Messages Listed by Severity Level

This appendix contains the following sections:


Note


The ASA does not send severity 0, emergency messages to the syslog server. These are analogous to a UNIX panic message, and denote an unstable system.


Alert Messages, Severity 1

The following messages appear at severity 1, alerts:


Note


The security event syslog messages (430001, 430002, 430003, 430004, 430005, and 430006) appear with varied severity levels depending on the nature of the event. For information on the messages and fields, see Security Event Syslog Message ID in the Cisco Secure Firewall Threat Defense Syslog Messages Guide .


  • %ASA-1-101001: (Primary) Failover cable OK.

  • %ASA-1-101002: (Primary) Bad failover cable.

  • %ASA-1-101003: (Primary) Failover cable not connected (this unit)

  • %ASA-1-101004: (Primary) Failover cable not connected (other unit).

  • %ASA-1-101005: (Primary) Error reading failover cable status.

  • %ASA-1-103001: (Primary) No response from other firewall (reason code = code).

  • %ASA-1-103002: (Primary) Other firewall network interface interface_number OK.

  • %ASA-1-103003: (Primary) Other firewall network interface interface_number failed.

  • %ASA-1-103004: (Primary) Other firewall reports this firewall failed. reason-string

  • %ASA-1-103005: (Primary) Other firewall reporting failure. Reason: SSM card failure

  • %ASA-1-103006: (Primary|Secondary) Mate version ver_num is not compatible with ours ver_num.

  • %ASA-1-103007: (Primary|Secondary) Mate version ver_num is not identical with ours ver_num.

  • %ASA-1-103008: host Mate hwdib index Idx is not identical with ours.

  • %ASA-1-104001: (Primary) Switching to ACTIVE - string.

  • %ASA-1-104002: (Primary) Switching to STANDBY (cause: string).

  • %ASA-1-104003: (Primary) Switching to FAILED.

  • %ASA-1-104004: (Primary) Switching to OK.

  • %ASA-1-104501: (Primary|Secondary) Switching to BACKUP - switch reason: reason

  • %ASA-1-104501: (Primary|Secondary) Switching to BACKUP - switch reason: reason

  • %ASA-1-104502: (Primary|Secondary) Becoming Backup unit failed

  • %ASA-1-105001: (Primary) Disabling failover.

  • %ASA-1-105002: (Primary) Enabling failover.

  • %ASA-1-105003: (Primary) Monitoring on interface interface_name waiting

  • %ASA-1-105004: (Primary) Monitoring on interface interface_name normal

  • %ASA-1-105005: (Primary) Lost Failover communications with mate on interface interface_name

  • %ASA-1-105006: (Primary) Link status 'Up' on interface interface_name

  • %ASA-1-105007: (Primary) Link status Down on interface interface_name.

  • %ASA-1-105008: (Primary) Testing Interface interface_name

  • %ASA-1-105009: (Primary) Testing on interface interface_name {Passed|Failed}

  • %ASA-1-105011: (Primary) Failover cable communication failure

  • %ASA-1-105020: (Primary) Incomplete/slow config replication

  • %ASA-1-105021: (failover_unit) Standby unit failed to sync due to a locked context_name config. Lock held by lock_owner_name

  • %ASA-1-105022: (host) Config replication failed with reason = reason

  • %ASA-1-105031: Failover LAN interface is up.

  • %ASA-1-105032: LAN Failover interface is down.

  • %ASA-1-105033: LAN FO cmd Iface down and up again.

  • %ASA-1-105034: Receive a LAN_FAILOVER_UP message from peer.

  • %ASA-1-105035: Receive a LAN failover interface down msg from peer.

  • %ASA-1-105036: dropped a LAN Failover command message.

  • %ASA-1-105037: (Primary and Standby ) Both units are switching back and forth as the active unit

  • %ASA-1-105038: (Primary) Interface count mismatch

  • %ASA-1-105039: (Primary) Unable to verify the Interface count with mate. Failover may be disabled in mate.

  • %ASA-1-105040: (Primary) Mate failover version is not compatible.

  • %ASA-1-105041: cmd failed during sync.

  • %ASA-1-105042: (Primary) Failover interface OK

  • %ASA-1-105043: (Primary) Failover interface failed

  • %ASA-1-105044: (Primary) Mate operational mode (mode) is not compatible with my mode (mode).

