Table Of Contents
System Log Messages
Messages 102001 to 199009
102001
103002
103003
103004
103005
103006
103007
104001, 104002
104003
104004
105001
105002
105003
105004
105005
105006, 105007
105008
105010
105020
105021
105031
105032
105034
105035
105038
105039
105040
105042
105043
105044
105045
105046
105047
106001
106002
106006
106007
106010
106011
106012
106013
106014
106015
106016
106017
106018
106020
106021
106022
106023
106024
106025, 106026
106027
106100
106101
107001
107002
108002
108003
109001
109002
109003
109005
109006
109007
109008
109010
109011
109012
109013
109014
109016
109017
109018
109019
109020
109021
109022
109023
109024
109025
109026
109027
109028
109030
109031
109037
109039
110001
111003
111004
111005
111007
111008
111009
111111
112001
113001
113003
113004
113005
113006
113007
113008
113009
113010
113011
113012
113013
113014
113015
113016
113017
113018
113019
199001
199002
199003
199005
199006
199907
199908
199909
Messages 201002 to 217001
201002
201003
201004
201005
201006
201009
202001
202005
202011
208005
209003
209004
209005
210001
210002
210003
210005
210006
210007
210008
210010
210020
210021
210022
211001
211003
212001
212002
212003
212004
212005
212006
214001
215001
217001
Messages 302003 to 326028
302003
302004
302009
302010
302012
302013
302014
302015
302016
302017
302018
302019
302020
302021
302022
302023
302302
303002
303003
303004
304001
304002
304003
304004
304005
304006
304007
304008
304009
305005
305006
305007
305008
305009
305010
305011
305012
308001
308002
311001
311002
311003
311004
312001
313001
313003
313004
313008
314001
315004
315011
316001
317001
317002
317003
317004
317005
318001
318002
318003
318004
318005
318006
318007
318008
319001
319002
319003
319004
320001
321001
321002
321003
321004
322001
322002
322003
322004
323004
323005
324000
324001
324002
324003
324004
324005
324006
324007
325001
325002
326001
326002
326004
326005
326006
326007
326008
326009
326010
326011
326012
326013
326014
326015
326016
326017
326019
326020
326021
326022
326023
326024
326025
326026
326027
326028
Messages 400000 to 418001
402101
402102
402103
402106
404101
404102
405001
405101
405002
405101
405102
405103
405104
405105
405201
406001
406002
407001
407002
407003
408001
408002
409001
409002
409003
409004
409005
409006
409007
409008
409009
409010
409011
409012
409013
409023
410001
411001
411002
411003
411004
412001
412002
413001
413002
413003
413004
414001
414002
415001
415002
415003
415004
415005
415006
415007
415008
415009
415010
415011
415012
415013
415014
416001
417001
417004
417006
418001
Messages 500001 to 507002
500001
500002
500003
500004
501101
502101
502102
502103
502111
502112
503001
504001
504002
505001
505002
505003
505004
505005
505006
505007
506001
507001
507002
Messages 602101 to 609002
602101
602102
602201
602202
602203
602301
602302
602303
602304
604101
604102
604103
604104
605005
606001
606002
606003
606004
607001
608001
609001
609002
610001
610002
610101
612001
612002
612003
613001
613002
613003
614001
614002
615001
615002
616001
617001
617002
617003
617004
620001
620002
621001
621002
621003
621006
621007
Messages 701001 to 720073
701001
701002
702201
702202
702203
702204
702205
702206
702207
702208
702209
702210
702211
702212
702301
702302
702303
703001
703002
709001, 709002
709003
709004
709005
709006
709007
710001
710002
710003
710004
710005
710006
711001
711002
711003
713004
713006
713008
713009
713010
713012
713014
713016
713017
713018
713020
713022
713024
713025
713026
713027
713028
713029
713030
713031
713032
713033
713034
713035
713036
713037
713039
713040
713041
713042
713043
713047
713048
713049
713050
713051
713052
713056
713059
713060
713061
713062
713063
713065
713066
713068
713072
713073
713074
713075
713076
713078
713081
713082
713083
713084
713085
713086
713088
713092
713094
713098
713099
713102
713103
713104
713105
713107
713109
713112
713113
713114
713115
713116
713117
713118
713119
713120
713121
713122
713123
713124
713127
713128
713129
713130
713131
713132
713133
713134
713135
713136
713137
713138
713139
713140
713141
713142
713143
713144
713145
713146
713147
713148
713149
713152
713154
713155
713156
713157
713158
713159
713160
713161
713162
713163
713164
713165
713166
