert 875 --- Simple
Destination
Failed to get CRL from
VPN PKI User Activity Alert 271 --- Simple
Destination
Failed to Process CRL from
VPN PKI User Activity Alert 276 --- Simple
Destination
Failed to resolve name
Network Maintenance Information 84 --- Simple
Destination
Failed to
synchronize Relay IP Table
DHCP Relay System Error Warning 234 632 Standard
Failure to add data channel
Unused Debug Debug 49 --- Standard
Failure to reach Interface %s probe
High Availability
System Error Error 675 647 Standard
String Ser-vice
Fan Failure Firewall Hardware System Environment Alert 576 102 Simple Forbidden E-Mail attachment deleted Intrusion Detection
Attack Error 248 534 Standard
Destination Forbidden E-Mail attachment disabled Intrusion Detection
Attack Alert 165 527 Standard
Destination
Found Rogue Access Point
WLAN IDS WLAN IDS Alert 546 901 Simple
Destination
Found Rogue Access Point
WLAN IDS WLAN IDS Alert 556 901 Simple
Destination Fragmented packet dropped Network TCP | UDP | ICMP Notice 28 --- Standard Note Protocol Fraudulent Microsoft certificate found; access denied Intrusion Detection
Attack Error 193 532 Standard
FTP: Data connection from non default port dropped
Network Access
Attack Alert 538 557 Standard
FTP: PASV response bounce attack dropped.
Intrusion Detection
Attack Alert 528 556 Standard
FTP: PASV response spoof attack dropped.
Intrusion Detection
Attack Error 446 551 Standard
FTP: PORT bounce attack dropped.
Intrusion Detection
Attack Alert 527 555 Standard
Note String
Gateway Anti-Virus Alert: %s
Security Services
Attack Alert 809 --- Standard
Message String Gateway Anti-Virus Service expired Security Services
Maintenance Warning 810 --- Simple
Global VPN Client connection is not allowed. Appliance is not registered.
VPN Client System Error Information 529 643 Standard
Global VPN Client License Exceeded: Connection
denied.
VPN Client System Error Information 494 658 Standard
Global VPN Client version cannot enforce personal firewall. Minimum Version required is 2.1.
VPN Client User Activity Information 604 --- Standard
Destination
Got DHCP OFFER. Selecting.
DHCP Client Maintenance Information 107 --- Standard
Destination
GSC policy
out-of-date on host
Security Services
Maintenance Information 762 --- Standard
Guest account '%s' created
Authentication User Activity Information 558 --- Standard
Message String
Guest account '%s' deleted
Authentication User Activity Information 559 --- Standard
Message String
Guest account '%s' disabled
Authentication User Activity Information 560 --- Standard
Message String
Guest account '%s' pruned
Authentication User Activity Information 562 --- Standard
Message String
Guest account '%s' re-enabled
Authentication User Activity Information 561 --- Standard
Guest account '%s' re-generated
Authentication User Activity Information 563 --- Standard
Message String
Guest login denied. Guest '%s' is already logged in. Please try again later.
