Messages

Table 1. System
ID Message
60012 Appliance becomes standalone
60013 Appliance goes in fault
60014 Appliance becomes auxiliary
60015 Appliance becomes primary
60016 Appliance becomes standalone at appliance start up
60017 Appliance goes in fault at appliance start up
60018 Appliance becomes auxiliary at appliance start up
60019 Appliance becomes primary at appliance start up
17838 HA was disabled
60020 DHCP lease renew
60021 DHCP lease release
60022 DHCP lease expired
17807 CPU usage exceeded the threshold
17808 Physical memory usage exceeded the threshold
17809 SWAP memory usage exceeded the threshold
17810 Config disk usage exceeded the threshold
17811 Signature disk usage exceeded the threshold
17812 Reports disk usage reached the higher threshold
17816 Appliance started successfully
17904 Reserved for OPCODE failure SNMP trap (logs will be added later)
17905 Reserved for service failure SNMP trap (logs will be added later)
17923 Scheduled backup was successfully taken (Information)
17924 Failed to send scheduled backup
17931 Fan speed has decreased below the desirable level
17932 Temperature has increased above the desired level
17933 Report disk usage reached lower than the lower threshold
17934 Report disk usage exceeded the lower threshold
17941 The audit subsystem has successfully shut down
17942 Fail to send certificate passphrase
17943 Connectivity to ConnectWise server has been lost
17944 Fail to send test mail: <Reason>
17813 Interface up/interface down
17814 Gateway alive/gateway dead
18036 Up/down gateway detail to SFM
17815 DDNS update successful/failed
17817 WebCat database upgraded from <old version> to <new version>
17920 WebCat database upgrade failed
17819 AV definitions upgraded from <old version> to <new version>
17922 AV definitions upgrade failed
17921 IPS signatures upgrade failed
17820 Primary link down/up and link failover/failback to backup/primary link
17821 Dial-In client connected
17822 Dial-In client disconnected
17823 Quarantined email could not be released because <reason>
17824 SSL VPN connection (tunnel access) established
17825 SSL VPN connection (tunnel access) terminated
17826 SSL VPN connection (web access) established
17827 SSL VPN connection (web access) terminated
17828 SSL VPN connection (application access) established
17829 SSL VPN connection (application access) terminated
17830 SSL VPN resource access allowed
17831 SSL VPN resource access denied
17936 User certificate <certificate_name> was created for user <username>
17937 All user certificates deleted
17803 L2TP connection established
17804 L2TP connection terminated
17805 PPTP connection established
17806 PPTP connection terminated
17801 IPsec connection established
17802 IPsec connection terminated
17832 Failover group activation successful. A particular connection/no connection established.
17833 Failover successful
17834 Failover failed. Connection will be established on next failback event.
17835 Failback successful
17836 Failback failed, revert back to current running connection successful
17837 Failback failed, revert back to current running connection also failed. Connection will be established on next failback event.
17839 <connectionname>, activation: Connection activated successfully
17840 <connectionname>, activation: Failed to activate this connection. Reason: <reason>.
17841 <connectionname>, activation: Trying to deactivate/initiate/terminate an inactive connection. Probable DB sync problem.
17842 <connectionname>, EST-P1-MM: Response to establishment request from <peeris> peer <peerrequesterip> successful
17843 <connectionname>, EST-P1-MM: Response to establishment request from <peerrequesterip> failed because <reason>
17844 <connectionname>, EST-P1-AM: Responding to establishment request from <peerrequesterip>, state # <state>
17845 <connectionname>, EST-P1-AM: Response to establishment request from <peerrequesterip> failed because <reason>
17846 <connectionname>, EST-P1-MM: Connection being initiated on request
17847 <connectionname>, EST-P1-AM: Connection with state <state> being initiated on request
17848 <connectionname>, EST-P1-MM: Peer ID is <peerid>
17849 <connectionname>, EST-P1-AM: Peer ID is <peerid>
17850 <connectionname>, EST-P1: Phase-1 ID mismatch. Configured peer id is <remoteid> and received peer id is <peerid>. System is initiator. Verify ID configuration at both the ends is in sync.
17851 <connectionname>, EST-P1: Phase-1 ID mismatch. No suitable connection for peer id <peerid>. System is responder. Verify ID configuration at both the ends is in sync.
17852 <connectionname2>, EST-P1: switched the connection from <connectionname> to <connectionname2> because a <connection name2>’s configuration matches the request better.
17853 <connectionname>, EST-P1: Peer did not accept any proposal sent. Reconfigure the connection on either of the ends.