713167
713168
713169
713170
713171
713172
713174
713176
713177
713178
713179
713182
713184
713185
713186
713187
713189
713190
713193
713194
713195
713196
713197
713198
713199
713203
713204
713205
713206
713208
713209
713210
713211
713212
713213
713214
713215
713216
713217
713218
713219
713220
713221
713222
713223
713224
713225
713226
713229
713236
713229
: 713900
713901
713902
713903
713904
713905
713906
714001
714002
714003
714004
714005
714006
714007
714011
715001
715004
715005
715006
715007
715008
715009
715013
715019
715020
715021
715022
715027
715028
715033
715034
715035
715036
715037
715038
715039
715040
715041
715042
715044
715045
715046
715047
715048
715049
715050
715051
715052
715053
715054
715055
715056
715057
715058
715059
715060
715061
715062
715063
715064
715065
715066
715067
715068
715069
715070
715071
715072
715074
715075
715076
715077
717001
717002
717003
717004
717005
717006
717007
717008
717009
717010
717011
717012
717013
717014
717015
717016
717017
717018
717019
717022
717025
717028
717029
718001
718002
718003
718004
718005
718006
718007
718008
718009
718010
718011
718012
718013
718014
718015
718016
718017
718018
718019
718020
718021
718022
718023
718024
718025
718026
718027
718028
718029
718030
718031
718032
718033
718034
718035
718036
718037
718038
718039
718040
718041
718042
718043
718044
718045
718046
718047
718048
718049
718050
718051
718052
718053
718054
718055
718056
718057
718058
718059
718060
718061
718062
718063
718064
718065
718066
718067
718068
718069
718070
718071
718072
718073
718074
718075
718076
718077
718078
718079
718080
718081
718084
718085
718086
718087
718088
719001
719002
719003
719004
719005
719006
719007
719008
719009
719010
719011
719012
719013
719014
719015
719016
719025
719026
720001
720002
720003
720004
720005
720006
720007
720008
720009
720010
720011
720012
720013
720014
720015
720016
720017
720018
720019
720020
720021
720022
720023
720024
720025
720026
720027
720028
720029
720030
720031
720032
720033
720034
720035
720036
720037
720038
720039
720040
720041
720042
720043
720044
720045
720046
720047
720048
720049
720050
720051
720052
720053
720054
720055
720056
720057
720058
720059
720060
720061
720062
720063
720064
720065
720066
720067
720068
720069
720070
720071
720072
720073
System Log Messages
This chapter lists the FWSM system log messages. The messages are listed numerically by message code.
Note
The messages shown in this guide apply to software Version 3.1and higher. When a number is skipped from a sequence, the message is no longer in the security appliance code.
This chapter includes the following sections:
•
Messages 102001 to 199009
•
Messages 201002 to 217001
•
Messages 302003 to 326028
•
Messages 400000 to 418001
•
Messages 500001 to 507002
•
Messages 602101 to 609002
•
Messages 701001 to 720073
Messages 102001 to 199009
This section contains messages from 102001 to 199009.
102001
Error Message %FWSM-1-102001: (Primary) Power failure/System reload other side.
Explanation This is a failover message. This message is logged if the primary unit detects a system
reload or a power failure on the other unit. "Primary" can also be listed as "Secondary" for the
secondary unit.
Recommended Action On the unit that experienced the reload, issue the show crashinfo command to
determine if there is a traceback associated with the reload. Also verify that the unit is powered on
and that power cables are properly connected.
103002
Error Message %FWSM-1-103002: (Primary) Other firewall network interface
interface_number OK.
Explanation This is a failover message. This message is displayed when the primary unit detects that
the network interface on the secondary unit is okay. (Primary) can also be listed as (Secondary) for
the secondary unit. Refer to Table 1-4 in Configuring Logging and SNMP for possible values for the
interface_number variable.
Recommended Action None required.
103003
Error Message %FWSM-1-103003: (Primary) Other firewall network interface
interface_number failed.
Explanation This is a failover message. This message is displayed if the primary unit detects a bad
network interface on the secondary unit. (Primary) can also be listed as (Secondary) for the
secondary unit.
