03.05.2015 Views

SonicOS Log Event Reference Guide - SonicWALL

SonicOS Log Event Reference Guide - SonicWALL

SonicOS Log Event Reference Guide - SonicWALL

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

COMPREHENSIVE INTERNET SECURITY <br />

S o n i c WALL Internet Security Ap p l i a n c e s<br />

<strong>SonicOS</strong> <strong>Log</strong> <strong>Event</strong> <strong>Reference</strong> <strong>Guide</strong>


Using the <strong>SonicOS</strong> <strong>Log</strong> <strong>Event</strong><br />

<strong>Reference</strong> <strong>Guide</strong><br />

This reference guide lists and describes <strong>SonicOS</strong> log event messages. <strong>Reference</strong> a log event message<br />

by using the alphabetical index of log event messages.<br />

This document contains the following sections:<br />

• “<strong>SonicOS</strong> <strong>Log</strong> <strong>Event</strong> Messages Overview” on page 1<br />

• “Configuring <strong>SonicOS</strong> ‘<strong>Log</strong>’ > ‘View’” on page 4<br />

• “Referencing the <strong>SonicOS</strong> ‘<strong>Log</strong>’ > ‘View ’ Field Display” on page 7<br />

• “Index of <strong>Log</strong> <strong>Event</strong> Messages” on page 9<br />

• “Index of Syslog Tag Field Description” on page 63<br />

<strong>SonicOS</strong> <strong>Log</strong> <strong>Event</strong> Messages Overview<br />

During the operation of a <strong>SonicWALL</strong> security appliance, <strong>SonicOS</strong> software sends log event messages<br />

to the ‘<strong>Log</strong>’ > ‘View’ page in the <strong>SonicWALL</strong> management interface.<br />

In Figure 1, the ‘<strong>Log</strong>’ > ‘View’ page is displayed.<br />

Figure 1<br />

<strong>SonicOS</strong> Enhanced ‘<strong>Log</strong>’ > ‘View’ page<br />

<br />

Note:<br />

<strong>Event</strong> logging automatically begins when the <strong>SonicWALL</strong> security appliance is powered on and configured.<br />

<strong>SonicOS</strong> supports a traffic log containing entries with multiple fields.<br />

<strong>Log</strong> event messages provide operational informational and debugging information to help you diagnose<br />

problems with communication lines, internal hardware, or your firmware configuration.<br />

For the <strong>SonicOS</strong> CLI console display, use the show log command to display log events. Refer<br />

to the <strong>SonicOS</strong> CLI <strong>Reference</strong> <strong>Guide</strong> located on the <strong>SonicWALL</strong> Web site:<br />

<br />

SONICOS LOG EVENT REFERENCE GUIDE 1


Note:<br />

Not all log event messages indicate operational issues with your <strong>SonicWALL</strong> security<br />

appliance.<br />

<strong>SonicOS</strong> <strong>Log</strong> Entries<br />

Each log entry contains the date and time of the event and a brief message describing the event. The<br />

<strong>SonicWALL</strong> manages log events in the following manner:<br />

• TCP, UDP, or ICMP packets dropped<br />

When IP packets are dropped by the <strong>SonicWALL</strong> security appliance, dropped TCP, UDP and<br />

ICMP messages are displayed. The messages include the source and destination IP addresses of<br />

the packet. The TCP or UDP port number or the ICMP code follows the IP address. <strong>Log</strong> event<br />

messages usually include the name of the service in quotation marks.<br />

• Web, FTP, Gopher, or Newsgroup blocked<br />

When a computer attempts to connect to the blocked site or newsgroup, a log event is displayed.<br />

Blocked is defined as a Web site, connection, or event that is denied access from the <strong>SonicWALL</strong><br />

security appliance. The computer’s IP address, Ethernet address, the name of the blocked Web<br />

site, and the Content Filter List Code is displayed. Code definitions for the 12 Content Filter List<br />

categories are shown below.<br />

1. Violence 7. Cult<br />

2. Intimate Apparel/Swimsuit<br />

8. Drugs/Illegal Drugs<br />

3. Nudism 9. Criminal Skills/Illegal Skills<br />

4. Adult/Mature Content/<br />

Pornography<br />

10. Sex Education<br />

5. Weapons 11. Gambling<br />

6. Hate/Racism 12. Alcohol & Tobacco<br />

• ActiveX, Java, Cookie or Code Archive blocked<br />

When ActiveX, Java or Web cookies are blocked, messages with the source and destination IP<br />

addresses of the connection attempt is displayed.<br />

• Ping of Death, IP Spoof, and SYN Flood Attacks<br />

The IP address of the machine under attack and the source of the attack is displayed. In most<br />

attacks, the source address shown is fake and does not reflect the real source of the attack.<br />

<strong>SonicOS</strong> ‘<strong>Log</strong> View Settings’<br />

The ‘<strong>Log</strong> View Settings’ section of the ‘<strong>Log</strong>’ > ‘View’ page provides you the filtering controls to filter log<br />

event messages based on your configured log filter logic. It also contains the following log management<br />

buttons:<br />

• Refresh—Renews the ‘<strong>Log</strong> View’ table with current log event messages.<br />

• Clear <strong>Log</strong>—Empties the entries in the ‘<strong>Log</strong> View’ table.<br />

• E-mail <strong>Log</strong>—E-mails log event messages to your configured SMTP server or list of e-mail<br />

addresses.<br />

• Export <strong>Log</strong>—Exports the log into a plain .txt or .csv file format.<br />

2 SONICOS LOG EVENT REFERENCE GUIDE


<strong>SonicOS</strong> ‘<strong>Log</strong> View’ Display Format<br />

The ‘<strong>Log</strong>’ > ‘View’ page displays log event messages in following format for alert notification:<br />

• Time—Displays the hour and minute the event occurred.<br />

• Priority—Displays the level urgency for the event.<br />

• Category—Displays the event type.<br />

• Message—Displays a description of the event.<br />

• Source—Displays the source IP address of incoming IP packet.<br />

• Destination—Displays the destination IP address of incoming IP packet.<br />

• Note—Displays displays additional information specific to a particular event occurrence.<br />

• Rule—Displays the source and destination zones for the access rule. This field provides a link to<br />

the access rule defined in the ‘Firewall’ > ‘Access Rules’ page.<br />

The display fields for a log event message provides you with data to verify your configurations, trouble-shoot<br />

your security appliance, and track IP traffic.<br />

SONICOS LOG EVENT REFERENCE GUIDE 3


Configuring <strong>SonicOS</strong> ‘<strong>Log</strong>’ > ‘View’<br />

The ‘<strong>Log</strong>’ > ‘View” page in the Web-based <strong>SonicWALL</strong> management interface allows you to export log<br />

reports, e-mail log reports, and monitor real-time Syslog data. As soon as you power on your <strong>SonicWALL</strong><br />

security appliance, <strong>SonicOS</strong> software sends Syslog data to your log. In the <strong>SonicWALL</strong> management<br />

interface, you can navigate through the subcategories of the ‘<strong>Log</strong>’ setting for reporting and<br />

customizing log reports.<br />

In Figure 2, the ‘<strong>Log</strong>’ > ‘View’ page is displayed.<br />

Figure 2 <strong>SonicOS</strong> Enhanced ‘<strong>Log</strong>’ > ‘View’ page<br />

4 SONICOS LOG EVENT REFERENCE GUIDE


Setting the <strong>Log</strong> Filter <strong>Log</strong>ic<br />

By default, the <strong>SonicOS</strong> filter logic is set to “Priority && Category && Source && Destination.” The<br />

double ampersand symbols (&&) indicate the boolean expression “and.” The default <strong>SonicOS</strong> filter<br />

logic displays all log events.<br />

In Figure 3, the ‘<strong>Log</strong>’ > ‘View’ > ‘<strong>Log</strong> View Settings’ page is displayed.<br />

Figure 3<br />

<strong>SonicOS</strong> ‘<strong>Log</strong> View Settings’<br />

<strong>Log</strong> <strong>Event</strong> Message Filters<br />

Default filter logic value<br />

Group filters<br />

Apply filters<br />

Default filter logic<br />

Export logs<br />

Reset filters<br />

Applying Custom <strong>Log</strong> <strong>Event</strong> Message Filters<br />

This section provides examples on using the ‘<strong>Log</strong> View Settings’ to filter log event messages displayed<br />

in the ‘<strong>Log</strong> View’ page.<br />

Configuration Example: Filtering <strong>Log</strong> <strong>Event</strong> Messages by Priority Value<br />

To set the log filter logic to display only log event messages with a priority level of Emergency:<br />

1. Select Emergency from the filter-Priority Value pull-down menu.<br />

2. Click on the Apply Filters button.<br />

Configuration Example: Filtering <strong>Log</strong> <strong>Event</strong> Messages by Category Value<br />

To set the log filter logic to display only log event messages with a category event type of Attacks:<br />

1. Select Attacks from the filter-Category Value pull-down menu.<br />

2. Click on the Apply Filters button.<br />

SONICOS LOG EVENT REFERENCE GUIDE 5


Configuration Example: Filtering <strong>Log</strong> <strong>Event</strong> Messages by Source Value<br />

To set the log filter logic to display only log event messages associated to a source IP address:<br />

1. Enter the source IP address or select an interface from the filter-Source Value pull-down menu.<br />

2. Click on the Apply Filters button.<br />

Configuration Example: Filtering <strong>Log</strong> <strong>Event</strong> Messages by Destination Value<br />

To set the log filter logic to display only log event messages associated to a destination IP address:<br />

1. Enter the destination IP address or select an interface from the filter-Source Value pull-down<br />

menu.<br />

2. Click on the Apply Filters button.<br />

Using Group Filters<br />

<br />

Note:<br />

Use Group filters to change the default <strong>SonicOS</strong> filter logic (Priority && Category && Source && Destination)<br />

from double ampersand symbols (&&) to double pipe symbols (||) to indicate the boolean<br />

expression “or.” When using group filters, select two or more Group Filters checkboxes.<br />

If you select only one Group Filter checkbox, the filter logic will remain the same. Selecting only<br />

the Priority-Group Filter checkbox provides you with the following filter logic:<br />

(Priority) && Category && Source && Destination<br />

Configuration Example: Using the ‘Priority’ Group Filter and ‘Category Group’ Filter<br />

To set the log filter logic to display log event messages with a priority level of Emergency or a category<br />

event type of Attack:<br />

1. Select the ‘Priority’ group filter checkbox.<br />

2. Select the ‘Category’ group filter checkbox.<br />

3. Select Emergency from the filter-Priority Value pull-down menu.<br />

4. Select Attacks from the filter-Category Value pull-down menu.<br />

Figure 4 illustrates the <strong>SonicOS</strong> filter logic updated as follows:<br />

(Priority || Category) && Source && Destination<br />

Figure 4 <strong>SonicOS</strong> <strong>Log</strong> Group Filters<br />

A filter logic using the boolean expression “||” is less restrictive than the default filter logic using the<br />

boolean expression “&&”. With the boolean expression “||”, log event messages are displayed if they<br />

match either filter values. With the boolean expression “&&”, log event messages are displayed if they<br />

match both filter values.<br />

6 SONICOS LOG EVENT REFERENCE GUIDE


Exporting the <strong>Log</strong>s to a File<br />

This section provides instructions to export your log to a file.<br />

To export the log to a file:<br />

1. Click on the Export <strong>Log</strong> button. You will be prompted to select a export file format type as<br />

illustrated in Figure 5.<br />

Figure 5 <strong>SonicOS</strong> Export <strong>Log</strong><br />

<br />

Note:<br />

2. Select a file format:<br />

Plain text format used in log and alert e-mail—Saves the log file as plain text, which can be<br />

used for alert e-mails.<br />

Comma-Separated Value (CSV) format—Saves the log file for importing into Microsoft Excel or<br />

other presentation development application.<br />

3. Click on the Export button.<br />

4. Save the exported log file to a location on your personal computer’s hard drive.<br />

You can export a log to a file with applied filter settings.<br />

Referencing the <strong>SonicOS</strong> ‘<strong>Log</strong>’ > ‘View ’<br />

Field Display<br />

<strong>SonicOS</strong> 2.5 Enhanced and Standard releases and greater provide the <strong>SonicOS</strong> ‘<strong>Log</strong>’ > ‘View’ field<br />

display as illustrated in Figure 6.<br />

Figure 6 <strong>SonicOS</strong> ‘<strong>Log</strong>’ > ‘View’ Field Display<br />

Time and Date Stamp<br />

Category<br />

Source IP Address<br />

<strong>Log</strong> <strong>Event</strong> Notes<br />

Priority<br />

Message Descrition<br />

Destination IP<br />

Network Rule<br />

SONICOS LOG EVENT REFERENCE GUIDE 7


Referencing the <strong>SonicWALL</strong> Firmware ‘<strong>Log</strong>’ > ‘View <strong>Log</strong>’ Field Display<br />

<strong>SonicWALL</strong> Firmware 6.6.0.0 release and greater provide the <strong>SonicWALL</strong> Firmware ‘<strong>Log</strong>’ > ‘View<br />

<strong>Log</strong>’ field display as illustrated in Figure 7.<br />

Figure 7<br />

<strong>SonicWALL</strong> Firmware <strong>Log</strong>’ > ‘View <strong>Log</strong>’ Field Display<br />

Time and Date Stamp<br />

Source IP Address<br />

Additional Information<br />

<strong>Event</strong> Message<br />

Destination IP Address<br />

Rule Number (If Applicable)<br />

8 SONICOS LOG EVENT REFERENCE GUIDE


Index of <strong>Log</strong> <strong>Event</strong> Messages<br />

This section contains a list of log event messages for all <strong>SonicWALL</strong> Firmware and <strong>SonicOS</strong> Software<br />

Releases, ordered alphabetically. Use your web browser’s Find function to search for a command.<br />

<strong>Log</strong> <strong>Event</strong> Message Symbols Key<br />

<strong>Log</strong> <strong>Event</strong> Message Symbol Description Context<br />

%s Ethernet Port Down Represents a character string. [WAN | LAN | DMZ] Ethernet Port<br />

Down<br />

The cache is full; %u open<br />

connections; some will be dropped<br />

Represents a numerical string.<br />

The cache is full; [40,000] open<br />

connections; some will be dropped<br />

TCP IP Layered-Data Packet Processing and <strong>SonicOS</strong> <strong>Log</strong> <strong>Event</strong> Handling<br />

In specific cases of multi-layer packet processing, a TCP connection initially logged as "open," will be<br />

rejected by a deeper layer of packet processing. In these cases, the connection request has not been<br />

forwarded by the <strong>SonicWALL</strong> security appliance, and the initial Connection Open <strong>SonicOS</strong> log event<br />

message should be ignored in favor of the TCP Connection Dropped log event message.<br />

Each log event message described in the following table provides the following log event details:<br />

• <strong>SonicOS</strong> Category—Displays the <strong>SonicOS</strong> Software category event type.<br />

• Legacy Category—Displays the <strong>SonicWALL</strong> Firmware Software category event type.<br />

• Priority Level—Displays the level of urgency of the log event message.<br />

• <strong>Log</strong> Message ID Number—Displays the ID number of the log event message.<br />

• SNMP Trap Type—Displays the SNMP Trap ID number of the log event message.<br />