17854 <connectionname>, EST-P1: System did not accept any proposal received. Need to reconfigure the connection on either of the ends.
17855 <connectionname>, EST-P1: An error (mostly related to network) has occurred while sending a packet to advance the IKE state machine from state <state>.
17856 <connectionname>, EST-P1: max number of retransmissions <count> reached STATE_MAIN_I1. No response (or no acceptable response) to first IKE message.
17857 <connectionname>, EST-P1: max number of retransmissions <count> reached STATE_MAIN_I3. Possible authentication failure or NAT device in between: no acceptable response to first encrypted message.
17858 <connectionname>, EST-P1: Malformed payload in packet. probable authentication failure (mismatch of preshared secrets). Verify pre-shared secrets are same at both the ends.
17859 <connectionname>, EST-P1: unexpected message received in state <state>. Payload received from the peer doesn’t lead the system to the next expected IKE state.
17860 <connectionname>, EST-P1: Informational exchange message is invalid because it has a previously used ID <messageid>
17861 <connectionname>, EST-P1-MM: Phase-1 SA initiated by peer is established
17865 <connectionname>, EST-P2: Initiating Phase-2 (protected by Phase-1 SA with <state>) on request with policy <policybits>
17866 <connectionname>, EST-P2: Initiating Phase-2 SA re-keying using Phase-1 SA <state>
17867 <connectionname>, EST-P2: Responding to a Phase-2 establishment request with ID <ID>
17868 <connectionname>, EST-P2: max number of retransmissions <count> reached STATE_QUICK_I1. No acceptable response to our first Quick Mode message: perhaps peer likes no proposal.
17869 <connectionname>, EST-P2: System require Perfect Forward Secrecy (PFS) but peer proposed not to use PFS
17870 <connectionname>, EST-P2: Local subnet – remote subnet configuration of the connection being initiated conflicts with that of an already established connection <establishedconnectionname>. Terminate connection <establishedconnectionname> before initiating.
17871 <connectionname>, EST-P2: System received a Phase-2 connection request whose local subnet – remote subnet configuration conflicts with that of an already established connection <establishedconnectionname>. System is terminating connection <establishedconnectionname> to honour the incoming request.
17872 <connectionname>, EST-P2: A Phase-2 SA initiated by system is established.
17873 <connectionname>, EST-P2: A Phase-2 SA initiated by peer is established
17874 <connectionname>, NAT-T: No NAT device detected between local server and remote server
17875 <connectionname>, NAT-T: Local server is behind a NAT device
17876 <connectionname>, NAT-T: Remote server is behind a NAT device
17877 <connectionname>, NAT-T: Both local and remote server are behind NAT devices
17878 <connectionname>, SA-MGT: Peer requested to delete Phase-1 SA. Deleting ISAKMP state <state>.
17879 <connectionname>, SA-MGT: Peer requested to delete Phase-2 SA. Deleting IPsec state <state>.
17880 <connectionname>, SA-MGT: Peer requested to delete Phase-2 SA. Deleting existing SA and re-inititate a new one. Replacing IPsec status #<state>.
17881 <connectionname>, SA-MGT: Deleting remote access connection instance with peer <remoteinterfaceip>, isakmp=#<isakmp>, ipsec=#<ipsec>.
17882 <connectionname>, SA-MGT: Deleting connection
17883 <connectionname>, SA-MGT: On deletion of connection, corresponding SA <state> is being deleted
17884 <connectionname>, SA-MGT: Initiating re-keying of connection’s Phase-1 (main mode) SA <state>
17885 <connectionname>, SA-MGT: Initiating re-keying of connection’s Phase-1 (aggressive mode) state <oldstate> to state <newstate>
17886 <connectionname>, SA-MGT: Phase 1 SA is being re-keyed
17887 <connectionname>, SA-MGT: Phase 2 SA is being re-keyed
17888 <connectionname>, SA-MGT: Phase 1 SA has expired
17889 <connectionname>, SA-MGT: Phase 1 SA has expired. Connection is configured not to re-key.
17890 <connectionname>, SA-MGT: Phase 2 SA has expired
17891 <connectionname>, SA-MGT: Phase 2 SA has expired. Connection is configured not to re-key.
17892 <connectionname>, DPD: Dead peer detection enabled
17893 <connectionname>, DPD: Peer was unreachable and was marked as dead for this connection
17894 <connectionname>, DPD: Connection was <actiononpeerdead> because peer was dead
17895 <connectionname>, DPD: Connection was scheduled to be re-keyed because peer was unreachable and connection was re-initiated
17896 <connectionname>, XAUTH: Sending username/password request
17897 <connectionname>, XAUTH: User <user> attempting to sign in
17898 <connectionname>, XAUTH: User <user> authenticated successfully
17899 <connectionname>, XAUTH: User <user> failed to authenticate because <reason>
17900 <connectionname>, XAUTH: received MODECFG message when in state <STATE NAME>, and appliance is not XAUTH client
17901 <connectionname>, XAUTH: Username/password requested but connection configured as XAUTH client cannot be re-keyed. Turn off rekey for the connection.