Recommended Action Check the network connections on the secondary unit and check the network
hub connection. If necessary, replace the failed network interface.
103004
Error Message %FWSM-1-103004: (Primary) Other firewall reports this firewall failed.
Explanation This is a failover message. This message is displayed if the primary unit receives a
message from the secondary unit indicating that the primary has failed. (Primary) can also be listed
as (Secondary) for the secondary unit.
Recommended Action Verify the status of the primary unit.
103005
Error Message %FWSM-1-103005: (Primary) Other firewall reporting failure.
Explanation This is a failover message. This message is displayed if the secondary unit reports a
failure to the primary unit. (Primary) can also be listed as (Secondary) for the secondary unit.
Recommended Action Verify the status of the secondary unit.
103006
Error Message %FWSM-1-103006: (Primary|Secondary) Mate version ver_num is not
compatible with ours ver_num
Explanation This message appears when the FWSM detects a peer unit that is running a different
version from the local unit and is not compatible with the HA Hitless Upgrade feature.
•
ver_num—Version number.
Recommended Action Install the same or a compatible version image on both firewall units.
103007
Error Message %FWSM-1-103007: (Primary|Secondary) Mate version ver_num is not
identical with ours ver_num
Explanation This message appears when the FWSM detects a peer unit that is running a different (yet
compatible) version from the local unit, but does support the HA Hitless Upgrade feature. The
system performance could be degraded because the image version is not the same and you may
encounter a stability issue if you run this version for an extended period.
•
ver_num—Version number.
Recommended Action Install the same version image on both firewall units as soon as possible.
104001, 104002
Error Message %FWSM-1-104001: (Primary) Switching to ACTIVE (cause: string).
Error Message %FWSM-1-104002: (Primary) Switching to STNDBY (cause: string).
Explanation Both instances are failover messages. These messages usually are logged when you
force the pair to switch roles, either by entering the failover active command on the standby unit,
or the no failover active command on the active unit. (Primary) can also be listed as (Secondary)
for the secondary unit. Possible values for the string variable are as follows:
•
state check
•
bad/incomplete config
•
ifc [interface] check, mate is healthier
•
the other side wants me to standby
•
in failed state, cannot be active
•
switch to failed state
Recommended Action If the message occurs because of manual intervention, no action is required.
Otherwise, use the cause reported by the secondary unit to verify the status of both units of the pair.
104003
Error Message %FWSM-1-104003: (Primary) Switching to FAILED.
Explanation This is a failover message. This message is displayed when the primary unit fails.
Recommended Action Check the system log messages for the primary unit for an indication of the
nature of the problem (see message 104001). (Primary) can also be listed as (Secondary) for the
secondary unit.
104004
Error Message %FWSM-1-104004: (Primary) Switching to OK.
Explanation This is a failover message. This message is displayed when a previously failed unit now
reports that it is operating again. (Primary) can also be listed as (Secondary) for the secondary unit.
Recommended Action None required.
105001
Error Message %FWSM-1-105001: (Primary) Disabling failover.
Explanation This is a failover message. This message is displayed when you enter the no failover
command on the console. (Primary) can also be listed as (Secondary) for the secondary unit.
Recommended Action None required.
105002
Error Message %FWSM-1-105002: (Primary) Enabling failover.
Explanation This is a failover message. This message is displayed when you enter the failover
command with no arguments on the console, after having previously disabled failover. (Primary) can
also be listed as (Secondary) for the secondary unit.
Recommended Action None required.
105003
Error Message %FWSM-1-105003: (Primary) Monitoring on interface interface_name
waiting
Explanation This is a failover message. The security appliance is testing the specified network
interface with the other unit of the failover pair. (Primary) can also be listed as (Secondary) for the
secondary unit.
Recommended Action None required. The security appliance monitors its network interfaces
frequently during normal operations.
105004
Error Message %FWSM-1-105004: (Primary) Monitoring on interface interface_name
normal
Explanation This is a failover message. The test of the specified network interface was successful.
(Primary) can also be listed as (Secondary) for the secondary unit.
Recommended Action None required.
105005
Error Message %FWSM-1-105005: (Primary) Lost Failover communications with mate on
interface interface_name.
Explanation This is a failover message. This message is displayed if this unit of the failover pair can
no longer communicate with the other unit of the pair. (Primary) can also be listed as (Secondary)
for the secondary unit.