<strong>Log</strong> <strong>Event</strong><br />

Message<br />

<strong>SonicOS</strong><br />

Category<br />

Legacy<br />

Category<br />

Priority<br />

Level<br />

<strong>Log</strong><br />

Message<br />

ID<br />

Number<br />

SNMP<br />

Trap<br />

Type<br />

<strong>Log</strong> <strong>Event</strong><br />

Type<br />

#Web site hit<br />

Network<br />

Traffic<br />

Connection<br />

Traffic<br />

Information 97 --- Standard<br />

HTTP<br />

Traffic<br />

Report<br />

%s VPN IKE User Activity Information 171 --- Standard<br />

Message<br />

String<br />

%s ARS --- Information 840 --- Standard<br />

Message<br />

String<br />

%s ARS --- Notice 841 --- Standard<br />

Message<br />

String<br />

%s ARS --- Debug 842 --- Standard<br />

Message<br />

String<br />

SONICOS LOG EVENT REFERENCE GUIDE 9


%s Ethernet Port<br />

Down<br />

%s Ethernet Port<br />

Up<br />

%s-payload<br />

processing error<br />

Firewall <strong>Event</strong> System Error Error 333 641 Standard<br />

String<br />

Service<br />

Firewall <strong>Event</strong> System Error Warning 332 640 Standard<br />

String<br />

Service<br />

VPN IKE Debug Error 616 --- Standard<br />

Message<br />

String<br />

<strong>SonicWALL</strong><br />

Registration<br />

Update Needed:<br />

Restore your<br />

existing<br />

security service<br />

subscriptions by<br />

clicking here.<br />

Security<br />

Services<br />

Maintenance Warning 496 --- Simple<br />

802.11b<br />

Management<br />

Wireless 802.11b<br />

Management<br />

Information 518 --- Simple<br />

Destination<br />

A prior version of<br />

preferences was<br />

loaded because the<br />

most recent<br />

preferences file<br />

was inaccessible<br />

A <strong>SonicOS</strong><br />

Standard to<br />

Enhanced Upgrade<br />

was performed<br />

Firewall <strong>Event</strong> System Error Warning 572 648 Simple<br />

Firewall <strong>Event</strong> Maintenance Information 611 --- Simple<br />

Access attempt<br />

from host out of<br />

compliance with<br />

GSC policy<br />

Access attempt<br />

from host without<br />

Anti-Virus agent<br />

installed<br />

Access attempt<br />

from host without<br />

GSC installed<br />

Security<br />

Services<br />

Security<br />

Services<br />

Security<br />

Services<br />

Maintenance Information 761 --- Standard<br />

Maintenance Information 123 --- Standard<br />

Maintenance Information 763 524 Standard<br />

Access rule added Firewall Rule User Activity Information 440 --- Simple<br />

Rule<br />

Access rule<br />

deleted<br />

Firewall Rule User Activity Information 442 --- Simple<br />

Rule String<br />

10 SONICOS LOG EVENT REFERENCE GUIDE


Access rule<br />

modified<br />

Firewall Rule User Activity Information 441 --- Simple<br />

Rule<br />

Access to proxy<br />

server denied<br />

ActiveX access<br />

denied<br />

ActiveX or Java<br />

archive access<br />

denied<br />

Network<br />

Access<br />

Network<br />

Access<br />

Network<br />

Access<br />

Blocked Sites Notice 60 705 Standard<br />

Note<br />

Blocked<br />

Blocked Code Notice 18 --- Standard<br />

Note<br />

Blocked<br />

Blocked Code Notice 20 --- Standard<br />

Note<br />

Blocked<br />

AD agent %s is not<br />

responding<br />

Add an attack<br />

message<br />

Adding Dynamic<br />

Entry for Bound<br />

MAC Address<br />

Adding L2TP IP<br />

pool Address<br />

object Failed<br />

Adding to<br />

multicast<br />

policyList,<br />

interface: %s<br />

Adding to Multicast<br />

policyList, VPN<br />

SPI: %s<br />

Administrator<br />

logged out<br />

Administrator<br />

logged<br />

out - inactivity<br />

timer expired<br />

Administrator login<br />

allowed<br />

Administrator login<br />

denied due to bad<br />

credentials<br />

MS AD --- Error 769 --- Standard<br />

Message<br />

String<br />

Firewall <strong>Event</strong> Attack Error 143 525 Simple<br />

String<br />

Network --- Information 813 --- Standard<br />

Note ENET<br />

L2TP Server System Error Error 603 661 Simple<br />

Multicast --- Debug 697 --- Standard<br />

Message<br />

String<br />

Multicast --- Debug 699 --- Standard<br />

Message<br />

String<br />

Authentication User Activity Information 261 --- Standard<br />

Authentication User Activity Information 262 --- Standard<br />

Authentication User Activity Information 29 --- Standard<br />

Authentication Attack Alert 30 560 Standard<br />

SONICOS LOG EVENT REFERENCE GUIDE 11


Administrator login<br />

denied from %s;<br />

logins disabled<br />

from this interface<br />

Adminstrator name<br />

changed<br />

All DDNS<br />

associations have<br />

been deleted<br />

All preference<br />

values have been<br />

set to factory<br />

default values<br />

Allowed LDAP<br />

server certificate<br />

with wrong host<br />

name<br />

Authentication Attack Alert 35 506 Standard<br />

Message<br />

String<br />

Authentication Maintenance Information 328 --- Standard<br />

DDNS Maintenance Information 783 --- Simple<br />

Firewall <strong>Event</strong> System Error Warning 574 650 Simple<br />

RADIUS User Activity Warning 752 --- Standard<br />

Note String<br />

Anti-Spyware<br />

Detection Alert: %s<br />

Anti-Spyware<br />

Prevention Alert:<br />

%s<br />

Anti-Spyware<br />

Service Expired<br />

Anti-Virus agent<br />

out-of-date on host<br />

Anti-Virus<br />

Licenses Exceeded<br />

Intrusion<br />

Detection<br />

Intrusion<br />

Detection<br />

Security<br />

Services<br />

Security<br />

Services<br />

Security<br />

Services<br />

Attack Alert 795 576 Standard<br />

Anti-Spy<br />

Message<br />

String<br />

Attack Alert 794 575 Standard<br />

Anti-Spy<br />

Message<br />

String<br />

Maintenance Warning 796 577 Simple<br />

Maintenance Information 124 --- Standard<br />

Maintenance Information 408 --- Standard<br />

Arp request packet<br />

received<br />

Arp request packet<br />

sent<br />

Arp response<br />

packet received<br />

Arp response<br />

packet sent<br />

Network --- Information 717 --- Standard<br />

Note ENET<br />

Network --- Information 715 --- Standard<br />

Note ENET<br />

Network --- Information 716 --- Standard<br />

Note ENET<br />

Network --- Information 718 --- Standard<br />

Note ENET<br />

ARP timeout Network Debug Debug 45 --- Standard<br />

Association Flood<br />

from wlan station<br />

WLAN IDS WLAN IDS Alert 548 903 Simple<br />

Destination<br />

12 SONICOS LOG EVENT REFERENCE GUIDE


Authentication<br />

timeout during<br />

Remotely<br />

Triggered Dial-out<br />

session<br />

Authentication User Activity Information 821 --- Simple<br />

Back Orifice attack<br />

dropped<br />

Backup active<br />

Backup firewall<br />

being preempted<br />

by Primary<br />

Backup firewall<br />

has transitioned to<br />

Active<br />

Backup firewall<br />

has transitioned to<br />

Idle<br />

Backup going<br />

Active in preempt<br />

mode after reboot<br />

Backup missed<br />

heartbeats from<br />

Primary<br />

Backup received<br />

error signal from<br />

Primary<br />

Backup received<br />

reboot signal from<br />

Primary<br />

Backup shut down<br />

because license is<br />

expired<br />

Backup will be<br />

shut down in %s<br />

minutes<br />

Intrusion<br />

Detection<br />

High<br />

Avaiability<br />

High<br />

Availability<br />

High<br />

Availability<br />

High<br />

Availability<br />

High<br />

Availability<br />

High<br />

Availability<br />

High<br />

Availability<br />

High<br />

Availability<br />

High<br />

Availability<br />

High<br />

Availability<br />

Attack Alert 73 512 Standard<br />

System Error Information 825 --- Simple<br />

System Error Error 152 619 Simple<br />

Maintenance Information 145 --- Simple<br />

Maintenance Information 147 --- Simple<br />

System Error Error 170 622 Simple<br />

System Error Error 149 616 Simple<br />

System Error Error 151 618 Simple<br />

System Error Error 672 666 Simple<br />

System Error Error 824 --- Simple<br />

System Error Error 823 --- Standard<br />

String<br />

Service<br />

Bad CRL format VPN PKI User Activity Alert 277 --- Simple<br />

Destination<br />

Blocked Quick<br />

Mode for Client<br />

using Default<br />

KeyId<br />

VPN Client System Error Error 505 660 Standard<br />

SONICOS LOG EVENT REFERENCE GUIDE 13


BOOTP Client IP<br />

address on LAN<br />

conflicts with<br />

remote device IP,<br />

deleting IP address<br />

from remote table<br />

BOOTP reply<br />

relayed to local<br />

device<br />

BOOTP Request<br />

received from<br />

remote device<br />

BOOTP server<br />

response relayed<br />

to remote device<br />

BOOTP Maintenance Information 619 --- Standard<br />

Destination<br />

BOOTP Maintenance Information 620 --- Standard<br />

Destination<br />

BOOTP Debug Debug 621 --- Standard<br />

Destination<br />

BOOTP Debug Debug 618 --- Standard<br />

Destination<br />

Broadcast packet<br />

dropped<br />

Network<br />

Access<br />

Debug Debug 46 --- Standard<br />

Note<br />

Protocol<br />

Cannot connect to<br />

the CRL server<br />

Cannot Validate<br />

Issuer Path<br />

Certificate on<br />

Revoked list (CRL)<br />

VPN PKI User Activity Alert 274 --- Simple<br />

Destination<br />

VPN PKI User Activity Alert 878 --- Simple<br />

Destination<br />

VPN PKI User Activity Alert 279 --- Simple<br />

Destination<br />

CFL<br />

auto-download<br />

disabled, time<br />

problem detected<br />

Security<br />

Services<br />

Maintenance Information 268 --- Simple<br />

CLI administrator<br />

logged out<br />

CLI administrator<br />

login allowed<br />

CLI administrator<br />

login denied due to<br />

bad credentials<br />

Computed hash<br />

does not match<br />

hash received from<br />

peer<br />

Authentication User Activity Information 520 --- Simple<br />

Authentication User Activity Information 199 --- Simple<br />

Authentication User Activity Warning 200 --- Simple<br />

VPN IKE User Activity Warning 410 --- Standard<br />

Destination<br />

14 SONICOS LOG EVENT REFERENCE GUIDE


Connection Closed<br />

Note: In specific cases of<br />

multi-layer packet processing,<br />

a TCP connection initially<br />

logged as "open," will be<br />

rejected by a deeper layer of<br />

packet processing. In these<br />

cases, the connection request<br />

has not been forwarded by<br />

the <strong>SonicWALL</strong> security<br />

appliance, and the initial<br />

Connection Open <strong>SonicOS</strong><br />

log event message should be<br />

ignored in favor of the TCP<br />

Connection Dropped log<br />

event message.<br />

Network<br />

Traffic<br />

Connection<br />

Traffic<br />

Information 537 --- Standard<br />

Traffic<br />

Report<br />

Connection<br />

Opened<br />

Note: In specific cases of<br />

multi-layer packet processing,<br />

a TCP connection initially<br />

logged as "open," will be<br />

rejected by a deeper layer of<br />

packet processing. In these<br />

cases, the connection request<br />

has not been forwarded by<br />

the <strong>SonicWALL</strong> security<br />

appliance, and the initial<br />

Connection Open <strong>SonicOS</strong><br />

log event message should be<br />

ignored in favor of the TCP<br />

Connection Dropped log<br />

event message.<br />

Network<br />

Traffic<br />

Connection Information 98 --- Standard<br />

Note<br />

Protocol<br />

Connection timed<br />

out<br />

VPN PKI User Activity Alert 273 --- Simple<br />

Destination<br />

Cookie removed<br />

Network<br />

Access<br />

Blocked Code Notice 21 --- Standard<br />

String<br />

Service<br />

CRL has expired VPN PKI User Activity Alert 874 --- Simple<br />

Destination<br />

CRL loaded from VPN PKI User Activity Information 270 --- Simple<br />

Destination<br />

CRL<br />

missing - Issuer<br />

requires CRL<br />

checking<br />

CRL validation<br />

failure for Root<br />

Certificate<br />

Crypto DES test<br />

failed<br />

Crypto DH test<br />

failed<br />

VPN PKI User Activity Alert 876 --- Simple<br />

Destination<br />

VPN PKI User Activity Alert 877 --- Simple<br />

Destination<br />

Crypto Test Maintenance Error 360 --- Simple<br />

Crypto Test Maintenance Error 361 --- Simple<br />

SONICOS LOG EVENT REFERENCE GUIDE 15


Crypto Hardware<br />

3Des test failed<br />

Crypto Hardware<br />

3DES with SHA<br />

test failed<br />

Crypto Hardware<br />

AES test failed<br />

Crypto hardware<br />

DES test failed<br />

Crypto Haredware<br />

DES with SHA test<br />

failed<br />

Crypto Hmac-MD5<br />

fest failed<br />

Crypto Hmac-Sha1<br />

test failed<br />

Crypto MD5 test<br />

failed<br />

Crypto RSA test<br />

failed<br />

Crypto Sha1 test<br />

failed<br />

DDNS association<br />

%s disabled<br />

DDNS association<br />

%s enabled<br />

DDNS association<br />

%s added<br />

DDNS association<br />

%s deactivated<br />

DDNS association<br />

%s deleted<br />

DDNS Association<br />

%s put on line<br />

Crypto Test Maintenance Error 367 --- Simple<br />

Crypto Test Maintenance Error 369 --- Simple<br />

Crypto Test Maintenance Error 610 --- Standard<br />

Crypto Test Maintenance Error 366 --- Simple<br />

Crypto Test Maintenance Error 368 --- Simple<br />

Crypto Test Maintenance Error 362 --- Simple<br />

Crypto Test Maintenance Error 363 --- Simple<br />

Crypto Test Maintenance Error 370 --- Simple<br />

Crypto Test Maintenance Error 364 --- Simple<br />

Crypto Test Maintenance Error 365 --- Simple<br />

DDNS Maintenance Information 781 --- Simple<br />

Message<br />

String<br />

DDNS Maintenance Information 780 --- Simple<br />

Message<br />

String<br />

DDNS Maintenance Information 779 --- Simple<br />

Message<br />

String<br />

DDNS Maintenance Information 784 --- Simple<br />

Message<br />

String<br />

DDNS Maintenance Information 785 --- Simple<br />

Message<br />

String<br />

DDNS Maintenance Information 782 --- Simple<br />

Message<br />

String<br />

16 SONICOS LOG EVENT REFERENCE GUIDE


DDNS association<br />

%s taken Offline<br />

locally<br />

DDNS Failure:<br />

Provider %s<br />

DDNS Failure:<br />

Provider %s<br />

DDNS Failure:<br />

Provider %s<br />

DDNS Update<br />

success for<br />

domain %s<br />

DDNS Warning:<br />

Provider %s<br />

Deleting from<br />

Multicast policy<br />

list, interface : %s<br />

Deleting from<br />

Multicast policy<br />

list, VPN SPI : %s<br />

DDNS Maintenance Information 778 --- Simple<br />

Message<br />

String<br />

DDNS System Error Error 774 --- Simple<br />

Message<br />

String<br />

DDNS System Error Error 775 --- Simple<br />

Message<br />

String<br />

DDNS System Error Error 773 --- Simple<br />

Message<br />

String<br />

DDNS Maintenance Information 776 --- Standard<br />

Message<br />

String<br />

DDNS System Error Warning 777 --- Simple<br />

Message<br />

String<br />

Multicast --- Debug 698 --- Standard<br />

Message<br />

String<br />

Multicast --- Debug 700 --- Standard<br />

Message<br />

String<br />

Deleting IPSec SA VPN IKE User Activity Information 92 --- Standard<br />

Note SPI<br />

DHCP client<br />

enabled but not<br />

ready<br />

DHCP Client did<br />

not get DHCP ACK<br />

DHCP Client failed<br />

to verify and lease<br />

has expired. Go to<br />

INIT state.<br />

DHCP Client got a<br />

new IP address<br />

lease.<br />

DHCP Client got<br />

ACK from server<br />

DHCP Client got<br />

NACK<br />

DHCP Client Maintenance Information 504 --- Simple<br />

DHCP Client Maintenance Information 109 --- Standard<br />

DHCP Client Maintenance Information 119 --- Standard<br />

DHCP Client Maintenance Information 121 --- Standard<br />

Destination<br />

DHCP Client Maintenance Information 111 --- Standard<br />

Destination<br />

DHCP Client Maintenance Information 110 --- Standard<br />