17902 <connectionname>, XAUTH: XAUTH: Answering XAUTH challenge with user <user>
17903 <connectionname>, XAUTH: Successfully authenticated. Appliance is XAUTH client.
17939 Failed to send IPsec tunnel UP/Down notification mail
17938 IPsec tunnel UP/Down notification mail sent successfully
17906 Landing page accepted
17907 Landing page declined
17908 Rogue AP scan successfully completed
17909 Rogue AP scan failed
17911 System triggered rogue AP scan was initiated
17910 Failed to send heartbeat from appliance to CCC (reserved for use with CCC, no log is generated)
17912 heartbeat sent from appliance to CCC (reserved for use with CCC, no log is generated)
17918 Failed to send keep-alive from appliance to CCC (reserved for use with CCC, no log is generated)
17919 keep-alive sent from appliance to CCC (reserved for use with CCC, no log is generated)
17913 System blocked administrator account for sign-in because of too may wrong sign-in attempts
17914 System unblocked administrator account
17915 System locked administrator’s session
17916 Unknown protocol traffic was denied
17917 Invalid certificate was blocked
17925 Guest user is added in system
17926 Access details SMS sent to the SMS gateway for delivery to guest user
17927 One or more guest user expired and auto-purged successfully
17928 One or more guest user expired and auto-purged failed
17929 One or more guest user expired and auto-purge partially failed
17930 Failed to send access details SMS
17935 Mapped server <server_ipaddress> is up/mapped server <server_ipaddress> is down
17940 CTA started with active collectors
17953 <interface name>: PADO packet time-out no response from server
17954 <interface name>: Terminating session, reattempting in <seconds> sec
17955 <interface name>: Discovery process completed
17956 <interface name>: LCP link established
17957 <interface name>: ISP not supporting LCP
17958 <interface name>: Authentication successful
17959 <interface name>: Authentication failed. Please check username and password.
17960 <interface name>: Set interface IP <local IP>
17961 <interface name>: Set gateway IP <remote IP>
17962 <interface name>: Set primary DNS <DNS IP if enable>
17963 <interface name>: Set aux DNS <DNS IP>
17964 <interface name>: PPPoE link up
17965 <interface name>: PPPoE link down
17966 <interface name>: Disconnect PPPoE due to LCP time-out
17967 <interface name>: Disconnect PPPoE due to idle time-out
17969 <interface name>: Reconnected on schedule event
17972 LCP: Negotiation opening for <Client IP>
17973 LCP: Link established for <Client IP>
17974 <PAP/CHAP/MS-CHAPv2>: Starting authentication
17975 <PAP/CHAP/MS-CHAPv2>: Authentication successful for user <user name>
17976 <PAP/CHAP/MS-CHAPv2>: Authentication failed for user <user name>
17977 IPCP: IP allocated: <IP allocated>, IPCP: Set DNS: <Primary/secondary DNS server>, IPCP: Set WINS: <Primary/secondary WINS server>
17978 LCP: Disconnect due to LCP time-out
17979 STATS: Connect time: <connection time>, STATS: Sent <no. of bytes> bytes, received <no. of bytes> bytes
17980 IPCP: Taking IPCP down for <Client IP>: <Reason>, LCP: Negotiation closing for <Client IP>: <Reason>, LCP: Negotiation closed for <Client IP>
17981 IPCP: Taking IPCP down for <Client IP>: <Reason>, LCP: Negotiation closing for <Client IP>: <Reason>, LCP: Negotiation closed for <Client IP>
17982 LCP: Negotiation opening for <Client IP>
17983 LCP: Link established for <Client IP>
17984 <PAP/CHAP/MS-CHAP>: Starting authentication
17985 <PAP/CHAP/MS-CHAP>: Authentication successful for user <user name>
17986 <PAP/CHAP/MS-CHAP>: Authentication failed for user <user name>
17987 IPCP: IP allocated: <IP allocated>, IPCP: Set DNS: <Primary/secondary DNS server>, IPCP: Set WINS: <Primary/secondary WINS server>
17988 LCP: Disconnect due to LCP time-out
17989 STATS: Connect time: <connection time>, STATS: Sent <no. of bytes> bytes, received <no. of bytes> bytes
17990 IPCP: Taking IPCP down for <Client IP>: <Reason>, LCP: Negotiation closing for <Client IP>: <Reason>, LCP: Negotiation closed for <Client IP>
17991 IPCP: Taking IPCP down for <Client IP>: <Reason>, LCP: Negotiation closing for <Client IP>: <Reason>, LCP: Negotiation closed for <Client IP>
18000 Event
17998 new firmware detected for <type>: <version>
17999 [ <AP-ID>] unknown AP model encountered: <type>, dropping
18001 [<AP-ID>] no firmware available for AP type '<type>', dropping
18002 [ <AP-ID> ] device not authorized yet, dropping
18003 [ <AP-ID> ] Corrupt payload. XG Firewall may have wrong key. Delete device to re-register it.