Recommended Action Verify that the network connected to the specified interface is functioning
correctly.
105006, 105007
Error Message %FWSM-1-105006: (Primary) Link status `Up' on interface
interface_name.
Error Message %FWSM-1-105007: (Primary) Link status `Down' on interface
interface_name.
Explanation Both instances are failover messages. These messages report the results of monitoring
the link status of the specified interface. (Primary) can also be listed as (Secondary) for the
secondary unit.
Recommended Action If the link status is down, verify that the network connected to the specified
interface is operating correctly.
105008
Error Message %FWSM-1-105008: (Primary) Testing interface interface_name.
Explanation This is a failover message. This message is displayed when the tests a specified network
interface. This testing is performed only if the security appliance fails to receive a message from the
standby unit on that interface after the expected interval. (Primary) can also be listed as (Secondary)
for the secondary unit.
Recommended Action None required.
105010
Error Message %FWSM-3-105010: (Primary) Failover message block alloc failed
Explanation Block memory was depleted. This is a transient message and the security appliance
should recover. (Primary) can also be listed as (Secondary) for the secondary unit.
Recommended Action Use the show blocks command to monitor the current block memory.
105020
Error Message %FWSM-1-105020: (Primary) Incomplete/slow config replication
Explanation When a failover occurs, the active security appliance detects a partial configuration in
memory. Normally, this is caused by an interruption in the replication service. (Primary) can also be
listed as (Secondary) for the secondary unit.
Recommended Action Once the failover is detected by the security appliance, the security appliance
automatically reloads itself and loads configuration from Flash memory and/or resynchronizes with
another security appliance. If failovers happen continuously, check the failover configuration and
make sure both security appliance units can communicate with each other.
105021
Error Message %FWSM-1-105021: (failover_unit) Standby unit failed to sync due to a
locked context_name config. Lock held by lock_owner_name
Explanation During configuration synchronizing, a standby unit will reload itself if some other
process locks the configuration for more than 5 minutes, which prevents the failover process from
applying the new configuration. This can occur when an administrator pages through a running
configuration on the standby unit while configuration synchronization is in process. See also the
show running-config EXEC command and the pager lines num CONFIG command.
Recommended Action Avoid viewing or modifying configuration on standby unit when it first comes
up and is in the process of establishing a failover connection with the active unit.
105031
Error Message %FWSM-1-105031: Failover LAN interface is up
Explanation LAN failover interface link is up.
Recommended Action None required.
105032
Error Message %FWSM-1-105032: LAN Failover interface is down
Explanation LAN failover interface link is down.
Recommended Action Check the connectivity of the LAN failover interface. Make sure that the
speed/duplex setting is correct.
105034
Error Message %FWSM-1-105034: Receive a LAN_FAILOVER_UP message from peer.
Explanation The peer has just booted and sent the initial contact message.
Recommended Action None required.
105035
Error Message %FWSM-1-105035: Receive a LAN failover interface down msg from peer.
Explanation The peer LAN failover interface link is down. The unit switches to active mode if it is
in standby mode.
Recommended Action Check the connectivity of the peer LAN failover interface.
105038
Error Message %FWSM-1-105038: (Primary) Interface count mismatch
Explanation When a failover occurs, the active security appliance detects a partial configuration in
memory. Normally, this is caused by an interruption in the replication service. (Primary) can also be
listed as (Secondary) for the secondary unit.
Recommended Action Once the failover is detected by the security appliance, the security appliance
automatically reloads itself and loads the configuration from Flash memory and/or resyncs with
another security appliance. If failovers happen continuously, check the failover configuration and
make sure that both security appliance units can communicate with each other.
105039
Error Message %FWSM-1-105039: (Primary) Unable to verify the Interface count with
mate. Failover may be disabled in mate.
Explanation Failover initially verifies that the number of interfaces configured on the primary and
secondary security appliances are the same. This message indicates that the primary security
appliance is not able to verify the number of interfaces configured on the secondary security
appliance. This message indicates that the primary security appliance is not able communicate with
the secondary security appliance over the failover interface. (Primary) can also be listed as
(Secondary) for the secondary security appliance.
Recommended Action Verify the failover LAN, interface configuration, and status on the primary and
secondary security appliances. Make sure that the secondary security appliance is running the
security appliance application and that failover is enabled.
105040
Error Message %FWSM-1-105040: (Primary) Mate failover version is not compatible.