SONICOS LOG EVENT REFERENCE GUIDE 17


DHCP Client is<br />

declining address<br />

offered by the<br />

server.<br />

DHCP Client<br />

sending REQUEST<br />

and going to<br />

REBIND state<br />

DHCP Client<br />

sending REQUEST<br />

and going to<br />

RENEW state<br />

DHCP DISCOVER<br />

received from<br />

remote device<br />

DHCP lease<br />

dropped. Lease<br />

from Central<br />

Gateway conflicts<br />

with Relay IP<br />

DHCP lease<br />

dropped. Lease<br />

from Central<br />

Gateway conflicts<br />

with Remote<br />

Management IP<br />

DHCP lease<br />

relayed to local<br />

device<br />

DHCP lease<br />

relayed to remote<br />

device<br />

DHCP lease to LAN<br />

device conflicts<br />

with remote device,<br />

deleting remote IP<br />

entry<br />

DHCP NAK<br />

received from<br />

server<br />

DHCP OFFER<br />

received from<br />

server<br />

DHCP Client Maintenance Information 112 --- Standard<br />

Destination<br />

DHCP Client Maintenance Information 113 --- Standard<br />

Destination<br />

DHCP Client Maintenance Information 114 --- Standard<br />

Destination<br />

DHCP Relay Debug Information 474 --- Standard<br />

Destination<br />

DHCP Relay Maintenance Warning 228 --- Standard<br />

Destination<br />

DHCP Relay Maintenance Warning 484 --- Standard<br />

Destination<br />

DHCP Relay Maintenance Information 223 --- Standard<br />

Destination<br />

DHCP Relay Debug Information 225 --- Standard<br />

Destination<br />

DHCP Relay Maintenance Information 226 --- Standard<br />

Destination<br />

DHCP Relay Debug Information 477 --- Standard<br />

Destination<br />

DHCP Relay Debug Information 476 --- Standard<br />

Destination<br />

18 SONICOS LOG EVENT REFERENCE GUIDE


DHCP Ranges<br />

altered<br />

automatically due<br />

to change in<br />

network settings<br />

for interface %s<br />

DHCP RELEASE<br />

received from<br />

remote device<br />

DHCP RELEASE<br />

relayed to Central<br />

Gateway<br />

DHCP REQUEST<br />

received from<br />

remote device<br />

DHCP Server not<br />

available. Did not<br />

get any DHCP<br />

OFFER.<br />

Firewall <strong>Event</strong> --- Information 832 --- Standard<br />

String<br />

Service<br />

DHCP Relay Debug Information 224 --- Standard<br />

Destination<br />

DHCP Relay Maintenance Information 222 --- Standard<br />

Destination<br />

DHCP Relay Debug Information 473 --- Standard<br />

Destination<br />

DHCP Client Maintenance Information 106 --- Standard<br />

Diagnostic Code A<br />

Diagnostic Code B<br />

Diagnostic Code C<br />

Diagnostic Code D<br />

Diagnostic Code D<br />

Firewall<br />

Hardware<br />

Firewall<br />

Hardware<br />

Firewall<br />

Hardware<br />

Firewall<br />

Hardware<br />

Firewall<br />

Hardware<br />

System Error Error 93 611 Simple<br />

Note String<br />

System Error Error 94 612 Simple<br />

Note String<br />

System Error Error 95 613 Simple<br />

Note String<br />

System Error Error 64 610 Standard<br />

Note Code<br />

System Error Error 517 642 Simple<br />

Note String<br />

Diagnostic Code E VPN IPSec System Error Error 61 609 Standard<br />

Note Code<br />

Diagnostic Code F<br />

Diagnostic Code G<br />

Diagnostic Code H<br />

Diagnostic Code I<br />

Firewall<br />

Hardware<br />

Firewall<br />

Hardware<br />

Firewall<br />

Hardware<br />

Firewall<br />

Hardware<br />

System Error Error 164 621 Simple<br />

Note String<br />

System Error Error 599 655 Simple<br />

Note String<br />

System Error Error 600 656 Simple<br />

Note String<br />

System Error Error 601 657 Simple<br />

Note String<br />

Disconnecting<br />

L2TP Tunnel due to<br />

traffic timeout<br />

L2TP Client Maintenance Information 215 --- Simple<br />

SONICOS LOG EVENT REFERENCE GUIDE 19


Disconnecting<br />

PPPoE due to<br />

traffic timeout<br />

Disconnecting<br />

PPTP Tunnel due<br />

to traffic timeout<br />

PPPoE Maintenance Information 168 --- Simple<br />

PPTP Maintenance Information 389 --- Simple<br />

Discovered HA<br />

Backup Firewall<br />

DNS packet<br />

allowed<br />

Drop Wlan traffic<br />

from non<br />

SonicPoint devcies<br />

High<br />

Availability<br />

Network<br />

Access<br />

Intrusion<br />

Detection<br />

Maintenance Information 156 --- Simple<br />

Debug Information 602 --- Standard<br />

Policy<br />

Attack Error 662 572 Standard<br />

Dynamic IPSec<br />

client connected<br />

VPN IPSec User Activity Information 62 --- Standard<br />

Destination<br />

EIGRP packet<br />

dropped<br />

E-Mail fragment<br />

dropped<br />

Error initializing<br />

Hardware<br />

acceleration for<br />

VPN<br />

Error Rebooting<br />

HA Peer Firewall<br />

Error setting the IP<br />

address of the<br />

backup, please<br />

manually set to<br />

backup LAN IP<br />

Error<br />

Synchronizing HA<br />

Peer Firewall<br />

Network<br />

Access<br />

Intrusion<br />

Detection<br />

Firewall<br />

Hardware<br />

High<br />

Availability<br />

High<br />

Availability<br />

High<br />

Availability<br />

Debug Notice 714 --- Standard<br />

Note String<br />

Attack Error 437 550 Standard<br />

Maintenance Error 374 --- Simple<br />

System Error Error 669 663 Simple<br />

System Error Error 191 629 Simple<br />

System Error Error 158 662 Simple<br />

Exceeded Max<br />

multicast address<br />

limit<br />

Failed payload<br />

validation<br />

Failed payload<br />

verification after<br />

decryption.<br />

Possible preshared<br />

key mismatch.<br />

Multicast --- Warning 703 --- Standard<br />

VPN IKE User Activity Warning 405 --- Standard<br />

VPN IKE User Activity Warning 404 --- Standard<br />

20 SONICOS LOG EVENT REFERENCE GUIDE


Failed to find<br />

certificate<br />

Failed to get CRL<br />

from<br />

Failed to Process<br />

CRL from<br />

Failed to resolve<br />

name<br />

Failed to<br />

synchronize Relay<br />

IP Table<br />

Failure to add data<br />

channel<br />

VPN PKI User Activity Alert 875 --- Simple<br />

Destination<br />

VPN PKI User Activity Alert 271 --- Simple<br />

Destination<br />

VPN PKI User Activity Alert 276 --- Simple<br />

Destination<br />

Network Maintenance Information 84 --- Simple<br />

Destination<br />

DHCP Relay System Error Warning 234 632 Standard<br />

Unused Debug Debug 49 --- Standard<br />

Failure to reach<br />

Interface %s probe<br />

High<br />

Availability<br />

System Error Error 675 647 Standard<br />

String Service<br />

Fan Failure<br />

Firewall<br />

Hardware<br />

System<br />

Environment<br />

Alert 576 102 Simple<br />

Forbidden E-Mail<br />

attachment deleted<br />

Forbidden E-Mail<br />

attachment<br />

disabled<br />

Intrusion<br />

Detection<br />

Intrusion<br />

Detection<br />

Attack Error 248 534 Standard<br />

Destination<br />

Attack Alert 165 527 Standard<br />

Destination<br />

Found Rogue<br />

Access Point<br />

Found Rogue<br />

Access Point<br />

WLAN IDS WLAN IDS Alert 546 901 Simple<br />

Destination<br />

WLAN IDS WLAN IDS Alert 556 901 Simple<br />

Destination<br />

Fragmented packet<br />

dropped<br />

Network TCP | UDP |<br />

ICMP<br />

Notice 28 --- Standard<br />

Note<br />

Protocol<br />

Fraudulent<br />

Microsoft<br />

certificate found;<br />

access denied<br />

FTP: Data<br />

connection from<br />

non default port<br />

dropped<br />

FTP: PASV<br />

response bounce<br />

attack dropped.<br />

Intrusion<br />

Detection<br />

Network<br />

Access<br />

Intrusion<br />

Detection<br />

Attack Error 193 532 Standard<br />

Attack Alert 538 557 Standard<br />

Attack Alert 528 556 Standard<br />

Note String<br />

SONICOS LOG EVENT REFERENCE GUIDE 21


FTP: PASV<br />

response spoof<br />

attack dropped.<br />

FTP: PORT bounce<br />

attack dropped.<br />

Gateway Anti-Virus<br />

Alert: %s<br />

Gateway Anti-Virus<br />

Service expired<br />

Intrusion<br />

Detection<br />

Intrusion<br />

Detection<br />

Security<br />

Services<br />

Security<br />

Services<br />

Attack Error 446 551 Standard<br />

Attack Alert 527 555 Standard<br />

Note String<br />

Attack Alert 809 --- Standard<br />

Message<br />

String<br />

Maintenance Warning 810 --- Simple<br />

Global VPN Client<br />

connection is not<br />

allowed. Appliance<br />

is not registered.<br />

Global VPN Client<br />

License Exceeded:<br />

Connection<br />

denied.<br />

Global VPN Client<br />

version cannot<br />

enforce personal<br />

firewall. Minimum<br />

Version required is<br />

2.1.<br />

Got DHCP OFFER.<br />

Selecting.<br />

VPN Client System Error Information 529 643 Standard<br />

VPN Client System Error Information 494 658 Standard<br />

VPN Client User Activity Information 604 --- Standard<br />

Destination<br />

DHCP Client Maintenance Information 107 --- Standard<br />

Destination<br />

GSC policy<br />

out-of-date on host<br />

Security<br />

Services<br />

Maintenance Information 762 --- Standard<br />

Guest account '%s'<br />

created<br />

Guest account '%s'<br />

deleted<br />

Guest account '%s'<br />

disabled<br />

Guest account '%s'<br />

pruned<br />

Guest account '%s'<br />

re-enabled<br />

Authentication User Activity Information 558 --- Standard<br />

Message<br />

String<br />

Authentication User Activity Information 559 --- Standard<br />

Message<br />

String<br />

Authentication User Activity Information 560 --- Standard<br />

Message<br />

String<br />

Authentication User Activity Information 562 --- Standard<br />

Message<br />

String<br />

Authentication User Activity Information 561 --- Standard<br />

Message<br />

String<br />

22 SONICOS LOG EVENT REFERENCE GUIDE


Guest account '%s'<br />

re-generated<br />

Guest login denied.<br />

Guest '%s' is<br />

already logged in.<br />

Please try again<br />

later.<br />

H.323/H.225<br />

Connect<br />

Authentication User Activity Information 563 --- Standard<br />

Message<br />

String<br />

Authentication User Activity Information 557 --- Standard<br />

Message<br />

String<br />

VoIP VoIP Debug 634 --- Standard<br />

Note String<br />

H.323/H.225 Setup VoIP VoIP Debug 633 --- Standard<br />

Note String<br />

H.323/H.245<br />

Address<br />

H.323/H.245 End<br />

Session<br />

H.323/RAS<br />

Admission Confirm<br />

H.323/RAS<br />

Admission Reject<br />

H.323/RAS<br />

Admission<br />

Request<br />

H.323/RAS<br />

Bandwidth Reject<br />

H.323/RAS<br />

Disengage Confirm<br />

H.323/RAS<br />

Disengage Reject<br />

H.323/RAS<br />

Gatekeeper Reject<br />

H.323/RAS<br />

Location Confirm<br />

H.323/RAS<br />

Location Reject<br />

H.323/RAS<br />

Registration Reject<br />

H.323/RAS<br />

Unknown Message<br />

Response<br />

VoIP VoIP Debug 635 --- Standard<br />

Note String<br />

VoIP VoIP Debug 636 --- Standard<br />

Note String<br />

VoIP VoIP Debug 625 --- Standard<br />

Note String<br />

VoIP VoIP Debug 624 --- Standard<br />

Note String<br />

VoIP VoIP Debug 626 --- Standard<br />

Note String<br />

VoIP VoIP Debug 627 --- Standard<br />

Note String<br />

VoIP VoIP Debug 628 --- Standard<br />

Note String<br />

VoIP VoIP Debug 641 --- Standard<br />

Note String<br />

VoIP VoIP Debug 629 --- Standard<br />

Note String<br />

VoIP VoIP Debug 630 --- Standard<br />

Note String<br />

VoIP VoIP Debug 631 --- Standard<br />

Note String<br />

VoIP VoIP Debug 632 --- Standard<br />

Note String<br />

VoIP VoIP Debug 640 --- Standard<br />

Note String<br />

SONICOS LOG EVENT REFERENCE GUIDE 23


H.323/RAS<br />

Unregistration<br />

Reject<br />

VoIP VoIP Debug 642 --- Standard<br />

Note String<br />

HA packet<br />

processing error<br />

High<br />

Availability<br />

Maintenance Information 162 --- Simple<br />

Hardware Failover<br />

settings were not<br />

upgraded<br />

Header verification<br />

failed<br />

HTTP<br />

management port<br />

has changed<br />

HTTPS<br />

management port<br />

has changed<br />

Firewall <strong>Event</strong> Maintenance Information 743 --- Simple<br />

VPN IKE User Activity Warning 587 --- Standard<br />

Firewall <strong>Event</strong> Maintenance Information 340 --- Simple<br />

Note String<br />

Firewall <strong>Event</strong> Maintenance Information 341 --- Simple<br />

Note String<br />

ICMP checksum<br />

error<br />

ICMP packet<br />

allowed<br />

ICMP packet<br />

dropped<br />

ICMP packet<br />

dropped<br />

ICMP packet from<br />

LAN allowed<br />

Network<br />

Access<br />

Network<br />

Access<br />

Network<br />

Access<br />

Network<br />

Access<br />

Network<br />

Access<br />

UDP Notice 886 --- Standard<br />

Debug Information 597 --- Standard<br />

Policy<br />

ICMP Notice 38 --- Standard<br />

Policy<br />

ICMP Notice 523 --- Standard<br />

ICMP<br />

Service<br />

Debug Information 598 --- Standard<br />

ICMP<br />

Service<br />

ICMP packet from<br />

LAN dropped<br />

Network<br />

Access<br />

LAN ICMP |<br />

LAN TCP<br />

Notice 175 --- Standard<br />

ICMP<br />

Service<br />

If not already<br />

enabled, enabling<br />

NTP is<br />

recommended<br />

Firewall<br />

Hardware<br />

System Error Warning 540 645 Simple<br />

IGMP packet<br />

dropped, wrong<br />

checksum received<br />

on interface %s<br />

IGMP Leave group<br />

message Received<br />

on interface %s<br />

Multicast --- Notice 683 --- Standard<br />

Message<br />

String<br />

Multicast --- Information 682 --- Standard<br />

Message<br />

String<br />

24 SONICOS LOG EVENT REFERENCE GUIDE


IGMP packet<br />

dropped, decoding<br />

error<br />

IGMP Packet Not<br />

handled. Packet<br />

type : %s<br />

IGMP querier<br />

Router detected on<br />

interface %s<br />

IGMP querier<br />

Router detected on<br />

VPN tunnel , SPI<br />

%S<br />

IGMP state table<br />

entry time<br />

out,deleting<br />

interface : %s for<br />

multicast address :<br />

%s<br />

IGMP state table<br />

entry time<br />

out,deleting VPN<br />

SPI :%s for<br />

Multicast address :<br />

%s<br />

IGMP V2 client<br />

joined multicast<br />

Group : %s<br />

IGMP V2<br />

Membership report<br />

received from<br />

interface %s<br />

IGMP V3 client<br />

joined multicast<br />

Group : %s<br />

IGMP V3<br />

Membership report<br />

received from<br />

interface %s<br />

IGMP V3 packet<br />

dropped,<br />

unsupported<br />

Record type : %s<br />

Multicast --- Notice 686 --- Standard<br />

Multicast --- Notice 687 --- Standard<br />

Message<br />

String<br />

Multicast --- Debug 701 --- Standard<br />

Message<br />

String<br />

Multicast --- Debug 702 --- Standard<br />

Message<br />

String<br />

Multicast --- Debug 692 --- Standard<br />

Message<br />

String<br />

Multicast --- Debug 693 --- Standard<br />

Message<br />

String<br />

Multicast --- Information 676 --- Standard<br />

Message<br />

String<br />

Multicast --- Debug 679 --- Standard<br />

Message<br />

String<br />

Multicast --- Information 677 --- Standard<br />

Message<br />

String<br />

Multicast --- Debug 678 --- Standard<br />

Message<br />

String<br />

Multicast --- Notice 688 --- Standard<br />

Message<br />

String<br />

SONICOS LOG EVENT REFERENCE GUIDE 25


IGMP V3 reord<br />

type : %s not<br />

Handled<br />

IKE ID mismatch<br />

%s<br />

IKE Initiator drop:<br />

Packet dest<br />

address does not<br />

match selected<br />

local interface<br />

address<br />

IKE Initiator:<br />

Accepting IPSec<br />

proposal (Phase 2)<br />

IKE Initiator:<br />

Accepting peer<br />

lifetime (Phase 1)<br />

IKE Initiator:<br />

Aggressive Mode<br />

complete (Phase 1)<br />

IKE Initiator: Main<br />

Mode complete<br />

(Phase 1)<br />

IKE Initiator:<br />

Received notify.<br />

NO_PROPOSAL_<br />

CHOSEN<br />

IKE Initiator: Start<br />

Aggressive Mode<br />