Authentication User Activity Information 557 --- Standard
Message String
H.323/H.225 Connect
VoIP VoIP Debug 634 --- Standard
Note String
H.323/H.225 Setup VoIP VoIP Debug 633 --- Standard Note String
H.323/H.245 Address
VoIP VoIP Debug 635 --- Standard
Note String
H.323/H.245 End Session
VoIP VoIP Debug 636 --- Standard
Note String
H.323/RAS
Admission Confirm
VoIP VoIP Debug 625 --- Standard
Note String
H.323/RAS Admission Reject
VoIP VoIP Debug 624 --- Standard
Note String
H.323/RAS Admission Request
VoIP VoIP Debug 626 --- Standard
Note String
H.323/RAS Bandwidth Reject
VoIP VoIP Debug 627 --- Standard
Note String
H.323/RAS
Disengage Confirm
VoIP VoIP Debug 628 --- Standard
Note String
H.323/RAS Disengage Reject
VoIP VoIP Debug 641 --- Standard
Note String
H.323/RAS
Gatekeeper Reject
VoIP VoIP Debug 629 --- Standard
Note String
H.323/RAS Location Confirm
VoIP VoIP Debug 630 --- Standard
Note String
H.323/RAS Location Reject
VoIP VoIP Debug 631 --- Standard
Note String
H.323/RAS
Registration Reject
VoIP VoIP Debug 632 --- Standard
Note String
H.323/RAS
Unknown Message Response
VoIP VoIP Debug 640 --- Standard
H.323/RAS Unregistration Reject
VoIP VoIP Debug 642 --- Standard
Note String
HA packet processing error
High Availability
Maintenance Information 162 --- Simple
Hardware Failover settings were not upgraded
Firewall Event Maintenance Information 743 --- Simple
Header verification failed
VPN IKE User Activity Warning 587 --- Standard
HTTP
management port has changed
Firewall Event Maintenance Information 340 --- Simple
Note String
HTTPS
management port has changed
Firewall Event Maintenance Information 341 --- Simple
Note String
ICMP checksum error
Network Access
UDP Notice 886 --- Standard
ICMP packet allowed
Network Access
Debug Information 597 --- Standard
Policy
ICMP packet dropped
Network Access
ICMP Notice 38 --- Standard
Policy
ICMP packet dropped
Network Access
ICMP Notice 523 --- Standard
ICMP Service
ICMP packet from LAN allowed
Network Access
Debug Information 598 --- Standard
ICMP Service
ICMP packet from LAN dropped Network Access LAN ICMP | LAN TCP Notice 175 --- Standard ICMP Service If not already enabled, enabling NTP is recommended Firewall Hardware
System Error Warning 540 645 Simple
IGMP packet dropped, wrong checksum received on interface %s
Multicast --- Notice 683 --- Standard
Message String
IGMP Leave group message Received on interface %s
Multicast --- Information 682 --- Standard
IGMP packet dropped, decoding error
Multicast --- Notice 686 --- Standard
IGMP Packet Not handled. Packet type : %s
Multicast --- Notice 687 --- Standard
Message String
IGMP querier Router detected on interface %s
Multicast --- Debug 701 --- Standard
Message String IGMP querier Router detected on VPN tunnel , SPI %S
Multicast --- Debug 702 --- Standard
Message String
IGMP state table entry time out,deleting interface : %s for multicast address : %s
Multicast --- Debug 692 --- Standard
Message String
IGMP state table entry time
out,deleting VPN SPI :%s for
Multicast address : %s
Multicast --- Debug 693 --- Standard
Message String
IGMP V2 client joined multicast Group : %s
Multicast --- Information 676 --- Standard
Message String IGMP V2 Membership report received from interface %s
Multicast --- Debug 679 --- Standard
Message String
IGMP V3 client joined multicast Group : %s
Multicast --- Information 677 --- Standard
Message String IGMP V3 Membership report received from interface %s
Multicast --- Debug 678 --- Standard
Message String IGMP V3 packet dropped, unsupported Record type : %s
Multicast --- Notice 688 --- Standard
IGMP V3 reord type : %s not Handled
Multicast --- Debug 689 --- Standard
Message String
IKE ID mismatch %s
VPN IKE Debug Debug 658 --- Standard
String Service
IKE Initiator drop: Packet dest address does not match selected local interface address
VPN IKE User Activity Information 544 --- Standard
IKE Initiator: Accepting IPSec proposal (Phase 2)
VPN IKE User Activity Information 372 --- Standard
Note String
IKE Initiator: Accepting peer lifetime (Phase 1)
VPN IKE User Activity Information 445 --- Standard
Destination
IKE Initiator: Aggressive Mode complete (Phase 1)
VPN IKE User Activity Information 354 --- Standard
Destination
IKE Initiator: Main Mode complete (Phase 1)
VPN IKE User Activity Information 353 --- Standard
Destination
IKE Initiator: Received notify. NO_PROPOSAL_ CHOSEN
VPN IKE User Activity Warning 401 --- Standard
Destination
IKE Initiator: Start Aggressive Mode negotiation (Phase 1)
VPN IKE User Activity Information 358 --- Standard
IKE Initiator: Start Main Mode
negotiation (Phase 1)
VPN IKE User Activity Information 351 --- Standard
IKE Initiator: Start Quick Mode (Phase 2)
VPN IKE User Activity Information 346 --- Standard
IKE Initiator: Using secondary gateway to negotiate
VPN IKE User Activity Information 543 --- Standard
IKE negotiation aborted due to timeout
VPN IKE User Activity Information 403 --- Standard
IKE negotiation complete. Adding IPSec SA. (Phase 2)
VPN IKE User Activity Information 89 --- Standard
IKE Responder drop: Packet dest address does not match selected local interface address
VPN IKE User Activity Information 545 --- Standard
IKE Responder: %s policy does not allow static IP for Virtual Adapter.