Explanation The primary and secondary security appliance should run the same failover software
version to act as a failover pair. This message indicates that the secondary security appliance failover
software version is not compatible with the primary security appliance. Failover is disabled on the
primary security appliance. (Primary) can also be listed as (Secondary) for the secondary security
appliance.
Recommended Action Maintain consistent software versions between the primary and secondary
security appliances to enable failover.
105042
Error Message %FWSM-1-105042: (Primary) Failover interface OK
Explanation LAN failover interface link is up.
Explanation The interface used to send failover messages to the secondary security appliance is
functioning. (Primary) can also be listed as (Secondary) for the secondary security appliance.
Recommended Action None required.
105043
Error Message %FWSM-1-105043: (Primary) Failover interface failed
Explanation LAN failover interface link is down.
Recommended Action Check the connectivity of the LAN failover interface. Make sure that the
speed/duplex setting is correct.
105044
Error Message %FWSM-1-105044: (Primary) Mate operational mode mode is not compatible
with my mode mode.
Explanation When the operational mode (single or multi) does not match between failover peers,
failover will be disabled.
Recommended Action Configure the failover peers to have the same operational mode, and then
reenable failover.
105045
Error Message %FWSM-1-105045: (Primary) Mate license (number contexts) is not
compatible with my license (number contexts).
Explanation When the feature licenses do not match between failover peers, failover will be disabled.
Recommended Action Configure the failover peers to have the same feature license, and then reenable
failover.
105046
Error Message %FWSM-1-105046 (Primary|Secondary) Mate has a different chassis
Explanation This message is issued when two failover units have a different type of chassis.
Recommended Action Make sure that the two failover units are the same.
105047
Error Message %FWSM-1-105047: Mate has a io_card_name1 card in slot slot_number
which is different from my io_card_name2
Explanation The two failover units have different types of cards in their respective slots.
Recommended Action Make sure that the card configurations for the failover units are the same.
106001
Error Message %FWSM-2-106001: Inbound TCP connection denied from IP_address/port to
IP_address/port flags tcp_flags on interface interface_name
Explanation This is a connection-related message. This message occurs when an attempt to connect
to an inside address is denied by your security policy. Possible tcp_flags values correspond to the
flags in the TCP header that were present when the connection was denied. For example, a TCP
packet arrived for which no connection state exists in the security appliance, and it was dropped.
The tcp_flags in this packet are FIN and ACK.
The tcp_flags are as follows:
•
ACK—The acknowledgment number was received.
•
FIN—Data was sent.
•
PSH—The receiver passed data to the application.
•
RST—The connection was reset.
•
SYN—Sequence numbers were synchronized to start a connection.
•
URG—The urgent pointer was declared valid.
Recommended Action None required.
106002
Error Message %FWSM-2-106002: protocol Connection denied by outbound list acl_ID src
inside_address dest outside_address
Explanation This is a connection-related message. This message is displayed if the specified
connection fails because of an outbound deny command. The protocol variable can be ICMP, TCP,
or UDP.
Recommended Action Use the show outbound command to check outbound lists.
106006
Error Message %FWSM-2-106006: Deny inbound UDP from outside_address/outside_port to
inside_address/inside_port on interface interface_name.
Explanation This is a connection-related message. This message is displayed if an inbound UDP
packet is denied by your security policy.
Recommended Action None required.
106007
Error Message %FWSM-2-106007: Deny inbound UDP from outside_address/outside_port to
inside_address/inside_port due to DNS {Response|Query}.
Explanation This is a connection-related message. This message is displayed if a UDP packet
containing a DNS query or response is denied.
Recommended Action If the inside port number is 53, the inside host probably is set up as a caching
name server. Add an access-list command statement to permit traffic on UDP port 53. If the outside
port number is 53, a DNS server was probably too slow to respond, and the query was answered by
another server.
106010
Error Message %FWSM-3-106010: Deny inbound protocol src
interface_name:dest_address/dest_port dst
interface_name:source_address/source_port
Explanation This is a connection-related message. This message is displayed if an inbound
connection is denied by your security policy.
Recommended Action Modify the security policy if traffic should be permitted. If the message occurs
at regular intervals, contact the remote peer administrator.