negotiation (Phase<br />

1)<br />

IKE Initiator: Start<br />

Main Mode<br />

negotiation (Phase<br />

1)<br />

IKE Initiator: Start<br />

Quick Mode (Phase<br />

2)<br />

IKE Initiator: Using<br />

secondary gateway<br />

to negotiate<br />

Multicast --- Debug 689 --- Standard<br />

Message<br />

String<br />

VPN IKE Debug Debug 658 --- Standard<br />

String<br />

Service<br />

VPN IKE User Activity Information 544 --- Standard<br />

VPN IKE User Activity Information 372 --- Standard<br />

Note String<br />

VPN IKE User Activity Information 445 --- Standard<br />

Destination<br />

VPN IKE User Activity Information 354 --- Standard<br />

Destination<br />

VPN IKE User Activity Information 353 --- Standard<br />

Destination<br />

VPN IKE User Activity Warning 401 --- Standard<br />

Destination<br />

VPN IKE User Activity Information 358 --- Standard<br />

VPN IKE User Activity Information 351 --- Standard<br />

VPN IKE User Activity Information 346 --- Standard<br />

VPN IKE User Activity Information 543 --- Standard<br />

Destination<br />

26 SONICOS LOG EVENT REFERENCE GUIDE


IKE negotiation<br />

aborted due to<br />

timeout<br />

IKE negotiation<br />

complete. Adding<br />

IPSec SA. (Phase<br />

2)<br />

IKE Responder<br />

drop: Packet dest<br />

address does not<br />

match selected<br />

local interface<br />

address<br />

IKE Responder: %s<br />

policy does not<br />

allow static IP for<br />

Virtual Adapter.<br />

IKE Responder:<br />

Accepting IPSec<br />

proposal (Phase 2)<br />

IKE Responder:<br />

Aggressive Mode<br />

complete (Phase 1)<br />

IKE Responder: AH<br />

Perfect Forward<br />

Secrecy mismatch<br />

IKE Responder:<br />

Algorithms and/or<br />

keys do not match<br />

IKE Responder:<br />

Default LAN<br />

gateway is not set<br />

but peer is proposing<br />

to use this SA<br />

as a default route<br />

IKE Responder:<br />

Default LAN<br />

gateway is set but<br />

peer is not<br />

proposing to use<br />

this SA as a default<br />

route<br />

VPN IKE User Activity Information 403 --- Standard<br />

VPN IKE User Activity Information 89 --- Standard<br />

VPN IKE User Activity Information 545 --- Standard<br />

VPN Client System Error Error 660 --- Standard<br />

Message<br />

String<br />

VPN IKE User Activity Information 87 --- Standard<br />

Note String<br />

VPN IKE User Activity Information 373 --- Standard<br />

Destination<br />

VPN IKE User Activity Warning 258 544 Standard<br />

VPN IKE User Activity Warning 260 546 Standard<br />

VPN IKE Attack Error 516 553 Standard<br />

Note String<br />

VPN IKE User Activity Warning 253 539 Standard<br />

Note String<br />

SONICOS LOG EVENT REFERENCE GUIDE 27


IKE Responder:<br />

ESP Perfect<br />

Forward Secrecy<br />

mismatch<br />

IKE Responder:<br />

IKE proposal does<br />

not match<br />

(Phase 1)<br />

IKE Responder: IP<br />

Address already<br />

exists in the DHCP<br />

relay table. Client<br />

traffic not allowed.<br />

IKE Responder:<br />

IPSec proposal<br />

does not match<br />

(Phase 2)<br />

IKE Responder:<br />

Main Mode<br />

complete (Phase 1)<br />

IKE Responder:<br />

Mode %d - not<br />

transport mode.<br />

Xauth is required<br />

but not supported<br />

by peer.<br />

IKE Responder:<br />

Mode %d - not<br />

tunnel mode<br />

IKE Responder: No<br />

match for<br />

proposed remote<br />

network address<br />

IKE Responder: No<br />

matching Phase 1<br />

ID found for<br />

proposed remote<br />

network<br />

IKE Responder:<br />

Proposed local<br />

network is 0.0.0.0<br />

but SA has no LAN<br />

Default Gateway<br />

VPN IKE User Activity Warning 259 545 Standard<br />

VPN IKE User Activity Warning 402 --- Standard<br />

Destination<br />

VPN Client System Error Error 659 --- Standard<br />

Note String<br />

VPN IKE User Activity Warning 88 523 Standard<br />

Note String<br />

VPN IKE User Activity Information 357 --- Standard<br />

Destination<br />

VPN IKE Debug Warning 342 --- Standard<br />

Message<br />

Number<br />

VPN IKE User Activity Warning 249 535 Standard<br />

Message<br />

Number<br />

VPN IKE User Activity Warning 252 538 Standard<br />

Note String<br />

VPN IKE User Activity Warning 250 536 Standard<br />

Note String<br />

VPN IKE User Activity Warning 418 549 Standard<br />

Note String<br />

28 SONICOS LOG EVENT REFERENCE GUIDE


IKE Responder:<br />

Proposed remote<br />

network is 0.0.0.0<br />

but not DHCP relay<br />

nor default route<br />

IKE Responder:<br />

Received<br />

Aggressive Mode<br />

request (Phase 1)<br />

IKE Responder:<br />

Received Main<br />

Mode request<br />

(Phase 1)<br />

IKE Responder:<br />

Received Quick<br />

Mode Request<br />

(Phase 2)<br />

IKE Responder:<br />

Tunnel terminates<br />

inside firewall but<br />

proposed local<br />

network is not<br />

inside firewall<br />

IKE Responder:<br />

Tunnel terminates<br />

on DMZ but<br />

proposed local<br />

network is on LAN<br />

IKE Responder:<br />

Tunnel terminates<br />

on LAN but<br />

proposed local<br />

network is on DMZ<br />

IKE Responder:<br />

Tunnel terminates<br />

outside firewall but<br />

proposed local<br />

network is not NAT<br />

public address<br />

IKE Responder:<br />

Tunnel terminates<br />

outside firewall but<br />

proposed remote<br />

network is not NAT<br />

public address<br />

VPN IKE User Activity Warning 251 537 Standard<br />

VPN IKE User Activity Information 356 --- Standard<br />

VPN IKE User Activity Information 355 --- Standard<br />

VPN IKE User Activity Information 352 --- Standard<br />

VPN IKE User Activity Warning 255 541 Standard<br />

Note String<br />

VPN IKE User Activity Warning 256 542 Standard<br />

Note String<br />

VPN IKE User Activity Warning 257 543 Standard<br />

Note String<br />

VPN IKE User Activity Warning 254 540 Standard<br />

Note String<br />

VPN IKE User Activity Warning 345 548 Standard<br />

Note String<br />

SONICOS LOG EVENT REFERENCE GUIDE 29


IKE SA lifetime<br />

expired.<br />

VPN IKE User Activity Information 350 --- Standard<br />

Illegal IPSec SPI VPN IPSec User Activity Information 65 --- Standard<br />

Destination<br />

Imported VPN SA<br />

is invalid - disabled<br />

Inbound<br />

connection from<br />

RBL-listed SMTP<br />

server dropped<br />

Incoming call<br />

received for<br />

Remotely<br />

Triggered Dial-out<br />

session<br />

Incompatible IPSec<br />

Security<br />

Association<br />

Incorrect<br />

authentication<br />

received for<br />

Remotely<br />

Triggered Dial-out<br />

Firewall <strong>Event</strong> Maintenance Warning 348 --- Standard<br />

Note String<br />

RBL --- Notice 798 --- Standard<br />

Authentication User Activity Information 817 --- Simple<br />

VPN IPSec User Activity Information 69 --- Standard<br />

Destination<br />

Authentication User Activity Information 819 --- Simple<br />

Ini Killer attack<br />

dropped<br />

Intrusion<br />

Detection<br />

Attack Alert 80 519 Standard<br />

Interface %s Link<br />

Is Down<br />

Interface %s Link<br />

Is Up<br />

Interface IP<br />

Assignment :<br />

Binding and<br />

initializing %s<br />

Interface IP<br />

Assignment<br />

changed: Shutting<br />

down %s<br />

Interface statistics<br />

report<br />

Firewall <strong>Event</strong> System Error Error 566 647 Standard<br />

String<br />

Service<br />

Firewall <strong>Event</strong> System Error Warning 565 646 Standard<br />

String<br />

Service<br />

Firewall <strong>Event</strong> Maintenance Information 568 --- Standard<br />

String<br />

Service<br />

Firewall <strong>Event</strong> Maintenance Information 567 --- Standard<br />

String<br />

Service<br />

GMS --- Information 805 --- Simple<br />

Interface<br />

Statistics<br />

30 SONICOS LOG EVENT REFERENCE GUIDE


Invalid TCP flags<br />

on an incomplete<br />

connection<br />

Network<br />

Access<br />

--- Notice 760 --- Standard<br />

Note String<br />

Invalid VLAN<br />

packet dropped<br />

Network --- Alert 836 --- Standard<br />

Note String<br />

IP Header<br />

checksum error<br />

Network<br />

Access<br />

TCP | UDP Notice 883 --- Standard<br />

IP spoof detected<br />

on packet to<br />

Central Gateway,<br />

packet dropped<br />

DHCP Relay Attack Error 229 533 Standard<br />

Note ENET<br />

IP spoof dropped<br />

Intrusion<br />

Detection<br />

Attack Alert 23 502 Standard<br />

Note ENET<br />

IP type %s packet<br />

dropped<br />

Network<br />

Access<br />

LAN UDP |<br />

LAN TCP<br />

Notice 590 --- Standard<br />

Message<br />

String<br />

IPS Detection<br />

Alert: %s<br />

IPS Detection<br />

Alert: %s<br />

IPS Prevention<br />

Alert: %s<br />

IPS Prevention<br />

Alert: %s<br />

Intrusion<br />

Detection<br />

Intrusion<br />

Detection<br />

Intrusion<br />

Detection<br />

Intrusion<br />

Detection<br />

Attack Alert 608 569 Standard<br />

IDP<br />

Message<br />

String<br />

Attack Alert 789 573 Standard<br />

Message<br />

String<br />

Attack Alert 609 570 Standard<br />

IDP<br />

Message<br />

String<br />

Attack Alert 790 574 Standard<br />

Message<br />

String<br />

IPSec (AH) packet<br />

dropped<br />

VPN IPSec TCP | UDP |<br />

ICMP<br />

Notice 534 --- Standard<br />

Note String<br />

IPSec (AH) packet<br />

dropped; waiting<br />

for pending IPSec<br />

connection<br />

VPN IPSec Debug Debug 536 --- Standard<br />

IPSec (ESP) packet<br />

dropped<br />

VPN IPSec TCP | UDP |<br />

ICMP<br />

Notice 533 --- Standard<br />

Note String<br />

IPSec (ESP) packet<br />

dropped; waiting<br />

for pending IPSec<br />

connection<br />

VPN IPSec Debug Debug 535 --- Standard<br />

SONICOS LOG EVENT REFERENCE GUIDE 31


IPSec<br />

Authentication<br />

Failed<br />

VPN IPSec Attack Error 67 508 Standard<br />

Destination<br />

IPSec connection<br />

interrupt<br />

Network<br />

Access<br />

Debug Debug 43 --- Standard<br />

IPSec Decryption<br />

Failed<br />

VPN IPSec Attack Error 68 509 Standard<br />

Destination<br />

IPSec packet<br />

dropped<br />

Network<br />

Access<br />

TCP | UDP |<br />

ICMP<br />

Notice 40 --- Standard<br />

IPSec packet<br />

dropped; waiting<br />

for pending IPSec<br />

connection<br />

Network<br />

Access<br />

Debug Debug 42 --- Standard<br />

IPSec packet from<br />

an illegal host<br />

IPSec packet from<br />

or to an illegal host<br />

IPSEC Replay<br />

Detected<br />

VPN IPSec Maintenance Information 247 --- Standard<br />

Destination<br />

VPN IPSec Attack Error 70 510 Standard<br />

Destination<br />

VPN IPSec Attack Alert 180 531 Standard<br />

Note String<br />

IPSecTunnel<br />

status changed<br />

VPN<br />

VPN Tunnel<br />

Status<br />

Information 427 801 Simple<br />

ISDN Driver<br />

Firmware<br />

successfully<br />

updated<br />

Firewall <strong>Event</strong> Maintenance Information 493 --- Simple<br />

Issuer match failed VPN PKI User Activity Alert 278 --- Simple<br />

Destination<br />

Java access<br />

denied<br />

Network<br />

Access<br />

Blocked Code Notice 19 --- Standard<br />

Note<br />

Blocked<br />

L2TP enabled but<br />

not ready<br />

L2TP Max<br />

Retransmission<br />

Exceeded<br />

L2TP PPP<br />

Authentication<br />

Failed<br />

Unused Maintenance Information 500 --- Simple<br />

L2TP Client Maintenance Information 203 --- Simple<br />

L2TP Client Maintenance Information 212 --- Simple<br />

L2TP PPP Down L2TP Client Maintenance Information 211 --- Simple<br />

L2TP PPP link<br />

down<br />

L2TP Client Maintenance Information 217 --- Simple<br />

32 SONICOS LOG EVENT REFERENCE GUIDE


L2TP PPP<br />

Negotiation Started<br />

L2TP PPP Session<br />

Up<br />

L2TP Server :<br />

Deleting the L2TP<br />

active Session<br />

L2TP Server :<br />

Deleting the Tunnel<br />

L2TP Server : L2TP<br />

Session Established.<br />

L2TP Server : L2TP<br />

Tunnel Established.<br />

L2TP Server :<br />

Retransmission<br />

Timeout, Deleting<br />

the Tunnel<br />

L2TP Server : User<br />

Name<br />

authentication<br />

Failure locally.<br />

L2TP Server:<br />

Local<br />

Authentication<br />

Failure<br />

L2TP Server:<br />

Local<br />

Authentication<br />

Success.<br />

L2TP Server:<br />

Radius<br />

Authentication<br />

Success<br />

L2TP Server:<br />

Radius reports<br />

Authentication<br />

Failure<br />

L2TP Server:<br />

Radius server not<br />

assigned IP<br />

address<br />

L2TP Client Maintenance Information 208 --- Simple<br />

L2TP Client Maintenance Information 210 --- Simple<br />

L2TP Server Maintenance Information 337 --- Standard<br />

Destination<br />

L2TP Server Maintenance Information 336 --- Standard<br />

Destination<br />

L2TP Server Maintenance Information 309 --- Standard<br />

Destination<br />

L2TP Server Maintenance Information 308 --- Standard<br />

Destination<br />

L2TP Server Maintenance Information 338 --- Standard<br />

Destination<br />

L2TP Server Maintenance Information 344 --- Standard<br />

Destination<br />

L2TP Server Maintenance Information 312 --- Standard<br />

Destination<br />

L2TP Server Maintenance Information 318 --- Standard<br />

Destination<br />

L2TP Server Maintenance Information 319 --- Standard<br />

Destination<br />

L2TP Server Maintenance Information 311 --- Standard<br />

Destination<br />

L2TP Server Maintenance Information 313 --- Standard<br />

Destination<br />

SONICOS LOG EVENT REFERENCE GUIDE 33


L2TP Server: Call<br />

Disconnect from<br />

Remote.<br />

L2TP Server:<br />

Tunnel Disconnect<br />

from Remote.<br />

L2TP Session<br />

Disconnect from<br />

Remote<br />

L2TP Session<br />

Established<br />

L2TP Session<br />

Negotiation Started<br />

L2TP Tunnel<br />

Disconnect from<br />

Remote<br />

L2TP Tunnel<br />

Established<br />

L2TP Tunnel<br />

Negotiation Started<br />

LAN Subnet<br />

configurations<br />

were not upgraded.<br />

L2TP Server Maintenance Information 334 --- Standard<br />

Destination<br />

L2TP Server Maintenance Information 335 --- Standard<br />

Destination<br />

L2TP Client Maintenance Information 207 --- Simple<br />

L2TP Client Maintenance Information 206 --- Simple<br />

L2TP Client Maintenance Information 202 --- Simple<br />

L2TP Client Maintenance Information 205 --- Simple<br />

L2TP Client Maintenance Information 204 --- Simple<br />

L2TP Client Maintenance Information 201 --- Simple<br />

Firewall <strong>Event</strong> Maintenance Information 741 --- Simple<br />

Land attack<br />

dropped<br />

Intrusion<br />

Detection<br />

Attack Alert 27 505 Standard<br />

License exceeded:<br />

Connection<br />

dropped because<br />

too many IP<br />

addresses are in<br />

use on your LAN<br />

Firewall <strong>Event</strong> System Error Error 58 608 Standard<br />

License of HA pair<br />

doesn't match<br />

High<br />

Availability<br />

System Error Error 670 664 Simple<br />

Local user login<br />

allowed<br />

Local user login<br />

denied due to bad<br />

credentials<br />

Locked-out user<br />

logins<br />

allowed - lockout<br />

period expired<br />

Authentication User Activity Information 31 --- Standard<br />

String<br />

Service<br />

Authentication User Activity Information 32 --- Standard<br />

String<br />

Service<br />

Authentication User Activity Information 438 --- Standard<br />

Note String<br />

34 SONICOS LOG EVENT REFERENCE GUIDE


Locked-out user<br />

logins allowed by<br />

administrator<br />

Authentication User Activity Information 439 --- Standard<br />

Note String<br />

<strong>Log</strong> Cleared<br />

Firewall<br />

<strong>Log</strong>ging<br />

Maintenance Information 5 --- Simple<br />

<strong>Log</strong> Debug Firewall <strong>Event</strong> Debug Error 142 --- Simple<br />