VPN Client System Error Error 660 --- Standard
Message String
IKE Responder: Accepting IPSec proposal (Phase 2)
VPN IKE User Activity Information 87 --- Standard
Note String
IKE Responder: Aggressive Mode complete (Phase 1)
VPN IKE User Activity Information 373 --- Standard
Destination
IKE Responder: AH Perfect Forward Secrecy mismatch
VPN IKE User Activity Warning 258 544 Standard
IKE Responder: Algorithms and/or keys do not match
VPN IKE User Activity Warning 260 546 Standard
IKE Responder: Default LAN gateway is not set but peer is propos-ing to use this SA as a default route
VPN IKE Attack Error 516 553 Standard
Note String
IKE Responder: Default LAN gateway is set but peer is not
proposing to use this SA as a default route
VPN IKE User Activity Warning 253 539 Standard
IKE Responder: ESP Perfect Forward Secrecy mismatch
VPN IKE User Activity Warning 259 545 Standard
IKE Responder: IKE proposal does not match
(Phase 1)
VPN IKE User Activity Warning 402 --- Standard
Destination
IKE Responder: IP Address already exists in the DHCP relay table. Client traffic not allowed.
VPN Client System Error Error 659 --- Standard
Note String
IKE Responder: IPSec proposal does not match (Phase 2)
VPN IKE User Activity Warning 88 523 Standard
Note String
IKE Responder: Main Mode
complete (Phase 1)
VPN IKE User Activity Information 357 --- Standard
Destination
IKE Responder: Mode %d - not transport mode. Xauth is required but not supported by peer.
VPN IKE Debug Warning 342 --- Standard
Message Number
IKE Responder: Mode %d - not tunnel mode
VPN IKE User Activity Warning 249 535 Standard
Message Number IKE Responder: No match for proposed remote network address
VPN IKE User Activity Warning 252 538 Standard
Note String IKE Responder: No matching Phase 1 ID found for proposed remote network
VPN IKE User Activity Warning 250 536 Standard
Note String
IKE Responder: Proposed local network is 0.0.0.0 but SA has no LAN Default Gateway
VPN IKE User Activity Warning 418 549 Standard
IKE Responder: Proposed remote network is 0.0.0.0 but not DHCP relay nor default route
VPN IKE User Activity Warning 251 537 Standard
IKE Responder: Received
Aggressive Mode request (Phase 1)
VPN IKE User Activity Information 356 --- Standard
IKE Responder: Received Main Mode request (Phase 1)
VPN IKE User Activity Information 355 --- Standard
IKE Responder: Received Quick Mode Request (Phase 2)
VPN IKE User Activity Information 352 --- Standard
IKE Responder: Tunnel terminates inside firewall but proposed local network is not inside firewall
VPN IKE User Activity Warning 255 541 Standard
Note String IKE Responder: Tunnel terminates on DMZ but proposed local network is on LAN
VPN IKE User Activity Warning 256 542 Standard
Note String IKE Responder: Tunnel terminates on LAN but proposed local network is on DMZ
VPN IKE User Activity Warning 257 543 Standard
Note String
IKE Responder: Tunnel terminates outside firewall but proposed local network is not NAT public address
VPN IKE User Activity Warning 254 540 Standard
Note String
IKE Responder: Tunnel terminates outside firewall but proposed remote network is not NAT public address
VPN IKE User Activity Warning 345 548 Standard
IKE SA lifetime expired.