106011
Error Message %FWSM-3-106011: Deny inbound (No xlate) string
Explanation The message will appear under normal traffic conditions if there are internal users that
are accessing the Internet through a web browser. Any time a connection is reset, when the host at
the end of the connection sends a packet after the security appliance receives the reset, this message
will appear. It can typically be ignored.
Recommended Action Prevent this system log message from getting logged to the syslog& server by
entering the no logging message 106011 command.
106012
Error Message %FWSM-6-106012: Deny IP from IP_address to IP_address, IP options hex.
Explanation This is a packet integrity check message. An IP packet was seen with IP options. Because
IP options are considered a security risk, the packet was discarded.
Recommended Action Contact the remote host system administrator to determine the problem. Check
the local site for loose source routing or strict source routing.
106013
Error Message %FWSM-2-106013: Dropping echo request from IP_address to PAT address
IP_address
Explanation The security appliance discarded an inbound ICMP Echo Request packet with a
destination address that corresponds to a PAT global address. The inbound packet is discarded
because it cannot specify which PAT host should receive the packet.
Recommended Action None required.
106014
Error Message %FWSM-3-106014: Deny inbound icmp src interface_name: IP_address dst
interface_name: IP_address (type dec, code dec)
Explanation The security appliance denied any inbound ICMP packet access. By default, all ICMP
packets are denied access unless specifically permitted.
Recommended Action None required.
106015
Error Message %FWSM-6-106015: Deny TCP (no connection) from IP_address/port to
IP_address/port flags tcp_flags on interface interface_name.
Explanation The security appliance discarded a TCP packet that has no associated connection in the
security appliance connection table. The security appliance looks for a SYN flag in the packet,
which indicates a request to establish a new connection. If the SYN flag is not set, and there is not
an existing connection, the security appliance discards the packet.
Recommended Action None required unless the security appliance receives a large volume of these
invalid TCP packets. If this is the case, trace the packets to the source and determine the reason these
packets were sent.
106016
Error Message %FWSM-2-106016: Deny IP spoof from (IP_address) to IP_address on
interface interface_name.
Explanation The security appliance discarded a packet with an invalid source address. Invalid source
addresses are those addresses belonging to the following:
•
Loopback network (127.0.0.0)
•
Broadcast (limited, net-directed, subnet-directed, and all-subnets-directed)
•
The destination host (land.c)
To further enhance spoof packet detection, use the conduit command to configure the security appliance to discard packets with source addresses belonging to the internal network. Now that the icmp command has been implemented, the conduit command has been deprecated and is no longer guaranteed to work properly.
Recommended Action Determine if an external user is trying to compromise the protected network.
Check for misconfigured clients.
106017
Error Message %FWSM-2-106017: Deny IP due to Land Attack from IP_address to IP_address
Explanation The security appliance received a packet with the IP source address equal to the IP
destination, and the destination port equal to the source port. This message indicates a spoofed
packet that is designed to attack systems. This attack is referred to as a Land Attack.
Recommended Action If this message persists, an attack may be in progress. The packet does not
provide enough information to determine where the attack originates.
106018
Error Message %FWSM-2-106018: ICMP packet type ICMP_type denied by outbound list
acl_ID src inside_address dest outside_address
Explanation The outgoing ICMP packet with the specified ICMP from local host (inside_address) to
the foreign host (outside_address) was denied by the outbound ACL list.
Recommended Action None required.
106020
Error Message %FWSM-2-106020: Deny IP teardrop fragment (size = number, offset =
number) from IP_address to IP_address
Explanation The security appliance discarded an IP packet with a teardrop signature containing
either a small offset or fragment overlapping. This is a hostile event that circumvents the security
appliance or an Intrusion Detection System.
Recommended Action Contact the remote peer administrator or escalate this issue according to your
security policy.
106021
Error Message %FWSM-1-106021: Deny protocol reverse path check from source_address
to dest_address on interface interface_name
Explanation An attack is in progress. Someone is attempting to spoof an IP address on an inbound
connection. Unicast RPF, also known as reverse route lookup, detected a packet that does not have
a source address represented by a route and assumes that it is part of an attack on your security
appliance.
This message appears when you have enabled Unicast RPF with the ip verify reverse-path command. This feature works on packets input to an interface; if it is configured on the outside, then the security appliance checks packets arriving from the outside.
The security appliance looks up a route based on the source_address. If an entry is not found and a route is not defined, then this system log message appears and the connection is dropped.