String<br />

<strong>Log</strong> successfully<br />

sent via email<br />

Firewall<br />

<strong>Log</strong>ging<br />

Maintenance Information 6 --- Simple<br />

<strong>Log</strong>in screen timed<br />

out<br />

MAC address<br />

collides with Static<br />

ARP Entry with<br />

Bound MAC<br />

address; packet<br />

dropped<br />

Authentication User Activity Information 34 --- Standard<br />

String<br />

Service<br />

Network --- Notice 814 --- Standard<br />

Note ENET<br />

Machine %s<br />

removed from SYN<br />

flood blacklist<br />

Malformed or<br />

unhandled IP<br />

packet dropped<br />

Maximum events<br />

per second<br />

threshold<br />

exceeded<br />

Intrusion<br />

Detection<br />

Network<br />

Access<br />

Firewall<br />

<strong>Log</strong>ging<br />

--- Alert 865 --- Standard<br />

String<br />

Service<br />

Attack Alert 522 554 Standard<br />

Destination<br />

System Error Critical 654 --- Simple<br />

Maximum<br />

sequential failed<br />

dial attempts (10)<br />

to a single dial-up<br />

number: %s<br />

PPP Dial-up Attack Error 591 566 Standard<br />

Message<br />

String<br />

Maximum syslog<br />

data per second<br />

threshold<br />

exceeded<br />

Firewall<br />

<strong>Log</strong>ging<br />

System Error Critical 655 --- Simple<br />

Multicast<br />

application %s not<br />

supported<br />

Multicast packet<br />

dropped, Invalid<br />

src IP received on<br />

interface : %s<br />

Multicast --- Information 696 --- Standard<br />

Message<br />

String<br />

Multicast --- Alert 685 --- Standard<br />

Message<br />

String<br />

SONICOS LOG EVENT REFERENCE GUIDE 35


Multicast packet<br />

dropped, wrong<br />

MAC address<br />

receieved on<br />

interface : %s<br />

Multicast TCP<br />

packet dropped<br />

Multicast UDP<br />

packet dropped, no<br />

state entry<br />

Multicast UDP<br />

packet dropped,<br />

RTCP stateful<br />

failed<br />

Multicast UDP<br />

packet dropped,<br />

RTP stateful failed<br />

NAT device may<br />

not support IPSec<br />

AH passthrough<br />

NAT Discovery :<br />

No NAT/NAPT<br />

device detected<br />

between IPSec<br />

Security gateways<br />

NAT Discovery :<br />

Local IPSec<br />

Security Gateway<br />

behind a NAT/<br />

NAPT Device<br />

NAT Discovery :<br />

Peer IPSec<br />

Security Gateway<br />

behind a NAT/<br />

NAPT Device<br />

NAT Discovery :<br />

Peer IPSec<br />

Security Gateway<br />

doesn't support<br />

VPN NAT Traversal<br />

NAT translated<br />

packet exceeds<br />

size limit, packet<br />

dropped<br />

Multicast --- Alert 684 --- Standard<br />

Message<br />

String<br />

Multicast --- Notice 691 --- Standard<br />

Multicast --- Notice 690 --- Standard<br />

Multicast --- Warning 695 --- Standard<br />

Multicast --- Warning 694 --- Standard<br />

VPN IPSec Maintenance Information 266 --- Simple<br />

VPN IKE User Activity Information 241 --- Standard<br />

VPN IKE User Activity Information 240 --- Standard<br />

VPN IKE User Activity Information 239 --- Standard<br />

VPN IKE User Activity Information 242 --- Standard<br />

Network Debug Debug 339 --- Standard<br />

36 SONICOS LOG EVENT REFERENCE GUIDE


Net Spy attack<br />

dropped<br />

Intrusion<br />

Detection<br />

Attack Alert 74 513 Standard<br />

NetBIOS settings<br />

were not upgraded.<br />

Use Network>IP<br />

Helper to<br />

configure NetBIOS<br />

support<br />

Firewall <strong>Event</strong> Maintenance Information 740 --- Simple<br />

NetBus attack<br />

dropped<br />

Intrusion<br />

Detection<br />

Attack Alert 72 511 Standard<br />

Network for<br />

interface %s<br />

overlaps with<br />

another interface.<br />

Network Modem<br />

Mode Disabled:<br />

re-enabling NAT<br />

Network Modem<br />

Mode Enabled:<br />

turning off NAT<br />

Firewall <strong>Event</strong> Maintenance Information 569 --- Standard<br />

String<br />

Service<br />

PPP Dial-up Maintenance Information 531 --- Simple<br />

PPP Dial-up Maintenance Information 530 --- Simple<br />

New URL List<br />

loaded<br />

Newsgroup access<br />

allowed<br />

Newsgroup access<br />

denied<br />

Security<br />

Services<br />

Network<br />

Access<br />

Network<br />

Access<br />

Maintenance Information 8 --- Simple<br />

Blocked Sites Notice 17 704 Standard<br />

Note<br />

Blocked<br />

Blocked Sites Notice 15 702 Standard<br />

Note<br />

Blocked<br />

No Certificate for VPN PKI User Activity Alert 280 --- Simple<br />

Destination<br />

No new URL List<br />

available<br />

Security<br />

Services<br />

Maintenance Information 9 --- Simple<br />

No response from<br />

ISP Disconnecting<br />

PPPoE.<br />

No response from<br />

PPTP server to call<br />

requests<br />

No response from<br />

PPTP server to<br />

control connection<br />

requests<br />

PPPoE Maintenance Information 169 --- Simple<br />

PPTP Maintenance Information 431 --- Simple<br />

PPTP Maintenance Information 430 --- Simple<br />

SONICOS LOG EVENT REFERENCE GUIDE 37


No response from<br />

server to Echo<br />

Requests,<br />

disconnecting<br />

PPTP Tunnel<br />

No valid DNS<br />

server specified for<br />

RBL lookups<br />

Not all<br />

configurations may<br />

have been<br />

completely<br />

upgraded<br />

Not enough<br />

memory to hold the<br />

CRL<br />

Obtained Relay IP<br />

Table from Remote<br />

Gateway<br />

OCSP Failed to<br />

Resolve Domain<br />

Name.<br />

OCSP Internal<br />

error handling<br />

received response.<br />

OCSP received<br />

response error.<br />

OCSP received<br />

response.<br />

OCSP Resolved<br />

Domain Name.<br />

OCSP send<br />

request message<br />

failed.<br />

OCSP sending<br />

request.<br />

Outbound<br />

connection to<br />

RBL-listed SMTP<br />

server dropped<br />

PPTP Maintenance Information 429 --- Simple<br />

RBL --- Error 800 --- Simple<br />

Firewall <strong>Event</strong> Maintenance Information 612 --- Simple<br />

VPN PKI User Activity Warning 272 --- Simple<br />

Destination<br />

DHCP Relay Maintenance Information 233 --- Standard<br />

VPN PKI User Activity Error 853 --- Standard<br />

Note String<br />

VPN PKI User Activity Error 854 --- Standard<br />

Note String<br />

VPN PKI User Activity Error 851 --- Standard<br />

Note String<br />

VPN PKI User Activity Information 850 --- Standard<br />

Note String<br />

VPN PKI User Activity Information 852 --- Standard<br />

Note String<br />

VPN PKI User Activity Error 849 --- Standard<br />

Note String<br />

VPN PKI User Activity Information 848 --- Standard<br />

Note String<br />

RBL --- Notice 797 --- Standard<br />

Out-of-order<br />

command packet<br />

dropped<br />

Network<br />

Access<br />

Debug Debug 48 --- Standard<br />

38 SONICOS LOG EVENT REFERENCE GUIDE


Packet dropped by<br />

wlan guest check<br />

Packet dropped by<br />

wlan vpn traversal<br />

check<br />

Wireless TCP | UDP |<br />

ICMP<br />

Wireless TCP | UDP |<br />

ICMP<br />

Warning 488 --- Standard<br />

Destination<br />

Warning 495 --- Standard<br />

Destination<br />

Packet dropped.<br />

No firewall rule<br />

associated with<br />

VPN policy.<br />

VPN System Error Alert 739 --- Standard<br />

Note String<br />

Ping of death<br />

dropped<br />

Intrusion<br />

Detection<br />

Attack Alert 22 501 Standard<br />

PKI Failure: CA<br />

certificates store<br />

exceeded. Cannot<br />

verify this Local<br />

Certificate<br />

PKI Failure: Cannot<br />

alloc memory<br />

PKI Failure:<br />

Certificate's ID<br />

does not match<br />

this SonicWall<br />

PKI Failure:<br />

Duplicate local<br />

certificate<br />

PKI Failure:<br />

Duplicate local<br />

certificate name<br />

PKI Failure: Import<br />

failed<br />

PKI Failure:<br />

Improper file<br />

format. Please<br />

select PKCS#12<br />

(*.p12) file<br />

PKI Failure:<br />

Incorrect admin<br />

password<br />

PKI Failure:<br />

Internal error<br />

PKI Failure:<br />

Loaded but could<br />

not verify<br />

certificate<br />

VPN PKI Maintenance Error 453 --- Simple<br />

VPN PKI Maintenance Error 449 --- Simple<br />

VPN PKI Maintenance Error 455 --- Simple<br />

VPN PKI Maintenance Error 458 --- Simple<br />

VPN PKI Maintenance Error 457 --- Simple<br />

VPN PKI Maintenance Error 451 --- Simple<br />

VPN PKI Maintenance Error 454 --- Simple<br />

VPN PKI Maintenance Error 452 --- Simple<br />

VPN PKI Maintenance Error 460 --- Simple<br />

VPN PKI Maintenance Error 469 --- Simple<br />

SONICOS LOG EVENT REFERENCE GUIDE 39


PKI Failure:<br />

Loaded the<br />

certificate but<br />

could not verify it's<br />

chain<br />

PKI Failure: No CA<br />

certificates yet<br />

loaded<br />

PKI Failure:<br />

Output buffer too<br />

small<br />

PKI Failure:<br />

public-private key<br />

mismatch<br />

PKI Failure:<br />

Reached the limit<br />

for local certs, cant<br />

load any more<br />

PKI Failure:<br />

Temporary memory<br />

shortage, try again<br />

PKI Failure: The<br />

certificate chain<br />

has no root<br />

PKI Failure: The<br />

certificate chain is<br />

circular<br />

PKI Failure: The<br />

certificate chain is<br />

incomplete<br />

PKI Failure: The<br />

certificate or a<br />

certificate in the<br />

chain has a bad<br />

signature<br />

PKI Failure: The<br />

certificate or a<br />

certificate in the<br />

chain has a validity<br />

period in the future<br />

PKI Failure: The<br />

certificate or a<br />

certificate in the<br />

chain has expired<br />

VPN PKI Maintenance Error 470 --- Simple<br />

VPN PKI Maintenance Error 459 --- Simple<br />

VPN PKI Maintenance Error 448 --- Simple<br />

VPN PKI Maintenance Error 456 --- Simple<br />

VPN PKI Maintenance Error 450 --- Simple<br />

VPN PKI Maintenance Error 461 --- Simple<br />

VPN PKI Maintenance Error 464 --- Simple<br />

VPN PKI Maintenance Error 462 --- Simple<br />

VPN PKI Maintenance Error 463 --- Simple<br />

VPN PKI Maintenance Error 468 --- Simple<br />

VPN PKI Maintenance Error 466 --- Simple<br />

VPN PKI Maintenance Error 465 --- Simple<br />

40 SONICOS LOG EVENT REFERENCE GUIDE


PKI Failure: The<br />

certificate or a<br />

certificate in the<br />

chain is corrupt<br />

Please connect<br />

interface %s to<br />

another network to<br />

function properly<br />

Please manually<br />

check all system<br />

configurations for<br />

correctness of<br />

Upgrade<br />

VPN PKI Maintenance Error 467 --- Simple<br />

Firewall <strong>Event</strong> Maintenance Information 570 --- Standard<br />

String<br />

Service<br />

Firewall <strong>Event</strong> Maintenance Information 613 --- Simple<br />

Port configured to<br />

receive IPSEC<br />

ONLY. Drop packet<br />

received in the<br />

clear.<br />

Network<br />

Access<br />

TCP | UDP |<br />

ICMP<br />

Warning 347 --- Standard<br />

Destination<br />

Possible port scan<br />

dropped<br />

Possible SYN flood<br />

attack detected<br />

Possible SYN flood<br />

detected on WAN<br />

IF %s - switching to<br />

connection-proxy<br />

mode<br />

Possible SYN<br />

Flood on IF %s<br />

Possible SYN<br />

Flood on IF %s<br />

continues<br />

Possible SYN<br />

Flood on IF %s has<br />

ceased<br />

Intrusion<br />

Detection<br />

Intrusion<br />

Detection<br />

Intrusion<br />

Detection<br />

Intrusion<br />

Detection<br />

Intrusion<br />

Detection<br />

Intrusion<br />

Detection<br />

Attack Alert 82 521 Standard<br />

Note String<br />

Attack Warning 25 503 Standard<br />

--- Alert 859 --- Standard<br />

String<br />

Service<br />

--- Alert 860 --- Standard<br />

String<br />

Service<br />

--- Warning 866 --- Standard<br />

String<br />

Service<br />

--- Alert 867 --- Standard<br />

String<br />

Service<br />

PPP Dial-Up:<br />

Connect request<br />

canceled<br />

PPP Dial-Up:<br />

Connected at %s<br />

bps - starting PPP<br />

PPP Dial-up User Activity Information 306 --- Simple<br />

PPP Dial-up User Activity Information 286 --- Standard<br />

String<br />

Service<br />

SONICOS LOG EVENT REFERENCE GUIDE 41


PPP Dial-Up:<br />

Connection<br />

disconnected as<br />

scheduled.<br />

PPP Dial-Up:<br />

Dial initiated by %s<br />

PPP Dial-Up:<br />

Dialed number did<br />

not answer<br />

PPP Dial-Up:<br />

Dialed number is<br />

busy<br />

PPP Dial-Up:<br />

Dialing not allowed<br />

by schedule. %s<br />

PPP Dial-Up:<br />

Dialing: %s<br />

PPP Dial-Up: Idle<br />

time limit exceeded<br />

- disconnecting<br />

PPP Dial-Up:<br />

Initialization : %s<br />

PPP Dial-Up: Link<br />

carrier lost<br />

PPP Dial-Up:<br />

Manual<br />

intervention<br />

needed. Check<br />

Primary Profile or<br />

Profile details<br />

PPP Dial-Up:<br />

Maximum<br />

connection time<br />

exceeded -<br />

disconnecting<br />

PPP Dial-Up: No<br />

dialtone detected -<br />

check phone-line<br />

connection<br />

PPP Dial-up --- Information 666 --- Standard<br />

PPP Dial-up Maintenance Information 324 --- Standard<br />

Message<br />

String<br />

PPP Dial-up User Activity Information 285 --- Simple<br />

PPP Dial-up User Activity Information 284 --- Simple<br />

PPP Dial-up --- Information 665 --- Standard<br />

Message<br />

String<br />

PPP Dial-up User Activity Information 281 --- Standard<br />

String<br />

Service<br />

PPP Dial-up User Activity Information 297 --- Simple<br />

PPP Dial-up User Activity Information 303 --- Standard<br />

String<br />

Service<br />

PPP Dial-up User Activity Information 288 --- Simple<br />

PPP Dial-up User Activity Information 321 --- Simple<br />

PPP Dial-up User Activity Information 327 --- Simple<br />

PPP Dial-up User Activity Information 282 --- Simple<br />

42 SONICOS LOG EVENT REFERENCE GUIDE


PPP Dial-Up: No<br />

link carrier<br />

detected - check<br />

phone number<br />

PPP Dial-Up: No<br />

peer IP address<br />

from Dial-Up ISP,<br />