VPN IKE User Activity Information 350 --- Standard
Illegal IPSec SPI VPN IPSec User Activity Information 65 --- Standard Destination
Imported VPN SA is invalid - disabled
Firewall Event Maintenance Warning 348 --- Standard
Note String Inbound connection from RBL-listed SMTP server dropped RBL --- Notice 798 --- Standard Incoming call received for Remotely Triggered Dial-out session
Authentication User Activity Information 817 --- Simple
Incompatible IPSec Security
Association
VPN IPSec User Activity Information 69 --- Standard
Destination Incorrect authentication received for Remotely Triggered Dial-out
Authentication User Activity Information 819 --- Simple
Ini Killer attack dropped
Intrusion Detection
Attack Alert 80 519 Standard
Interface %s Link Is Down
Firewall Event System Error Error 566 647 Standard
String Service
Interface %s Link Is Up
Firewall Event System Error Warning 565 646 Standard
String Service Interface IP Assignment : Binding and initializing %s
Firewall Event Maintenance Information 568 --- Standard
String Service Interface IP Assignment changed: Shutting down %s
Firewall Event Maintenance Information 567 --- Standard
Invalid TCP flags on an incomplete connection Network Access --- Notice 760 --- Standard Note String Invalid VLAN packet dropped
Network --- Alert 836 --- Standard
Note String
IP Header checksum error
Network Access
TCP | UDP Notice 883 --- Standard
IP spoof detected on packet to Central Gateway, packet dropped
DHCP Relay Attack Error 229 533 Standard
Note ENET
IP spoof dropped Intrusion Detection
Attack Alert 23 502 Standard
Note ENET IP type %s packet dropped Network Access LAN UDP | LAN TCP Notice 590 --- Standard Message String IPS Detection Alert: %s Intrusion Detection
Attack Alert 608 569 Standard
IDP Message String IPS Detection Alert: %s Intrusion Detection
Attack Alert 789 573 Standard
Message String IPS Prevention Alert: %s Intrusion Detection
Attack Alert 609 570 Standard
IDP Message String IPS Prevention Alert: %s Intrusion Detection
Attack Alert 790 574 Standard
Message String
IPSec (AH) packet dropped
VPN IPSec TCP | UDP |
ICMP
Notice 534 --- Standard
Note String
IPSec (AH) packet dropped; waiting for pending IPSec connection
VPN IPSec Debug Debug 536 --- Standard
IPSec (ESP) packet dropped
VPN IPSec TCP | UDP |
ICMP
Notice 533 --- Standard
Note String
IPSec (ESP) packet dropped; waiting for pending IPSec connection
IPSec
Authentication Failed
VPN IPSec Attack Error 67 508 Standard
Destination
IPSec connection interrupt
Network Access
Debug Debug 43 --- Standard
IPSec Decryption Failed
VPN IPSec Attack Error 68 509 Standard
Destination IPSec packet dropped Network Access TCP | UDP | ICMP Notice 40 --- Standard IPSec packet dropped; waiting for pending IPSec connection
Network Access
Debug Debug 42 --- Standard
IPSec packet from an illegal host
VPN IPSec Maintenance Information 247 --- Standard
Destination
IPSec packet from or to an illegal host
VPN IPSec Attack Error 70 510 Standard
Destination
IPSEC Replay Detected
VPN IPSec Attack Alert 180 531 Standard
Note String IPSecTunnel status changed VPN VPN Tunnel Status Information 427 801 Simple ISDN Driver Firmware successfully updated
Firewall Event Maintenance Information 493 --- Simple
Issuer match failed VPN PKI User Activity Alert 278 --- Simple Destination
Java access denied
Network Access
Blocked Code Notice 19 --- Standard
Note Blocked
L2TP enabled but not ready
Unused Maintenance Information 500 --- Simple
L2TP Max Retransmission Exceeded
L2TP Client Maintenance Information 203 --- Simple
L2TP PPP Authentication Failed
L2TP Client Maintenance Information 212 --- Simple
L2TP PPP Down L2TP Client Maintenance Information 211 --- Simple
L2TP PPP link down
L2TP PPP
Negotiation Started
L2TP Client Maintenance Information 208 --- Simple
L2TP PPP Session Up
L2TP Client Maintenance Information 210 --- Simple
L2TP Server : Deleting the L2TP active Session
L2TP Server Maintenance Information 337 --- Standard
Destination
L2TP Server : Deleting the Tunnel
L2TP Server Maintenance Information 336 --- Standard
Destination
L2TP Server : L2TP Session Estab-lished.
L2TP Server Maintenance Information 309 --- Standard
Destination
L2TP Server : L2TP Tunnel Estab-lished.