18004 [ <AP-ID>] sent firmware <firmware> to device, releasing connection
18005 [ <AP-ID> ] failed to send <firmware> to device, dropping
18006 [MASTER] sending notification about offline AP <AP>
18007 Successfully sent config to AP [ <AP-ID> ]
18008 Failed to send config to AP [ <AP-ID> ]
18014 RED is connected
18015 RED in disconnected
18016 RED interim event
18032 RED devices: Disabled: 5 Enabled: 15 Connected: 12 Disconnected 3
18017 ATP definitions upgraded from <old version> to <new version>
18018 ATP definitions upgrade failed
18019 SSLVPN clients upgraded from <old version> to <new version>
18020 SSLVPN clients upgrade failed
18021 IPSEC clients upgraded from <old version> to <new version>
18022 IPSEC clients upgrade failed
18023 Authentication clients upgraded from <old version> to <new version>
18024 Authentication clients upgrade failed
18025 RED firmware upgraded from <old version> to <new version>
18026 RED firmware upgrade failed
18027 AP firmware upgraded from <old version> to <new version>
18028 AP firmware upgrade failed
18029 Failed to checked for updates
18030 Failed to download file <MODULE>
18033 WAF rules upgraded from <old version> to <new version>
18034 WAF rules upgrade failed
18096 Completed ZeroTouch provisioning
18097 ZeroTouch provisioning failed
18098 Completed firewall provisioning
18099 Firewall provisioning failed
Table 2. Web filter
ID Message
16001 Transaction is allowed based on web policy rule
16002 Transaction was denied/blocked based on web policy rule
16003 HTTP file upload allowed
16004 Token override
16005 Transaction resulted in a warning based on web policy rules
16006 Transaction was allowed after the user proceeded through a warning
16007 HTTP file upload warned allowed
16008 Sandbox file allowed
16009 Sandbox file denied
Table 3. Application filter
ID Message
17051 Application access was denied according to application filter policy
Table 4. Malware
ID Message
08001 The URL has been blocked as it contained a virus
08002 Access to URL is allowed as it does not contain any virus
09001 FTP data transfer was blocked as it contained a virus
09002 FTP data transfer didn’t have any virus and completed successfully
10001 The mail is infected with a virus detected by the firewall
10002 Mail does not contain any virus
11001 The mail is infected with a virus detected by the firewall
11002 Mail does not contain any virus
12001 The mail is infected with a virus detected by the firewall
12002 Mail does not contain any virus
Table 5. Email
ID Message
13001 A mail considered to be SPAM
13002 A mail considered to be PROBABLE SPAM
13003 A mail was not considered SPAM or PROBABLE SPAM
13004 Sender IP address is blocked
13005 A mail considered to be an outbound spam
13006 A mail considered to be an outbound probable spam
13007 Flagged clean by both IBS/OBS
13008 Message is marked clean by outbound
13009 DLP detected in mail
13010 SPX successfully applied
13011 SPX failed
13012 SMTP DOS
13013 Email is marked clean by Sandstorm
13014 Email is marked malicious by Sandstorm
14001 A mail considered to be SPAM
14002 A mail considered to be PROBABLE SPAM
14003 A mail was not considered SPAM or PROBABLE SPAM
15001 A mail considered to be SPAM
15002 A mail considered to be PROBABLE SPAM
15003 A mail was not considered SPAM or PROBABLE SPAM
Table 6. Firewall
ID Message
00001 Firewall traffic allowed
00002 Firewall traffic denied
00003 Firewall traffic dropped by Security Heartbeat
00004 ICMP-related packets denied
00005 ICMP-related packets allowed
00007 Allowed missing heartbeat traffic in case of no restriction
01001 Invalid traffic dropped
01301 Fragmented traffic denied
01601 Invalid fragmented traffic denied
02001 Local ACL traffic allowed
02002 Local ACL traffic denied
03001 DoS attack dropped
04001 ICMP-redirected packet dropped
05001 Source-routed packet dropped
05051 Foreign host denied
05101 IPMAC pair denied
05151 IP spoof denied
05201 SSL VPN resource access denied
05301 ARP flood traffic denied
05401 Traffic for virtual host <virtualhostname> is denied. No internal server is available to process the traffic.