local and remote<br />

IPs will be the<br />

same<br />

PPP Dial-Up:<br />

PPP link down<br />

PPP Dial-Up:<br />

PPP link<br />

established<br />

PPP Dial-Up:<br />

Previous session<br />

was connected for<br />

%s<br />

PPP Dial-Up:<br />

Received new IP<br />

address<br />

PPP Dial-Up:<br />

Shutting down link<br />

PPP Dial-Up: The<br />

profile in use<br />

disabled VPN<br />

networking.<br />

PPP Dial-Up:<br />

Trying to failover<br />

but Alternate<br />

Profile is manual<br />

PPP Dial-Up:<br />

Trying to failover<br />

but Primary Profile<br />

is manual<br />

PPP Dial-Up:<br />

Unknown dialing<br />

failure<br />

PPP Dial-Up:<br />

User requested<br />

connect<br />

PPP Dial-up User Activity Information 283 --- Simple<br />

PPP Dial-up Maintenance Information 481 --- Simple<br />

PPP Dial-up User Activity Information 301 --- Simple<br />

PPP Dial-up User Activity Information 300 --- Simple<br />

PPP Dial-up User Activity Information 542 --- Standard<br />

String<br />

Service<br />

PPP Dial-up User Activity Information 299 --- Standard<br />

PPP Dial-up User Activity Information 302 --- Simple<br />

PPP Dial-up Maintenance Information 330 --- Simple<br />

WAN Failover User Activity Information 434 --- Simple<br />

PPP Dial-up User Activity Information 322 --- Simple<br />

PPP Dial-up User Activity Information 287 --- Simple<br />

PPP Dial-up User Activity Information 305 --- Simple<br />

SONICOS LOG EVENT REFERENCE GUIDE 43


PPP Dial-Up:<br />

User requested<br />

disconnect<br />

PPP Dial-Up:<br />

VPN networking<br />

restored.<br />

PPP:<br />

Authentication<br />

successful<br />

PPP: CHAP<br />

authentication<br />

failed - check<br />

username /<br />

password<br />

PPP: MS-CHAP<br />

authentication<br />

failed - check<br />

username /<br />

password<br />

PPP: PAP<br />

Authentication<br />

failed - check<br />

username /<br />

password<br />

PPP: Starting<br />

CHAP<br />

authentication<br />

PPP: Starting<br />

MS-CHAP<br />

authentication<br />

PPP: Starting PAP<br />

authentication<br />

PPP Dial-up User Activity Information 304 --- Simple<br />

PPP Dial-up Maintenance Information 331 --- Simple<br />

PPP User Activity Information 289 --- Simple<br />

PPP User Activity Information 291 --- Simple<br />

PPP User Activity Information 292 --- Simple<br />

PPP User Activity Information 290 --- Simple<br />

PPP User Activity Information 294 --- Simple<br />

PPP User Activity Information 293 --- Simple<br />

PPP User Activity Information 295 --- Simple<br />

PPPoE terminated PPPoE Maintenance Information 130 --- Simple<br />

PPPoE discovery<br />

process complete<br />

PPPoE enabled but<br />

not ready<br />

PPPoE LCP Link<br />

Down<br />

PPPoE LCP Link<br />

Up<br />

PPPoE Network<br />

Connected<br />

PPPoE Maintenance Information 133 --- Simple<br />

PPPoE Maintenance Information 499 --- Simple<br />

PPPoE Maintenance Information 129 --- Simple<br />

PPPoE Maintenance Information 128 --- Simple<br />

PPPoE Maintenance Information 131 --- Simple<br />

44 SONICOS LOG EVENT REFERENCE GUIDE


PPPoE Network<br />

Disconnected<br />

PPPoE starting<br />

CHAP<br />

Authentication<br />

PPTP enabled but<br />

not ready<br />

PPTP Connect<br />

Initiated by the<br />

User<br />

PPTP Control<br />

Connection<br />

Established<br />

PPTP Control<br />

Connection<br />

Negotiation Started<br />

PPTP decode<br />

failure<br />

PPTP Disconnect<br />

Initiated by the<br />

User<br />

PPTP PAP<br />

Authentication<br />

success.<br />

PPPoE Maintenance Information 132 --- Simple<br />

PPPoE Maintenance Information 134 --- Simple<br />

PPTP Maintenance Information 501 --- Simple<br />

PPTP Maintenance Information 390 --- Standard<br />

Destination<br />

PPTP Maintenance Information 378 --- Simple<br />

PPTP Maintenance Information 375 --- Simple<br />

PPTP Debug Debug 596 --- Standard<br />

PPTP Maintenance Information 388 --- Standard<br />

Destination<br />

PPTP Maintenance Information 396 --- Simple<br />

PPTP PPP Down PPTP Maintenance Information 385 --- Simple<br />

PPTP PPP Link<br />

down<br />

PPTP PPP Link<br />

Finished<br />

PPTP Maintenance Information 399 --- Simple<br />

PPTP Maintenance Information 400 --- Simple<br />

PPTP PPP Link Up PPTP Maintenance Information 398 --- Simple<br />

PPTP PPP<br />

Negotiation Started<br />

PPTP PPP Session<br />

Up<br />

PPTP Server is not<br />

responding, check<br />

if the server is UP<br />

and running.<br />

PPTP server<br />

rejected control<br />

connection<br />

PPTP Maintenance Information 382 --- Simple<br />

PPTP Maintenance Information 384 --- Simple<br />

PPTP Maintenance Information 444 --- Simple<br />

PPTP Maintenance Information 432 --- Simple<br />

SONICOS LOG EVENT REFERENCE GUIDE 45


PPTP server<br />

rejected the call<br />

request<br />

PPTP Session<br />

Disconnect from<br />

Remote<br />

PPTP Session<br />

Established<br />

PPTP Session<br />

Negotiation Started<br />

PPTP starting<br />

CHAP<br />

Authentication<br />

PPTP starting PAP<br />

Authentication<br />

PPTP Tunnel<br />

Disconnect from<br />

Remote<br />

PPTP Maintenance Information 433 --- Simple<br />

PPTP Maintenance Information 381 --- Simple<br />

PPTP Maintenance Information 380 --- Simple<br />

PPTP Maintenance Information 376 --- Simple<br />

PPTP Maintenance Information 392 --- Simple<br />

PPTP Maintenance Information 393 --- Simple<br />

PPTP Maintenance Information 379 --- Simple<br />

Primary firewall<br />

has transitioned to<br />

Active<br />

Primary firewall<br />

has transitioned to<br />

Idle<br />

Primary firewall<br />

preempting<br />

Backup<br />

Primary missed<br />

heartbeats from<br />

Backup<br />

Primary received<br />

error signal from<br />

Backup<br />

Primary received<br />

reboot signal from<br />

Backup<br />

Priority attack<br />

dropped<br />

Probable port scan<br />

dropped<br />

Probable TCP FIN<br />

scan dropped<br />

High Availability<br />

High Availability<br />

High<br />

Availability<br />

High<br />

Availability<br />

High<br />

Availability<br />

High<br />

Availability<br />

Intrusion<br />

Detection<br />

Intrusion<br />

Detection<br />

Intrusion<br />

Detection<br />

Maintenance Information 144 --- Simple<br />

System Error Error 146 614 Simple<br />

System Error Error 153 620 Simple<br />

System Error Error 148 615 Simple<br />

System Error Error 150 617 Simple<br />

System Error Error 671 665 Simple<br />

Attack Alert 79 518 Standard<br />

Attack Alert 83 522 Standard<br />

Note String<br />

Attack Alert 177 528 Standard<br />

46 SONICOS LOG EVENT REFERENCE GUIDE


Probable TCP<br />

NULL scan<br />

dropped<br />

Probable TCP<br />

XMAS scan<br />

dropped<br />

Intrusion<br />

Detection<br />

Intrusion<br />

Detection<br />

Attack Alert 179 530 Standard<br />

Attack Alert 178 529 Standard<br />

Probing failure on<br />

%s<br />

Probing succeeded<br />

on %s<br />

WAN Failover System Error Alert 326 637 Standard<br />

Message<br />

String<br />

WAN Failover System Error Alert 436 638 Standard<br />

Message<br />

String<br />

Problem loading<br />

the URL List;<br />

Appliance not<br />

registered.<br />

Problem loading<br />

the URL List;<br />

check Filter<br />

settings<br />

Problem loading<br />

the URL List;<br />

check your DNS<br />

server<br />

Problem loading<br />

the URL List; Flash<br />

write failure.<br />

Problem loading<br />

the URL List;<br />

Retrying later.<br />

Problem loading<br />

the URL List;<br />

Subscription<br />

expired.<br />

Problem loading<br />

the URL List; Try<br />

loading it again.<br />

Problem sending<br />

log email; check<br />

log settings.<br />

Real time clock<br />

battery failure.<br />

Time values may<br />

be incorrect.<br />

Security<br />

Services<br />

Security<br />

Services<br />

Security<br />

Services<br />

Security<br />

Services<br />

Security<br />

Services<br />

Security<br />

Services<br />

Security<br />

Services<br />

Firewall<br />

<strong>Log</strong>ging<br />

Firewall<br />

Hardware<br />

System Error Error 183 623 Simple<br />

System Error Error 10 602 Standard<br />

Note Code<br />

System Error Error 11 603 Simple<br />

System Error Error 187 627 Simple<br />

System Error Error 186 626 Standard<br />

System Error Error 184 624 Standard<br />

System Error Error 185 625 Simple<br />

System Error Warning 12 604 Simple<br />

System Error Warning 539 644 Simple<br />

SONICOS LOG EVENT REFERENCE GUIDE 47


Received a path<br />

MTU icmp<br />

message from<br />

router/gateway<br />

Received a path<br />

MTU icmp<br />

message from<br />

router/gateway<br />

Network User Activity Information 182 --- Standard<br />

Note SPI<br />

Network User Activity Information 188 --- Standard<br />

Note MTU<br />

Received AV Alert:<br />

%s<br />

Received AV Alert:<br />

Your <strong>SonicWALL</strong><br />

Network Anti-Virus<br />

subscription has<br />

expired. %s<br />

Received AV Alert:<br />

Your <strong>SonicWALL</strong><br />

Network Anti-Virus<br />

subscription will<br />

expire in 7 days.<br />

%s<br />

Received CFS<br />

Alert: Your<br />

<strong>SonicWALL</strong><br />

Content Filtering<br />

subscription has<br />

expired.<br />

Received CFS<br />

Alert: Your<br />

<strong>SonicWALL</strong><br />

Content Filtering<br />

subscription will<br />

expire in 7 days.<br />

Security<br />

Services<br />

Security<br />

Services<br />

Security<br />

Services<br />

Security<br />

Services<br />

Security<br />

Services<br />

Maintenance Warning 125 524 Standard<br />

String<br />

Service<br />

Maintenance Warning 159 526 Standard<br />

String<br />

Service<br />

Maintenance Warning 482 552 Standard<br />

String<br />

Service<br />

Maintenance Warning 490 563 Simple<br />

Maintenance Warning 489 562 Simple<br />

Received DHCP<br />

offer packet has<br />

errors<br />

DHCP Client Maintenance Information 588 --- Standard<br />

Destination<br />

Received E-Mail<br />

Filter Alert: Your<br />

<strong>SonicWALL</strong> E-Mail<br />

Filtering<br />

subscription has<br />

expired.<br />

Security<br />

Services<br />

Maintenance Warning 492 565 Simple<br />

48 SONICOS LOG EVENT REFERENCE GUIDE


Received E-Mail<br />

Filter Alert: Your<br />

<strong>SonicWALL</strong> E-Mail<br />

Filtering<br />

subscription will<br />

expire in 7 days.<br />

Security<br />

Services<br />

Maintenance Warning 491 564 Simple<br />

Received<br />

fragmented packet<br />

or fragmentation<br />

needed<br />

Received IKE SA<br />

delete request<br />

Network Debug Debug 63 --- Standard<br />

VPN IKE User Activity Information 413 --- Standard<br />

Received IPS Alert:<br />

Your <strong>SonicWALL</strong><br />

Intrusion<br />

Prevention (IDP)<br />

subscription has<br />

expired.<br />

Security<br />

Services<br />

Maintenance Warning 614 571 Simple<br />

Received IPSEC<br />

SA delete request<br />

Received ISAKMP<br />

packet destined to<br />

port %s<br />

Received LCP<br />

Echo Reply<br />

Received LCP<br />

Echo Request<br />

Received notify:<br />

INVALID_COOKIES<br />

Received notify:<br />

INVALID_ID_INFO<br />

Received notify:<br />

INVALID_PAYLOAD<br />

Received notify:<br />

INVALID_SPI<br />

Received notify:<br />

ISAKMP_AUTH_<br />

FAILED<br />

Received notify:<br />

PAYLOAD_<br />

MALFORMED<br />

VPN IKE User Activity Information 412 --- Standard<br />

Destination<br />

VPN IKE Debug | UDP Information 607 --- Standard<br />

Message<br />

String<br />

PPPoE Maintenance Information 723 --- Simple<br />

PPPoE Maintenance Information 721 --- Simple<br />

VPN IKE User Activity Information 414 --- Standard<br />

Destination<br />

VPN IPSec User Activity Warning 483 --- Standard<br />

VPN IKE User Activity Error 661 --- Standard<br />

VPN IKE User Activity Information 416 --- Standard<br />

Destination<br />

VPN IKE User Activity Warning 409 --- Standard<br />

Destination<br />

VPN IKE User Activity Warning 411 --- Standard<br />

Destination<br />

SONICOS LOG EVENT REFERENCE GUIDE 49


Received notify:<br />

RESPONDER_<br />

LIFETIME<br />

Received packet<br />

retransmission.<br />

Drop duplicate<br />

packet<br />

Received PPPoE<br />

Active Discovery<br />

Offer<br />

Received PPPoE<br />

Active Discovery<br />

Session_<br />

confirmation<br />

Received response<br />

packet for DHCP<br />

request has errors<br />

Received<br />

unencrypted<br />

packet while crypto<br />

active<br />

Regulatory<br />

requirements<br />

prohibit %s from<br />

being re-dialed for<br />

30 minutes<br />

Remotely<br />

Triggered Dial-out<br />

session ended.<br />

Valid WAN bound<br />

data found.<br />

Normal dial-up<br />

sequence will<br />

commence<br />

Remotely<br />

Triggered Dial-out<br />

session started.<br />

Requesting<br />

authentication<br />

Request for Relay<br />

IP Table from<br />

Central Gateway<br />

Requesting CRL<br />

from<br />

VPN IKE User Activity Information 415 --- Standard<br />

Destination<br />

VPN IKE User Activity Warning 406 --- Standard<br />

PPPoE Maintenance Information 593 --- Simple<br />

PPPoE Maintenance Information 594 --- Simple<br />

DHCP Client Maintenance Information 589 --- Standard<br />

Destination<br />

VPN IKE User Activity Warning 605 --- Standard<br />

PPP Dial-up Attack Error 592 567 Standard<br />

Message<br />

String<br />

Authentication User Activity Information 822 --- Simple<br />

Authentication User Activity Information 818 --- Simple<br />

DHCP Relay Maintenance Information 230 --- Standard<br />

VPN PKI User Activity Information 269 --- Simple<br />

Destination<br />

50 SONICOS LOG EVENT REFERENCE GUIDE


Requesting Relay<br />

IP Table from<br />

Remote Gateway<br />

Retransmitting<br />

DHCP DISCOVER<br />

Retransmitting<br />