L2TP Server Maintenance Information 308 --- Standard
Destination
L2TP Server : Retransmission Timeout, Deleting the Tunnel
L2TP Server Maintenance Information 338 --- Standard
Destination
L2TP Server : User Name
authentication Failure locally.
L2TP Server Maintenance Information 344 --- Standard
Destination
L2TP Server: Local
Authentication Failure
L2TP Server Maintenance Information 312 --- Standard
Destination
L2TP Server: Local
Authentication Success.
L2TP Server Maintenance Information 318 --- Standard
Destination
L2TP Server: Radius
Authentication Success
L2TP Server Maintenance Information 319 --- Standard
Destination
L2TP Server: Radius reports Authentication Failure
L2TP Server Maintenance Information 311 --- Standard
Destination
L2TP Server: Radius server not assigned IP address
L2TP Server Maintenance Information 313 --- Standard
L2TP Server: Call Disconnect from Remote.
L2TP Server Maintenance Information 334 --- Standard
Destination
L2TP Server: Tunnel Disconnect from Remote.
L2TP Server Maintenance Information 335 --- Standard
Destination
L2TP Session Disconnect from Remote
L2TP Client Maintenance Information 207 --- Simple
L2TP Session Established
L2TP Client Maintenance Information 206 --- Simple
L2TP Session Negotiation Started
L2TP Client Maintenance Information 202 --- Simple
L2TP Tunnel Disconnect from Remote
L2TP Client Maintenance Information 205 --- Simple
L2TP Tunnel Established
L2TP Client Maintenance Information 204 --- Simple
L2TP Tunnel Negotiation Started
L2TP Client Maintenance Information 201 --- Simple
LAN Subnet configurations were not upgraded.
Firewall Event Maintenance Information 741 --- Simple
Land attack dropped
Intrusion Detection
Attack Alert 27 505 Standard
License exceeded: Connection dropped because too many IP addresses are in use on your LAN
Firewall Event System Error Error 58 608 Standard
License of HA pair doesn't match
High Availability
System Error Error 670 664 Simple
Local user login allowed
Authentication User Activity Information 31 --- Standard
String Service
Local user login denied due to bad credentials
Authentication User Activity Information 32 --- Standard
String Service Locked-out user logins allowed - lockout period expired
Authentication User Activity Information 438 --- Standard
Locked-out user logins allowed by administrator
Authentication User Activity Information 439 --- Standard
Note String
Log Cleared Firewall Logging
Maintenance Information 5 --- Simple
Log Debug Firewall Event Debug Error 142 --- Simple String
Log successfully sent via email
Firewall Logging
Maintenance Information 6 --- Simple
Login screen timed out
Authentication User Activity Information 34 --- Standard
String Service
MAC address collides with Static ARP Entry with Bound MAC address; packet dropped
Network --- Notice 814 --- Standard
Note ENET
Machine %s removed from SYN flood blacklist Intrusion Detection --- Alert 865 --- Standard String Service Malformed or unhandled IP packet dropped Network Access
Attack Alert 522 554 Standard
Destination Maximum events per second threshold exceeded Firewall Logging
System Error Critical 654 --- Simple
Maximum sequential failed dial attempts (10) to a single dial-up number: %s
PPP Dial-up Attack Error 591 566 Standard
Message String
Maximum syslog data per second threshold exceeded
Firewall Logging
System Error Critical 655 --- Simple
Multicast
application %s not supported
Multicast --- Information 696 --- Standard
Message String Multicast packet dropped, Invalid src IP received on interface : %s
Multicast --- Alert 685 --- Standard
Multicast packet dropped, wrong MAC address receieved on interface : %s
Multicast --- Alert 684 --- Standard
Message String
Multicast TCP packet dropped
Multicast --- Notice 691 --- Standard
Multicast UDP packet dropped, no state entry
Multicast --- Notice 690 --- Standard
Multicast UDP packet dropped, RTCP stateful failed
Multicast --- Warning 695 --- Standard
Multicast UDP packet dropped, RTP stateful failed
Multicast --- Warning 694 --- Standard
NAT device may not support IPSec AH passthrough
VPN IPSec Maintenance Information 266 --- Simple
NAT Discovery : No NAT/NAPT device detected between IPSec Security gateways
VPN IKE User Activity Information 241 --- Standard
NAT Discovery : Local IPSec Security Gateway behind a NAT/ NAPT Device
VPN IKE User Activity Information 240 --- Standard
NAT Discovery : Peer IPSec Security Gateway behind a NAT/ NAPT Device
VPN IKE User Activity Information 239 --- Standard
NAT Discovery : Peer IPSec Security Gateway doesn't support VPN NAT Traversal
VPN IKE User Activity Information 242 --- Standard
NAT translated packet exceeds size limit, packet dropped
Net Spy attack dropped
Intrusion Detection
Attack Alert 74 513 Standard
NetBIOS settings were not upgraded. Use Network>IP Helper to
configure NetBIOS support
Firewall Event Maintenance Information 740 --- Simple
NetBus attack dropped
Intrusion Detection
Attack Alert 72 511 Standard
Network for interface %s overlaps with another interface.