010202100 Invalid packet
010202101 IP packet with invalid header
010202102 IP packet with invalid header version
010202103 IP packet with invalid header time-to-live
010202104 IP packet with invalid header protocol
010202105 Truncated/malformed IP packet
010202106 Bad IP checksum
010202107 IP packet with invalid addresses
010202108 Invalid IP fragment
010202109 Short ICMP packet
010202110 Bad ICMP checksum
010202111 ICMP packets with invalid ICMP type/code
010202112 Invalid packet, no ICMP record found
010202113 ICMP packet error
010202114 Short UDP packet
010202115 Truncated/malformed UDP packet
010202116 Bad UDP checksum
010202117 Invalid UDP destination
010202118 Short TCP packet
010202119 Truncated/malformed TCP packet
010202120 Bad TCP checksum
010202121 TCP packets with invalid flag combination
010202122 Invalid TCP state
010202123 Invalid TCP RST
010202124 Invalid TCP source port
010202125 Invalid TCP destination port
010202126 TCP land attack
010202127 Invalid TCP reserved bit
010202128 TCP WinNuke attack
010202129 Could not associate packet with any connection
010202130 FTP-bounce attack
010202131 Short UDP-Lite packet
010202132 Bad UDP-Lite checksum
010202133 UDP-Lite checksum missing
010202134 Invalid DCCP packet
010202135 Invalid DCCP state
010202136 Short DCCP packet
010202137 Truncated/malformed DCCP packet
010202138 Bad DCCP checksum
010202139 Invalid DCCP reserved packet
010202140 Invalid connection helper
010202141 Packet discarded
Table 7. IPS
ID Message
06001 IPS anomaly detected
06002 IPS anomaly dropped
07001 IPS signature detected
07002 IPS signature dropped
Table 8. Authentication
ID Message
17701 User logged in successfully to firewall
17702 User failed to sign in to firewall
17703 User logged out from firewall
17945 Received challenge from <Auth mech> server via <Client type>
17704 User logged in successfully to My Account
17705 User failed to sign in to My Account
17706 User logged out from Account
17947 Received challenge from <Auth mech> server via <Client type>
17707 User logged in successfully to VPN
17708 User failed to sign in to VPN
17709 User logged out from VPN
17710 User logged in successfully to SSL VPN
17711 User failed to sign in to SSL VPN
17712 User logged out from SSL VPN
17946 Received challenge from <Auth mech> server via <Client type>
17713 User logged in using dial-in
17714 User failed to sign in using dial-in
17715 User logged out of dial-in
17948 NTLM enabled but AD server not configured
17949 Cannot establish NTLM authentication channel with <server name>
17950 NTLM authentication channel established successfully with <server name>
17951 Cannot establish NTLM authentication channel with <server name>
17952 NTLM authentication disabled from appliance access
17968 connection to ADS/LDAPS <server ip/fqdn> failed because <reason>
Table 9. Admin
ID Message
17501 Add operation
17502 Update
17503 Delete
17504 Other management action
17505 System - Maintenance actions
17506 Wizard
17507 Admin sign-in sign-out
17504 <interface name>: Disconnect PPPoE due to admin event
17970 HA enable event
17971 HA disable event
17504 PPTP/L2TP service enabled/disabled successfully
Table 10. Sandstorm
ID Message
13013 Sandbox allowed
13014 Sandbox denied
18041 Sandbox file allowed
18042 Sandbox file denied
18043 Sandbox file pending
16005 Website/file/application access is warned allowed according to the internet access policy
16006 Website/file/application access is warned blocked according to the internet access policy
16007 HTTP file upload warned allowed
16008 Sandbox file allowed
16009 Sandbox file denied
18009 Alert by ATP
18010 Drop by ATP
18012 Heartbeat status
18013 Endpoint status
Table 11. Web server protection
ID Message
17071 A web request is allowed by WAF
17072 A web request is blocked by WAF
Table 12. Advanced threat protection
ID Message
18009 Alert by ATP
18010 Drop by ATP
Table 13. Security Heartbeat
ID Message
18012 Heartbeat status
18013 Endpoint status
Table 14. Web content policy
ID Message
16010 Content filter matched