11.08.2013 Views

Error Messages

Error Messages

Error Messages

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

Chapter 1: Layer 3 Access Control List (ACL) <strong>Error</strong> <strong>Messages</strong><br />

%ACL-E-HSTFLOWMODE Interface ’%s’ has a port in Host Flow Mode.<br />

Explanation:<br />

The user is trying to attach an ACL to an interface which has one or more ports in Host Flow based<br />

routing mode. An inbound ACL cannot be applied to such interfaces because the ACL may have<br />

Source Port or Destination Port fields in its parameters.<br />

Recommended Action:<br />

Either the ports associated with the interface should not be in Host Flow based mode or the ACL<br />

should only contain Destination IP address and Source IP address in its parameters.<br />

%ACL-E-HSTFLOWSERVICEACL Service ACL has incompatible rules<br />

for Host Flow based routing.<br />

Explanation:<br />

The user is trying to change the port mode to Host Flow based, where there is a service ACL in the<br />

system. A service ACL requires that all ports not be in either Destination or Host Flow based<br />

modes because a service ACL requires to compare the Destination Port number in the packet and a<br />

port in Destination flow mode would produce a flow block with only the Destination and Source IP<br />

addresses.<br />

Recommended Action:<br />

Cannot change port mode to Host Flow based mode if a service ACL is present in the system. The<br />

ACL could be detached from the services if the port needs to be in Host Flow based mode.<br />

%ACL-E-HWNOTSFR Slot %d of interface '%s' is not SFR compliant.<br />

Explanation:<br />

An ACL created with the 'tcp established' option will check for a sin/fin/reset bit (SFR) in TCP<br />

packets without an accompanying ACK bit and send any such packets to the CPU for processing.<br />

This helps prevent against SYN attacks.<br />

Recommended Action:<br />

This functionality exists only in the SIPP (i.e., T-series cards)—the XP does not allow the use of an<br />

established ACL with a module that uses an IPP.<br />

6 Enterasys X-Pedition <strong>Error</strong> Reference Manual

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!