Firewall Event Maintenance Information 569 --- Standard
String Service
Network Modem Mode Disabled: re-enabling NAT
PPP Dial-up Maintenance Information 531 --- Simple
Network Modem Mode Enabled: turning off NAT
PPP Dial-up Maintenance Information 530 --- Simple
New URL List loaded
Security Services
Maintenance Information 8 --- Simple
Newsgroup access allowed
Network Access
Blocked Sites Notice 17 704 Standard
Note Blocked Newsgroup access denied Network Access
Blocked Sites Notice 15 702 Standard
Note Blocked
No Certificate for VPN PKI User Activity Alert 280 --- Simple Destination
No new URL List available
Security Services
Maintenance Information 9 --- Simple
No response from ISP Disconnecting PPPoE.
PPPoE Maintenance Information 169 --- Simple
No response from PPTP server to call requests
PPTP Maintenance Information 431 --- Simple
No response from PPTP server to control connection requests
No response from server to Echo Requests, disconnecting PPTP Tunnel
PPTP Maintenance Information 429 --- Simple
No valid DNS server specified for RBL lookups RBL --- Error 800 --- Simple Not all configurations may have been completely upgraded
Firewall Event Maintenance Information 612 --- Simple
Not enough
memory to hold the CRL
VPN PKI User Activity Warning 272 --- Simple
Destination
Obtained Relay IP Table from Remote Gateway
DHCP Relay Maintenance Information 233 --- Standard
OCSP Failed to Resolve Domain Name.
VPN PKI User Activity Error 853 --- Standard
Note String
OCSP Internal error handling received response.
VPN PKI User Activity Error 854 --- Standard
Note String
OCSP received response error.
VPN PKI User Activity Error 851 --- Standard
Note String
OCSP received response.
VPN PKI User Activity Information 850 --- Standard
Note String
OCSP Resolved Domain Name.
VPN PKI User Activity Information 852 --- Standard
Note String
OCSP send request message failed.
VPN PKI User Activity Error 849 --- Standard
Note String
OCSP sending request.
VPN PKI User Activity Information 848 --- Standard
Note String Outbound connection to RBL-listed SMTP server dropped RBL --- Notice 797 --- Standard Out-of-order command packet dropped Network Access
Packet dropped by wlan guest check
Wireless TCP | UDP | ICMP Warning 488 --- Standard Destination Packet dropped by wlan vpn traversal check Wireless TCP | UDP | ICMP Warning 495 --- Standard Destination Packet dropped. No firewall rule associated with VPN policy.