DHCP REQUEST<br />

(Rebinding)<br />

Retransmitting<br />

DHCP REQUEST<br />

(Rebooting)<br />

Retransmitting<br />

DHCP REQUEST<br />

(Renewing)<br />

Retransmitting<br />

DHCP REQUEST<br />

(Requesting)<br />

Retransmitting<br />

DHCP REQUEST<br />

(Verifying)<br />

RIP disabled on<br />

interface %s<br />

DHCP Relay Maintenance Information 231 --- Standard<br />

DHCP Client Maintenance Information 99 --- Standard<br />

Destination<br />

DHCP Client Maintenance Information 102 --- Standard<br />

Destination<br />

DHCP Client Maintenance Information 103 --- Standard<br />

Destination<br />

DHCP Client Maintenance Information 101 --- Standard<br />

Destination<br />

DHCP Client Maintenance Information 100 --- Standard<br />

Destination<br />

DHCP Client Maintenance Information 104 --- Standard<br />

Destination<br />

RIP Maintenance Information 419 --- Standard<br />

String<br />

Service<br />

Ripper attack<br />

dropped<br />

Intrusion<br />

Detection<br />

Attack Alert 76 515 Standard<br />

RIPv1 enabled on<br />

interface %s<br />

RIPv2<br />

compatibility<br />

(broadcast) mode<br />

enabled on<br />

interface %s<br />

RIPv2 enabled on<br />

interface %s<br />

Router IGMP<br />

General query<br />

received on<br />

interface %s<br />

Router IGMP<br />

Membership query<br />

received on<br />

interface %s<br />

RIP Maintenance Information 420 --- Standard<br />

String<br />

Service<br />

RIP Maintenance Information 422 --- Standard<br />

String<br />

Service<br />

RIP Maintenance Information 421 --- Standard<br />

String<br />

Service<br />

Multicast --- Debug 680 --- Standard<br />

Message<br />

String<br />

Multicast --- Debug 681 --- Standard<br />

Message<br />

String<br />

SONICOS LOG EVENT REFERENCE GUIDE 51


Sending DHCP<br />

DISCOVER.<br />

Sending DHCP<br />

RELEASE.<br />

Sending DHCP<br />

REQUEST<br />

(Rebinding).<br />

Sending DHCP<br />

REQUEST<br />

(Rebooting).<br />

Sending DHCP<br />

REQUEST<br />

(Renewing).<br />

Sending DHCP<br />

REQUEST<br />

(Verifying).<br />

Sending DHCP<br />

REQUEST.<br />

Sending LCP Echo<br />

Reply<br />

Sending LCP Echo<br />

Request<br />

Sending PPPoE<br />

Active Discovery<br />

Request<br />

DHCP Client Maintenance Information 105 --- Standard<br />

Destination<br />

DHCP Client Maintenance Information 122 --- Standard<br />

Destination<br />

DHCP Client Maintenance Information 116 --- Standard<br />

Destination<br />

DHCP Client Maintenance Information 117 --- Standard<br />

Destination<br />

DHCP Client Maintenance Information 115 --- Standard<br />

Destination<br />

DHCP Client Maintenance Information 118 --- Standard<br />

Destination<br />

DHCP Client Maintenance Information 108 --- Standard<br />

Destination<br />

PPPoE Maintenance Information 722 --- Simple<br />

PPPoE Maintenance Information 720 --- Simple<br />

PPPoE Maintenance Information 595 --- Simple<br />

Senna Spy attack<br />

dropped<br />

Intrusion<br />

Detection<br />

Attack Alert 78 517 Standard<br />

Sent Relay IP Table<br />

to Central Gateway<br />

SIP Register expiration<br />

exceeds<br />

configured<br />

Signaling<br />

inactivity time out<br />

DHCP Relay Maintenance Information 232 --- Standard<br />

VoIP VoIP Warning 645 --- Standard<br />

Note String<br />

SIP Request VoIP VoIP Debug 643 --- Standard<br />

Note String<br />

SIP Response VoIP VoIP Debug 644 --- Standard<br />

Note String<br />

SMTP<br />

POP-Before-SMTP<br />

authentication<br />

failed<br />

Firewall<br />

<strong>Log</strong>ging<br />

System Error Warning 656 --- Simple<br />

52 SONICOS LOG EVENT REFERENCE GUIDE


SMTP server found<br />

on RBL blacklist<br />

RBL --- Notice 799 --- Standard<br />

Note String<br />

Smurf<br />

Amplification<br />

attack dropped<br />

Intrusion<br />

Detection<br />

Attack Alert 81 520 Standard<br />

SonicPoint<br />

Provision<br />

SonicPoint<br />

statistics report<br />

SonicPoint SonicPoint Information 727 --- Simple<br />

Destination<br />

GMS --- Information 806 --- Simple<br />

SonicPoint<br />

Statistics<br />

SonicPoint Status SonicPoint SonicPoint Information 667 --- Simple<br />

Destination<br />

<strong>SonicWALL</strong><br />

activated<br />

<strong>SonicWALL</strong><br />

initializing<br />

Firewall <strong>Event</strong> Maintenance Alert 4 --- Simple<br />

Firewall <strong>Event</strong> Maintenance Information 521 --- Simple<br />

Source routed IP<br />

packet dropped<br />

Spank attack<br />

multicast packet<br />

dropped<br />

Intrusion<br />

Detection<br />

Intrusion<br />

Detection<br />

Debug Warning 428 --- Standard<br />

Attack Alert 606 568 Standard<br />

Starting IKE<br />

negotiation<br />

Starting PPPoE<br />

discovery<br />

VPN IKE User Activity Information 90 --- Standard<br />

Note String<br />

PPPoE Maintenance Information 127 --- Simple<br />

Status GMS Maintenance Emergency 96 --- Simple<br />

GMS<br />

Status<br />

Striker attack<br />

dropped<br />

Sub Seven attack<br />

dropped<br />

Success to reach<br />

Interface %s probe<br />

Intrusion<br />

Detection<br />

Intrusion<br />

Detection<br />

High<br />

Availability<br />

Attack Alert 77 516 Standard<br />

Attack Alert 75 514 Standard<br />

System Error Information 674 --- Standard<br />

String<br />

Service<br />

Successful<br />

authentication<br />

received for<br />

Remotely<br />

Triggered Dial-out<br />

Authentication User Activity Information 820 --- Simple<br />

SONICOS LOG EVENT REFERENCE GUIDE 53


SYN Flood<br />

Blacklist on IF %s<br />

continues<br />

SYN Flood<br />

blacklisting<br />

disabled by user<br />

SYN Flood<br />

blacklisting<br />

enabled by user<br />

SYN flood ceased<br />

or flooding<br />

machines<br />

blacklisted -<br />

connection proxy<br />

disabled<br />

SYN Flood Mode<br />

changed by user<br />

to: Always proxy<br />

WAN connections<br />

SYN Flood Mode<br />

changed by user<br />

to: Watch and<br />

proxy WAN<br />

connections when<br />

under attack<br />

SYN Flood Mode<br />

changed by user<br />

to: Watch and<br />

report possible<br />

SYN floods<br />

Synchronizing<br />

preferences to HA<br />

Peer Firewall<br />

SYN-Flooding<br />

machine %s<br />

blacklisted<br />

TCP checksum<br />

error<br />

TCP connection<br />

dropped<br />

TCP connection<br />

from LAN denied<br />

Intrusion<br />

Detection<br />

Intrusion<br />

Detection<br />

Intrusion<br />

Detection<br />

Intrusion<br />

Detection<br />

Intrusion<br />

Detection<br />

Intrusion<br />

Detection<br />

Intrusion<br />

Detection<br />

High<br />

Availability<br />

Intrusion<br />

Detection<br />

Network<br />

Access<br />

Network<br />

Access<br />

Network<br />

Access<br />

--- Warning 868 --- Standard<br />

String<br />

Service<br />

--- Warning 863 --- Standard<br />

--- Warning 862 --- Standard<br />

--- Alert 861 --- Standard<br />

--- Warning 858 --- Standard<br />

--- Warning 857 --- Standard<br />

--- Warning 856 --- Standard<br />

Maintenance Information 673 --- Simple<br />

--- Alert 864 --- Standard<br />

String<br />

Service<br />

UDP Notice 884 --- Standard<br />

UDP Notice 36 --- Standard<br />

Policy<br />

LAN TCP Notice 173 --- Standard<br />

Service<br />

TCP FIN packet<br />

dropped<br />

Network Debug Debug 181 --- Standard<br />

54 SONICOS LOG EVENT REFERENCE GUIDE


TCP stateful<br />

inspection<br />

enforcement:<br />

Bad header<br />

dropped<br />

TCP stateful<br />

inspection<br />

enforcement:<br />

Connection<br />

aborted<br />

TCP stateful<br />

inspection<br />

enforcement:<br />

Connection<br />

refused<br />

TCP stateful<br />

inspection<br />

enforcement:<br />

Invalid ack<br />

dropped<br />

TCP stateful<br />

inspection<br />

enforcement:<br />

Invalid flag<br />

dropped<br />

TCP stateful<br />

inspection<br />

enforcement:<br />

Invalid sequence<br />

dropped<br />

Network Debug Debug 711 --- Standard<br />

Network Debug Debug 713 --- Standard<br />

Network Debug Debug 712 --- Standard<br />

Network Debug Debug 709 --- Standard<br />

Network Debug Information 710 --- Standard<br />

Network Debug Debug 708 --- Standard<br />

TCP SYN received<br />

TCP Syn/Fin<br />

packet dropped<br />

TCP Xmas Tree<br />

dropped<br />

Intrusion<br />

Detection<br />

Network<br />

Access<br />

Intrusion<br />

Detection<br />

--- Debug 869 --- Standard<br />

Attack Alert 580 558 Standard<br />

Attack Alert 267 547 Standard<br />

The cache is full;<br />

%u open<br />

connections; some<br />

will be dropped<br />

Firewall <strong>Event</strong> System Error Error 53 607 Standard<br />

Message<br />

Number<br />

The loaded<br />

content URL List<br />

has expired<br />

Security<br />

Services<br />

System Error Error 190 628 Simple<br />

SONICOS LOG EVENT REFERENCE GUIDE 55


The network<br />

connection in use<br />

is %s<br />

The preferences<br />

file is too large to<br />

be saved in<br />

available flash<br />

memory<br />

WAN Failover System Error Warning 307 639 Standard<br />

Message<br />

String<br />

Firewall <strong>Event</strong> System Error Warning 573 649 Simple<br />

Thermal Red<br />

Firewall<br />

Hardware<br />

System<br />

Environment<br />

Alert 578 104 Simple<br />

Thermal Red Timer<br />

Exceeded<br />

Firewall<br />

Hardware<br />

System<br />

Environment<br />

Alert 579 105 Simple<br />

Thermal Yellow<br />

Firewall<br />

Hardware<br />

System<br />

Environment<br />

Alert 577 103 Simple<br />

Time of day<br />

settings for firewall<br />

policies were<br />

not upgraded.<br />

Firewall <strong>Event</strong> Maintenance Information 742 --- Simple<br />

UDP checksum<br />

error<br />

UDP packet<br />

dropped<br />

Network<br />

Access<br />

Network<br />

Access<br />

UDP Notice 885 --- Standard<br />

UDP Notice 37 --- Standard<br />

Policy<br />

UDP packet from<br />

LAN dropped<br />

Network<br />

Access<br />

LAN UDP |<br />

LAN TCP<br />

Notice 174 --- Standard<br />

Service<br />

Unable to<br />

download IPS/GAV/<br />

Aspy Signature<br />

database. Firewall<br />

must first be<br />

restarted to free<br />

memory used by<br />

downloaded<br />

firmware.<br />

Unused --- Warning 873 --- Simple<br />

Unknown protocol<br />

dropped<br />

Network<br />

Access<br />

Debug Notice 41 --- Standard<br />

Note String<br />

Unknown reason VPN PKI User Activity Error 275 --- Simple<br />

Destination<br />

User logged out Authentication User Activity Information 263 --- Standard<br />

String<br />

Service<br />

User logged<br />

out - inactivity<br />

timer expired<br />

Authentication User Activity Information 265 --- Standard<br />

Note String<br />

56 SONICOS LOG EVENT REFERENCE GUIDE


User logged<br />

out - max session<br />

time exceeded<br />

User logged<br />

out - user<br />

disconnect<br />

detected (heartbeat<br />

timer expired)<br />

User login denied -<br />

insufficient access<br />

on LDAP server<br />

User login denied -<br />

invalid credentials<br />

on LDAP server<br />

User login denied -<br />

LDAP<br />

authentication failure<br />

User login denied -<br />

LDAP<br />

communication<br />

problem<br />

User login denied -<br />

LDAP directory<br />

mismatch<br />

User login denied -<br />

LDAP schema<br />

mismatch<br />

User login denied -<br />

LDAP server<br />

certificate not valid<br />

User login denied -<br />

LDAP server down<br />

or misconfigured<br />

User login denied -<br />

LDAP server name<br />

resolution failed<br />

User login denied -<br />

LDAP server<br />

timeout<br />

User login denied -<br />

RADIUS<br />

authentication<br />

failure<br />

Authentication User Activity Information 264 --- Standard<br />

Note String<br />

Authentication User Activity Information 24 --- Standard<br />

Note String<br />

RADIUS User Activity Warning 750 --- Standard<br />

String Service<br />

RADIUS User Activity Warning 749 --- Standard<br />

String Service<br />

RADIUS User Activity Information 745 --- Standard<br />

String Service<br />

RADIUS User Activity Warning 748 --- Standard<br />

String<br />

Service<br />

RADIUS User Activity Warning 757 --- Standard<br />

String<br />

Service<br />

RADIUS User Activity Warning 751 --- Standard<br />

String<br />

Service<br />

RADIUS User Activity Warning 755 --- Standard<br />

String<br />

Service<br />

RADIUS User Activity Warning 747 --- Standard<br />

String<br />

Service<br />

RADIUS User Activity Warning 753 --- Standard<br />

String<br />

Service<br />

RADIUS User Activity Warning 746 --- Standard<br />

String<br />

Service<br />

RADIUS User Activity Information 243 --- Standard<br />

String<br />

Service<br />

SONICOS LOG EVENT REFERENCE GUIDE 57


User login denied -<br />

RADIUS<br />

communication<br />

problem<br />

User login denied -<br />

RADIUS<br />

configuration error<br />

User login denied -<br />

RADIUS server<br />

name resolution<br />

failed<br />

User login denied -<br />

RADIUS server<br />

timeout<br />

User login denied -<br />

TLS or local<br />

certificate problem<br />

User login denied -<br />

User has no<br />

privileges for login<br />

from that location<br />

User login denied -<br />

User has no<br />

privileges for<br />

WLAN guest<br />

service<br />

User login denied<br />

due to bad<br />

credentials<br />

User login disabled<br />

from %s<br />

User login failed -<br />

Guest service limit<br />

reached<br />

User login failure<br />

rate exceeded -<br />

logins from user IP<br />

address denied<br />

RADIUS User Activity Warning 744 --- Standard<br />

String<br />

Service<br />

RADIUS User Activity Information 245 --- Standard<br />

String<br />

Service<br />

RADIUS User Activity Warning 754 --- Standard<br />

String<br />

Service<br />

RADIUS User Activity Information 244 --- Standard<br />

