Application Control Engine Module System Message Guide (Software Version A2(1.0))
Index

Table Of Contents

A - B - C - D - E - F - H - I - L - M - N - O - P - Q - R - S - T - U - V - W -

Index

A

ACE

initialization failure 2-41

logging, enabling 1-20

logging, rejecting new connections 1-20

logging levels 1-4

logging overview 1-2

log message format 1-3

network processor error 2-48

physical memory for load-balancing 2-47

severity levels 1-4

subsystem levels 1-4

ACL resources

minimum not guaranteed 2-12

usage beyond limit 2-11

ACLs

compilation process out of memory 2-3

alert messages 3-1

ARP

collision 2-19

inspection check failure 2-18

poisoning 2-19

attacks

ARP poisoning 2-19

spoofing 2-1, 2-17, 2-18, 2-21

B

buffer, logging to 1-9

C

cache alignment error 2-45

clearing log messages 1-22

configuration, modified by command, system message 2-3

configuration files

replication failure 2-33

configuration modified by command message 2-2, 2-3

console

logging to 1-11

content type verification

failed, unexpected number in message body 2-22

context

adding context with an associated sticky group 2-44

associated sticky group 2-44

configuration synchronization failure 2-36

removing with an associated sticky group 2-44

show command failure 2-45

state change 2-36

sticky entry request 2-44

control processor, unrecognized message 2-49

critical messages 3-2

D

debugging messages 3-8

debug logging failure 2-51

DNS

packet message 2-20

E

EMBLEM-format logging 1-12

Encap table full 2-18

error messages 3-2

F

facility, changing 1-17

fault tolerance

See HA

Flash memory

logging to 1-14

FT group

context name mismatch 2-33

peer state change 2-50

two active devices detected 2-33

FT interface, peer unreachable 2-33

FTP port command

address other than the address used in the connection 2-20

low port number 2-19

FTP traffic

strict inspection policy denies request command 2-15

unrecognized command in request message when using strict inspection policy 2-15

FT track state change 2-39

H

HA

alternate pings 2-39, 2-40

communication failure 2-35

configuration replication failure 2-36

context name mismatch 2-33

context state change 2-36

data dropped 2-51

FT track state change 2-39

heartbeat interval mismatch 2-38

heartbeats unidirectional 2-38

initialization failure 2-34

internal error 2-35

mapping failure 2-50

module 2-34

peer compatibility 2-40

peer incompatibility 2-34

peer reachable 2-37, 2-40

peer state change 2-50

peer unreachable 2-32, 2-33, 2-46

receive error 2-46

redundancy heartbeat stopped 2-40

replication failure 2-33, 2-35

replication in process 2-38

state transitions 2-36

two active devices detected 2-33

hash table, invalid index 2-48

heartbeat

interval mismatch 2-38

started 2-40

stopped 2-32, 2-39, 2-40

unidirectional 2-38

High Availability

See HA

HTTP

body length within configured range 2-24

body matches regular expression 2-22

header length within configured range 2-24

parser unable to detect valid message 2-23

request method matches regular expression 2-23

return code, threshold reached 2-51

transfer/content encoding matches regular expression 2-23

URI length within configured range 2-23

URI matches regular expression 2-22

HTTP content

instant messenger protocol detected 2-25

peer-to-peer protocol detected 2-25

tunneling protocol detected 2-24

HTTP header

matches regular expression 2-22, 2-24

I

ICMP

health probe error 2-7

initialization failure 2-16

memory failure 2-17

packet denied 2-16

probe error 2-6, 2-7

session established 2-14

session removed 2-14

unexpected server response 2-8

informational messages 3-7

initialization failure 2-34, 2-41

interface

configuration status change 2-21

configuration status changed 2-21

line protocol change of state 2-20

VLAN availability 2-32

invalid lookup key 2-49

IP header option error 2-19

L

levels

changing 1-18

overview 1-4

severity listing 1-4

licenses

16G takes effects after reboot 2-29

evaluation time expired 2-28

evaluation time warning 2-28

failed checkout 2-27

installation completed 2-28

manager exiting 2-28

uninstall completed 2-28

limiting the syslog rate 1-19

line protocol, status change 2-20

load balancing

cache alignment error 2-45

general error 2-42

HA data dropped 2-51

internal channel error 2-45

internal error 2-43

mapped memory 2-47

processor communications error 2-45

sticky database error 2-43, 2-47

sticky entry inconsistency 2-47

sticky error 2-43

transmit failure 2-42

unrecognized message 2-49

log files, logging levels 1-4

logging

changing message levels 1-7, 1-19

connection setup and teardown syslog messages, enabling 1-22

disabling messages 1-18

EMBLEM-format logging 1-12

enabling 1-8, 1-20

facility, changing 1-17

levels 1-4

log messages, clearing 1-22

message format 1-3

message queue size, changing 1-17

overview 1-2

quick start 1-6

rejecting new connections 1-20

severity level of messages, changing 1-18

severity levels 1-4

syslog output locations, specifying 1-8

syslog rate, limiting 1-19

system message timestamp, enabling 1-15

to buffer 1-9

to console 1-11

to Flash memory 1-14

to SNMP NMS 1-13

to SSH session 1-9

to Supervisor engine 1-13

to syslog server 1-11

to Telnet session 1-9

variables 1-4

viewing log message information 1-23