VPN System Error Alert 739 --- Standard
Note String
Ping of death dropped
Intrusion Detection
Attack Alert 22 501 Standard
PKI Failure: CA certificates store exceeded. Cannot verify this Local Certificate
VPN PKI Maintenance Error 453 --- Simple
PKI Failure: Cannot alloc memory
VPN PKI Maintenance Error 449 --- Simple
PKI Failure: Certificate's ID does not match this SonicWall
VPN PKI Maintenance Error 455 --- Simple
PKI Failure: Duplicate local certificate
VPN PKI Maintenance Error 458 --- Simple
PKI Failure: Duplicate local certificate name
VPN PKI Maintenance Error 457 --- Simple
PKI Failure: Import failed
VPN PKI Maintenance Error 451 --- Simple
PKI Failure: Improper file format. Please select PKCS#12 (*.p12) file
VPN PKI Maintenance Error 454 --- Simple
PKI Failure: Incorrect admin password
VPN PKI Maintenance Error 452 --- Simple
PKI Failure: Internal error
VPN PKI Maintenance Error 460 --- Simple
PKI Failure: Loaded but could not verify
certificate
PKI Failure: Loaded the certificate but could not verify it's chain
VPN PKI Maintenance Error 470 --- Simple
PKI Failure: No CA certificates yet loaded
VPN PKI Maintenance Error 459 --- Simple
PKI Failure: Output buffer too small
VPN PKI Maintenance Error 448 --- Simple
PKI Failure: public-private key mismatch
VPN PKI Maintenance Error 456 --- Simple
PKI Failure: Reached the limit for local certs, cant load any more
VPN PKI Maintenance Error 450 --- Simple
PKI Failure:
Temporary memory shortage, try again
VPN PKI Maintenance Error 461 --- Simple
PKI Failure: The certificate chain has no root
VPN PKI Maintenance Error 464 --- Simple
PKI Failure: The certificate chain is circular
VPN PKI Maintenance Error 462 --- Simple
PKI Failure: The certificate chain is incomplete
VPN PKI Maintenance Error 463 --- Simple
PKI Failure: The certificate or a certificate in the chain has a bad signature
VPN PKI Maintenance Error 468 --- Simple
PKI Failure: The certificate or a certificate in the chain has a validity period in the future
VPN PKI Maintenance Error 466 --- Simple
PKI Failure: The certificate or a certificate in the chain has expired
PKI Failure: The certificate or a certificate in the chain is corrupt
VPN PKI Maintenance Error 467 --- Simple
Please connect interface %s to another network to function properly
Firewall Event Maintenance Information 570 --- Standard
String Service
Please manually check all system configurations for correctness of Upgrade
Firewall Event Maintenance Information 613 --- Simple
Port configured to receive IPSEC ONLY. Drop packet received in the clear. Network Access TCP | UDP | ICMP Warning 347 --- Standard Destination
Possible port scan dropped
Intrusion Detection
Attack Alert 82 521 Standard
Note String
Possible SYN flood attack detected
Intrusion Detection
Attack Warning 25 503 Standard
Possible SYN flood detected on WAN IF %s - switching to connection-proxy mode Intrusion Detection --- Alert 859 --- Standard String Service Possible SYN Flood on IF %s Intrusion Detection --- Alert 860 --- Standard String Service Possible SYN Flood on IF %s continues Intrusion Detection --- Warning 866 --- Standard String Service Possible SYN Flood on IF %s has ceased Intrusion Detection --- Alert 867 --- Standard String Service PPP Dial-Up: Connect request canceled
PPP Dial-up User Activity Information 306 --- Simple
PPP Dial-Up: Connected at %s bps - starting PPP
PPP Dial-up User Activity Information 286 --- Standard
PPP Dial-Up: Connection disconnected as scheduled.
PPP Dial-up --- Information 666 --- Standard
PPP Dial-Up: Dial initiated by %s
PPP Dial-up Maintenance Information 324 --- Standard
Message String
PPP Dial-Up: Dialed number did not answer
PPP Dial-up User Activity Information 285 --- Simple
PPP Dial-Up: Dialed number is busy
PPP Dial-up User Activity Information 284 --- Simple
PPP Dial-Up: Dialing not allowed by schedule. %s
PPP Dial-up --- Information 665 --- Standard
Message String
PPP Dial-Up: Dialing: %s
PPP Dial-up User Activity Information 281 --- Standard
String Service
PPP Dial-Up: Idle time limit exceeded - disconnecting
PPP Dial-up User Activity Information 297 --- Simple
PPP Dial-Up: Initialization : %s
PPP Dial-up User Activity Information 303 --- Standard
String Service
PPP Dial-Up: Link carrier lost
PPP Dial-up User Activity Information 288 --- Simple
PPP Dial-Up: Manual intervention needed. Check Primary Profile or Profile details
PPP Dial-up User Activity Information 321 --- Simple
PPP Dial-Up: Maximum connection time exceeded - disconnecting
PPP Dial-up User Activity Information 327 --- Simple
PPP Dial-Up: No dialtone detected - check phone-line connection