String<br />

Service<br />

RADIUS User Activity Warning 756 --- Standard<br />

String<br />

Service<br />

RADIUS User Activity Information 246 --- Standard<br />

String<br />

Service<br />

Authentication User Activity Information 486 --- Standard<br />

Destination<br />

Authentication User Activity Information 33 --- Standard<br />

String<br />

Service<br />

Authentication Attack Error 583 559 Standard<br />

Message<br />

String<br />

Authentication User Activity Information 549 --- Standard<br />

Note String<br />

Authentication Attack Error 329 561 Standard<br />

Destination<br />

Virtual Access<br />

Point is disabled<br />

Virtual Access<br />

Point is enabled<br />

SonicPoint 802.11b<br />

Management<br />

SonicPoint 802.11b<br />

Management<br />

Information 731 --- Simple<br />

Destination<br />

Information 730 --- Simple<br />

Destination<br />

58 SONICOS LOG EVENT REFERENCE GUIDE


VoIP %s Endpoint<br />

added<br />

VoIP %s Endpoint<br />

not added -<br />

configured 'public'<br />

endpoint limit<br />

reached<br />

VoIP %s Endpoint<br />

removed<br />

VoIP Call<br />

Connected<br />

VoIP Call<br />

Disconnected<br />

VoIP VoIP Debug 637 --- Standard<br />

String<br />

Service<br />

VoIP VoIP Warning 639 --- Standard<br />

String<br />

Service<br />

VoIP VoIP Debug 638 --- Standard<br />

String<br />

Service<br />

VoIP VoIP Information 622 --- Standard<br />

Note String<br />

VoIP VoIP Information 623 --- Standard<br />

Note String<br />

Voltages Out of<br />

Tolerance<br />

Firewall Hardware<br />

System Environment<br />

Error 575 101 Simple<br />

VPN Cleanup:<br />

Dynamic network<br />

settings change<br />

VPN Client Policy<br />

Provisioning<br />

VPN disabled by<br />

administrator<br />

VPN disabled for<br />

active dial up<br />

VPN enabled by<br />

administrator<br />

VPN User Activity Information 471 --- Standard<br />

VPN Client User Activity Information 371 --- Standard<br />

Destination<br />

Authentication Maintenance Information 506 --- Simple<br />

Unused Maintenance Information 503 --- Simple<br />

Authentication Maintenance Information 507 --- Simple<br />

VPN <strong>Log</strong> Debug VPN IKE Debug Information 172 --- Simple<br />

String<br />

VPN policy count<br />

received exceeds<br />

the limit; %s<br />

VPN zone<br />

administrator login<br />

allowed<br />

VPN zone remote<br />

user login allowed<br />

WAN Interface not<br />

setup<br />

VPN System Error Error 719 --- Standard<br />

String<br />

Service<br />

Authentication User Activity Information 235 --- Standard<br />

Authentication User Activity Information 237 --- Standard<br />

String<br />

Service<br />

Firewall <strong>Event</strong> Maintenance Information 498 --- Simple<br />

WAN IP Changed Firewall <strong>Event</strong> System Error Warning 138 636 Standard<br />

SONICOS LOG EVENT REFERENCE GUIDE 59


WAN not ready Firewall <strong>Event</strong> Maintenance Information 502 --- Simple<br />

WAN zone<br />

administrator login<br />

allowed<br />

WAN zone remote<br />

user login allowed<br />

WARNING: DHCP<br />

lease relayed from<br />

Central Gateway<br />

conflicts with IP in<br />

Static Devices list<br />

Authentication User Activity Information 236 --- Standard<br />

Authentication User Activity Information 238 --- Standard<br />

String Service<br />

DHCP Relay Maintenance Information 227 --- Standard<br />

Destination<br />

Web access<br />

request dropped<br />

Web management<br />

request allowed<br />

Web site access<br />

allowed<br />

Web site access<br />

denied<br />

Network<br />

Access<br />

Network<br />

Access<br />

Network<br />

Access<br />

Network<br />

Access<br />

UDP Notice 524 --- Standard<br />

Policy<br />

User Activity Notice 526 --- Standard<br />

Service<br />

Blocked Sites Notice 16 703 Standard<br />

Note<br />

Blocked<br />

Blocked Sites Notice 14 701 Standard<br />

Note<br />

Blocked<br />

Wireless MAC<br />

Filter List disabled<br />

by administrator<br />

Wireless MAC<br />

Filter List enabled<br />

by administrator<br />

WLAN client null<br />

probing<br />

WLAN disabled by<br />

administrator<br />

WLAN disabled by<br />

schedule<br />

Authentication Maintenance Information 513 --- Simple<br />

Authentication Maintenance Information 512 --- Simple<br />

WLAN IDS WLAN IDS Warning 615 904 Standard<br />

Destination<br />

Authentication Maintenance Information 508 --- Simple<br />

Authentication Maintenance Information 728 --- Simple<br />

Wlan drop traffic to<br />

deny network<br />

Network<br />

Access<br />

--- Information 724 --- Standard<br />

Note String<br />

WLAN enabled by<br />

administrator<br />

WLAN enabled by<br />

schedule<br />

Authentication Maintenance Information 509 --- Simple<br />

Authentication Maintenance Information 729 --- Simple<br />

60 SONICOS LOG EVENT REFERENCE GUIDE


WLAN firmware<br />

image has been<br />

updated<br />

WLAN Guest<br />

Account Timeout<br />

WLAN Guest Idle<br />

Timeout<br />

WLAN Guest<br />

Session Timeout<br />

Wireless Maintenance Information 487 --- Simple<br />

String<br />

Authentication User Activity Information 551 --- Standard<br />

Note String<br />

Authentication User Activity Information 564 --- Standard<br />

Note String<br />

Authentication User Activity Information 550 --- Standard<br />

Note String<br />

WLAN max<br />

concurrent users<br />

reached already<br />

Network<br />

Access<br />

--- Information 726 --- Standard<br />

Note String<br />

WLAN not in AP<br />

mode, DHCP<br />

server will not<br />

provide lease to<br />

clients on WLAN<br />

Wireless Maintenance Information 617 --- Simple<br />

WLAN pass traffic<br />

to access allow<br />

network<br />

Network<br />

Access<br />

--- Information 725 --- Standard<br />

Note String<br />

WLAN recovery Wireless Maintenance Information 519 --- Simple<br />

String<br />

WLAN sequence<br />

number out of<br />

order<br />

WLB Failback<br />

initiated by %s<br />

WLB Failover in<br />

progress<br />

WLB Resource<br />

failed<br />

WLB Resource is<br />

now available<br />

WLB Spill-over<br />

started,<br />

configured<br />

threshold<br />

exceeded<br />

WLB Spill-over<br />

stopped<br />

WLAN IDS WLAN IDS Warning 547 902 Simple<br />

Destination<br />

WAN Failover System Error Alert 435 652 Standard<br />

Message<br />

String<br />

WAN Failover System Error Alert 584 651 Standard<br />

WAN Failover System Error Alert 586 654 Standard<br />

WAN Failover System Error Alert 585 653 Standard<br />

WAN Failover Maintenance Warning 581 --- Simple<br />

WAN Failover Maintenance Warning 582 --- Simple<br />

SONICOS LOG EVENT REFERENCE GUIDE 61


WPA MIC Failure Wireless 802.11b<br />

Management<br />

Warning 663 --- Simple<br />

Destination<br />

WPA Radius Server<br />

Timeout<br />

Wireless 802.11b<br />

Management<br />

Information 664 --- Simple<br />

Destination<br />

XAUTH Failed with<br />

VPN client,<br />

Authentication<br />

failure<br />

XAUTH Failed with<br />

VPN client, Cannot<br />

Contact RADIUS<br />

Server<br />

XAUTH Succeeded<br />

with VPN client<br />

VPN Client User Activity Information 140 --- Standard<br />

Destination<br />

VPN Client User Activity Information 141 --- Standard<br />

Destination<br />

VPN Client User Activity Information 139 --- Standard<br />

Destination<br />

62 SONICOS LOG EVENT REFERENCE GUIDE


Index of Syslog Tag Field Description<br />

This section provides an alphabetical listing of Syslog tags and the associated field description.<br />

Tag Field Description<br />

Syslog message prefix The beginning of each syslog message has a<br />

string of the form where ddd is a decimal<br />

number indicating facility and priority of the message.<br />

(See [1] Section 4.1.1)<br />

arg URL Used to render a URL: arg represents the URL<br />

path name part.<br />

bcastRx Interface statistics report Displays the broadcast packets received<br />

bcastTx Interface statistics report Displays the broadcast packets transmitted<br />

bytesRx Interface statistics report Displays the bytes received<br />

bytesTx Interface statistics report Displays the bytes transmitted<br />

c Message category (legacy only) Indicates the legacy category number (Note: We<br />

are not currently sending new category information.)<br />

change Configuration change webpage Displays the basename of the firewall web page<br />

that performed the last configuration change<br />

code Blocking code Indicates the CFS block code category<br />

code ICMP type and code Indicates the ICMP code<br />

conns Firewall status report Indicates the number of connections in use<br />

cpuUtil Firewall status report Displays the CPU utilization (not in use)<br />

dst Destination Destination IP address, and optionally, port, network<br />

interface, and resolved name.<br />

dstname Destination URL Displays the URL of web site hit and other legacy<br />

destination strings<br />

dstname URL Used to render a URL: dstname represents the<br />

URL host part<br />

dyn Firewall status report Displays the HA and dialup connection state (rendered<br />

as “h.d” where “h” is “n” (not enabled), “b”<br />

(backup), or “p” (primary) and “d” is “1” (enabled)<br />

or “0” (disabled))<br />

fw Firewall WAN IP Indicates the WAN IP Address<br />

fwlan Firewall status report Indicates the LAN zone IP address<br />

goodRxBytes SonicPoint statistics report Indicates the well formed bytes recevied<br />

goodTxBytes SonicPoint statistics report Indicates the well formed bytes transmitted<br />

SONICOS LOG EVENT REFERENCE GUIDE 63


i Firewall status report Displays the GMS message interval in seconds<br />

id=firewall Webtrends prefix Syntactic sugar for WebTrends (and GMS by<br />

habit)<br />

if Interface statistics report Displays the interface on which statistics are<br />

reported<br />

ipscat IPS message Displays the IPS category<br />

ipspri IPS message Displays the IPS priority<br />

lic Firewall status report Indicates the number of licenses for firewalls with<br />

limited modes<br />

m Message ID Provides the message ID number<br />

mac MAC address Provides the MAC address<br />

msg Static message Displays the event message (from spreadsheet)<br />

msg Dynamically-defined message Displays a dynamically defined message string<br />

msg Static message with dynamic string Displays a message using the predefined message<br />

string containing a “%s” and a dynamic<br />

string argument.<br />

msg<br />

Static message with dynamic number<br />

Displays a message using the predefined string<br />

string containing a “%s” and a dynamic numeric<br />

argument.<br />

msg IPS message Displays a message using the predefined message<br />

string containing a “%s” and a dynamic<br />

string argument.<br />

msg Anti-Spyware message Displays the event message (from spreadsheet)<br />

n Message count Indicates the number of times event occurs<br />

op HTTP OP code Displays the HTTP operation (GET, POST, etc.)<br />

of web site hit<br />

pri Message priority Displays the event priority level (0=emergency..7=debug)<br />

proto IP protocol Indicates the IP protocol and detail information<br />

proto Protocol and service Displays the protocol information (rendered as<br />

“proto/service”)<br />

proto Protocol and service Displays the protocol information (rendered as<br />

“proto/service”)<br />

pt Firewall status report Displays the HTTP/HTTPS management port<br />

(rendered as “hhh.sss”)<br />

radio SonicPoint statistics report Displays the SonicPoint radio on which event<br />

occurred<br />

ramUtil Firewall status report Displays the RAM utilization (not in use)<br />

64 SONICOS LOG EVENT REFERENCE GUIDE


cvd Bytes received Indicates the number of bytes received within<br />

connection<br />

result HTTP Result code Displays the HTTP result code (200, 403, etc.) of<br />

web site hit<br />

rule Rule ID Displays the Access Rule number causing packet<br />

drop<br />

sent Bytes sent Displays the number of bytes sent within connection<br />

sid IPS message Provides the IPS signature ID<br />

sid Anti-Spyware message Provides the AntiSpyware signature ID<br />

sn Firewall serial number Indicates the device serial number<br />

spycat Anti-Spyware message Displays the antiSpyware category<br />

spypri Anti-Spyware message Displays the AntiSpyware priority<br />

src Source Indicates the source IP address, and optionally,<br />

port, network interface, and resolved name.<br />

station SonicPoint statistics report Displays the client (station) on which event<br />

occurred<br />

time Time Reports the time of event<br />

type ICMP type and code Indicates the ICMP type<br />

ucastRx Interface statistics report Displays the unicast packets received<br />

ucastTx Interface statistics report Displays the unicast packets transmitted<br />

unsynched Firewall status report Reports the time since last local change in seconds<br />

usesstandbysa Firewall status report Displays whether standby SA is in use (“1” or “0”)<br />

for GMS management<br />

usr (or user) User Displays the user name (“user” is the tag used by<br />

WebTrends)<br />

vpnpolicy VPN policy name Displays the VPN policy name of event<br />

SONICOS LOG EVENT REFERENCE GUIDE 65


66 SONICOS LOG EVENT REFERENCE GUIDE


<strong>SonicWALL</strong>,Inc.<br />

1143 Borregas Avenue<br />

Sunnyvale,CA 94089-1306<br />

T: 408.745.9600<br />

F: 408.745.9300<br />

www.sonicwall.com<br />

© 2002 <strong>SonicWALL</strong>, I n c .<strong>SonicWALL</strong> is a registered trademark of <strong>SonicWALL</strong>, I n c .Other product and company names mentioned herein may be<br />

t rademarks and/ or registered trademarks of their respective companies. Specifications and descriptions subject to change with out notice.<br />

P/ N 232-000827-00<br />

Rev B 6/05

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!