logging on the ACE, enabling 1-20

M

MAC addresses

mapping change 2-21

mapping failure 2-50

memory mapping failure 2-51

messages

format 1-3

message queue size, changing 1-17

severity levels 1-4, 3-1

timestamp, enabling 1-15

understanding 1-3

variables 1-4

N

network processor error, sticky 2-48, 2-49

notification messages 3-5

numerical codes of system messages 2-1

O

output locations

buffer 1-9

console 1-11

Flash memory 1-14

SNMP 1-13

SNMP NMS 1-13

specifying 1-8

SSH session 1-9

Supervisor module 1-13

syslog server 1-11

Telnet 1-9

Telnet session 1-9

P

peer

alternate pings 2-39, 2-40

communication failure 2-35

heartbeat interval mismatch 2-38

heartbeats unidirectional 2-38

incompatibility 2-34

mapping failure 2-50

reachable 2-37, 2-40

receive error 2-46

replication failure 2-33, 2-35

replication in process 2-38

state change 2-50

unreachable 2-32, 2-33, 2-46

probe

connectivity error 2-7

connectivity error for ICMP probe 2-7

empty health probe script 2-5

failure due to internal error 2-6

internal error for ICMP probe 2-6, 2-7

internal error when loading script 2-6

lost script file 2-5

memory allocation failure 2-5

unable to load script 2-6

unexpected ICMP server response 2-8

unexpected server response 2-8

processing

ACL compilation process out of memory 2-3

invalid lookup key 2-49

proxy connection rebalanced 2-46

Q

quick start

logging 1-6

R

real servers

HTTP return code threshold 2-51

state change 2-27

state change to down 2-27

state change to down in specified server farm 2-26

state change to up 2-27

state change to up in specified server farm 2-26

regex resources

minimum not guaranteed 2-52

usage beyond limit 2-52

regular expression table compilation process, out of memory 2-52

reload

reasons 2-4

record 2-4

RTSP

connection, opened by ASA for specified IP address and ports 2-17

S

SCCP

command denied by inspection policy 2-31

connection preallocated for session-negotiated media streams 2-30

message over configured size dropped 2-31

message that is too small dropped 2-30

registration not completed 2-31

scripts

empty 2-5

error determining size 2-9

error reading 2-9

internal error when loading 2-6

lost file 2-5

memory allocation error 2-6

security context

added to system 2-29

removed from system 2-29

server connection

lost 2-42

rebalanced 2-46

server farms

failover back in service notification 2-26

failover to backup notification 2-26

HTTP return code threshold 2-51

severity codes of system messages 3-1

severity level messages

Level 1 messages 3-1

Level 2 messages 3-2

Level 3 messages 3-2

Level 4 messages 3-4

Level 5 messages 3-5

Level 6 messages 3-7

Level 7 messages 3-8

overview 1-4

severity levels

alerts 3-1

changing 1-18

critical 3-2

debugging 3-8

errors 3-2

informational 3-7

notifications 3-5

of messages 3-1

overview 1-4

warning 3-4

show command

failure 2-45

site security policy, averting 2-19, 2-20

SNMP

daemon initialization failure 2-4, 2-5

memory allocation failure 2-4, 2-5

network management station 1-13

Shadow Table error 2-25

spoofing attack 2-1, 2-17, 2-18, 2-21

SSH

session, sending syslog messages 1-9

SSL

CRL, failure to retrieve 2-11

SSL certificate

expired 2-9, 2-11

invalid or nonexistent 2-10

not currently valid 2-9

revoked by certificate authority 2-10

signature invalid 2-10

unknown certificate authority 2-10

sticky

associated group 2-44

database error 2-43

entries added or removed 2-48

entry dropped 2-50

entry inconsistency 2-47

initialization failure 2-41

key, invalid 2-49

network processor error 2-49

processor error 2-43, 2-48

request not responded to 2-47

resources exceeded 2-44

unexpected sticky group lookup result 2-47

subsystems 1-4

supervisor

logging to 1-13

syslog output locations

buffer 1-9

console 1-11

Flash memory 1-14

SNMP NMS 1-13

specifying 1-8

SSH session 1-9

Supervisor engine 1-13

syslog server 1-11

Telnet session 1-9

syslog rate, limiting 1-19

syslog server

device ID, specifying 1-16

EMBLEM-format logging 1-12

identifying messages sent 1-15

sending syslog messages 1-11

system message logging

connections

setup and teardown syslog messages, enabling 1-22

disabling messages 1-18

EMBLEM-format logging 1-12

enabling 1-8, 1-20

facility, changing 1-17

format 1-3

log messages, clearing 1-22

overview 1-2

queue, changing 1-17

quick start 1-6

rejecting new connections 1-20

severity level, changing 1-18

severity levels 1-4

syslog output locations, specifying 1-8

syslog rate, limiting 1-19

to buffer 1-9

to console 1-11

to Flash memory 1-14

to SNMP NMS 1-13

to SSH session 1-9

to Supervisor engine 1-13

to syslog server 1-11

to Telnet session 1-9

understanding 1-3

variables 1-4

viewing log message information 1-23

system messages

by numerical code 2-1

by severity code 3-1

timestamps, enabling 1-15

T

TCP

connection failure 2-35

connection slot creation 2-12, 2-14

connection slot termination 2-12, 2-14

termination reasons 2-12, 2-14

Telnet

session, sending syslog messages 1-9

U

UDP

connection slot creation 2-13, 2-15

connection slot deletion 2-13, 2-15

DNS packet 2-20

URL

host access record 2-16

V

variables

fields 1-4

in messages 1-4

viewing log message information 1-23

VLANs

number availability 2-32

W

warning messages 3-4