If there is a route, the security appliance checks which interface it corresponds to. If the packet arrived on another interface, it is either a spoof or there is an asymmetric routing environment that has more than one path to a destination. The security appliance does not support asymmetric routing.
If the security appliance is configured on an internal interface, it checks static route command statements or RIP, and if the source_address is not found, then an internal user is spoofing their address.
Recommended Action Even though an attack is in progress, if this feature is enabled, no user action
is required. The security appliance repels the attack.
106022
Error Message %FWSM-1-106022: Deny protocol connection spoof from source_address to
dest_address on interface interface_name
Explanation A packet matching a connection arrives on a different interface from the interface that
the connection began on.
For example, if a user starts a connection on the inside interface, but the security appliance detects the same connection arriving on a perimeter interface, the security appliance has more than one path to a destination. This is known as asymmetric routing and is not supported on the security appliance.
An attacker also might be attempting to append packets from one connection to another as a way to break into the security appliance. In either case, the security appliance displays this message and drops the connection.
Recommended Action This message appears when the ip verify reverse-path command is not
configured. Check that the routing is not asymmetric.
106023
Error Message %FWSM-4-106023: Deny protocol src
[interface_name:source_address/source_port] dst
interface_name:dest_address/dest_port [type {string}, code {code}] by
access_group acl_ID
Explanation An IP packet was denied by the ACL. This message displays even if you do not have the
log option enabled for an extended ACL.
Recommended Action If messages persist from the same source address, messages might indicate a
foot-printing or port-scanning attempt. Contact the remote host administrators.
106024
Error Message %FWSM-2-106024: Access rules memory exhausted
Explanation The access list compilation process has run out of memory. All configuration
information that has been added since the last successful access list was removed from the system,
and the most recently compiled set of access lists will continue to be used.
Recommended Action Access lists, AAA, ICMP, SSH, Telnet, and other rule types are stored and
compiled as access list rule types. Remove some of these rule types so that others can be added.
106025, 106026
Error Message %FWSM-6-106025: Failed to determine the security context for the
packet:sourceVlan:source_address dest_address source_port dest_port protocol
Error Message %FWSM-6-106026: Failed to determine the security context for the
packet:sourceVlan:source_address dest_address source_port dest_port protocol
Explanation The security context of the packet in multiple context mode cannot be determined. Both
messages can be generated for IP packets being dropped in either router and transparent mode.
Recommended Action None required.
106027
Error Message %FWSM-4-106027:Failed to determine the security context for the
packet:vlansource Vlan#:ethertype src sourceMAC dst destMAC
Explanation The security context of the packet in multiple context mode cannot be determined. This
message is generated for non-IP packets being dropped in transparent mode only.
Recommended Action None required.
106100
Error Message %FWSM-4-106100: access-list acl_ID {permitted | denied | est-allowed}
protocol interface_name/source_address(source_port) ->
interface_name/dest_address(dest_port) hit-cnt number ({first hit |
number-second interval})
Explanation If you configured the log option for the access-list command, the packets matched an
ACL statement. The message level depends on the level set in the access-list command. The
message indicates either the initial occurrence or the total number of occurrences during an interval.
This message provides more information than message 106027, which only logs denied non-IP
packets, and does not include the hit count or a configurable level. The following list describes the
message values:
•
permitted | denied | est-allowed —These values specify if the packet was permitted or denied by the ACL. If the value is est-allowed, the packet was denied by the ACL but was allowed for an already established session (for example, an internal user is allowed to accesss the Internet, and responding packets that would normally be denied by the ACL are accepted).
•
protocol—TCP, UDP, ICMP, or an IP protocol number.
•
interface_name—The interface name for the source or destination of the logged flow. The VLAN interfaces are supported.
•
source_address—The source IP address of the logged flow.
•
dest_address—The destination IP address of the logged flow.
•
source_port—The source port of the logged flow (TCP or UDP). For ICMP, this field is 0.
•
dest_port—The destination port of the logged flow (TCP or UDP). For ICMP, this field is icmp-type.
•
hit-cnt number—The number of times this flow was permitted or denied by this ACL entry in the configured time interval. The value is 1 when the security appliance generates the first system log message for this flow.
•
first hit—The first message generated for this flow.
•
number-second interval—The interval in which the hit count is accumulated. Set this interval using the access-list command with the interval option.
Recommended Action None required.
106101