  • %ASA-1-105045: (Primary) Mate license (number contexts) is not compatible with my license (number contexts).

  • %ASA-1-105046: (Primary|Secondary) Mate has a different chassis

  • %ASA-1-105047: (host) Mate has a card_name1 card in slot slot_number which is different with my card_name2.

  • %ASA-1-105048: (unit) Mate's service module (application) is different from mine (application).

  • %ASA-1-105502: (Primary|Secondary) Restarting Cloud HA on this unit, reason: string

  • %ASA-1-106021: Deny protocol reverse path check from source_address to dest_address on interface interface_name

  • %ASA-1-106022: Deny protocol connection spoof from source_address to dest_address on interface interface_name

  • %ASA-1-106101: Number of cached deny-flows for ACL log has reached limit (number)

  • %ASA-1-107001: RIP auth failed from IP_address: version=number, type=string, mode=string, sequence=number on interface interface_name

  • %ASA-1-107002: RIP pkt failed from IP_address: version=number on interface interface_name

  • %ASA-1-111111 error_message.

  • %ASA-1-114001: Failed to initialize card-type I/O card due to error_string.

  • %ASA-1-114002: Failed to initialize SFP in card-type I/O card due to error_string.

  • %ASA-1-114003: Failed to run cached commands in card-type I/O card due to error_string.

  • %ASA-1-1199012: Stack smash during new_stack_call in process/fiber process/fiber, call target f, stack size s, process/fiber name of the process/fiber that caused the stack smash.

  • %ASA-1-199010: Signal number caught in process/fiber (rtcli_async_executor_process)/(rtcli_async_executor) at address ip_address, corrective action at ip_address

  • %ASA-1-199012: Stack overflow during new_stack_call in process/fiber process_name/fiber_name, call target f, stack size s

  • %ASA-1-199013: syslog.

  • %ASA-1-199021: System memory utilization has reached the configured threshold of Y%%. System will now reload.

  • %ASA-1-211004: WARNING: Minimum Memory Requirement for device version ver not met. min MB required, actual MB found.

  • %ASA-n-216001: internal error in: function: message

  • %ASA-1-216005: ERROR: Duplex-mismatch on interface_name resulted in transmitter lockup. A soft reset of the switch was performed.

  • %ASA-1-323006: Module ips experienced a data channel communication failure, data channel is DOWN.

  • %ASA-1-332004: Web Cache IP_address/service_ID lost

  • %ASA-1-413007: An unsupported configuration is detected. The combination of an mpc_description with ips_description is not supported.

  • %ASA-1-413008: An unsupported configuration is detected.

  • %ASA-1-505011: Module ips data channel communication is UP.

  • %ASA-1-505014: Module module_id, application down "name", version "version" reason

  • %ASA-1-505015: Module module_id, application up "application", version "ver_num" version

  • %ASA-1-709003: (Primary) Beginning configuration replication: Send to mate.

  • %ASA-1-709004: (Primary) End Configuration Replication (ACT)

  • %ASA-1-709005: (Primary) Beginning configuration replication: Receiving from mate.

  • %ASA-1-709006: (Primary) End Configuration Replication (STB)

  • %ASA-1-713900: Descriptive_event_string.

  • %ASA-1-716507: Fiber scheduler has reached unreachable code. Cannot continue, terminating

  • %ASA-1-716508: Fiber scheduler is scheduling rotten fiber. Cannot continue, terminating

  • %ASA-1-716509: Fiber scheduler is scheduling alien fiber. Cannot continue, terminating

  • %ASA-1-716510: Fiber scheduler is scheduling finished fiber. Cannot continue, terminating

  • %ASA-1-716516: OCCAM has corrupted ROL array. Cannot continue, terminating

  • %ASA-1-716519: OCCAM has corrupted pool list. Cannot continue, terminating

  • %ASA-1-716528: Unexpected fiber scheduler error; possible out-of-memory condition

  • %ASA-1-717049: Local CA Server certificate is due to expire in number days and a replacement certificate is available for export.

  • %ASA-1-717054: The type certificate in the trustpoint tp name is due to expire in number days. Expiration date and time Subject Name subject name Issuer Name issuer name Serial Number serial number

  • %ASA-1-717055: The type certificate in the trustpoint tp name has expired. Expiration date and time Subject Name subject name Issuer Name issuer name Serial Number serial number

  • %ASA-1-735001 Cooling Fan var1: OK.

  • %ASA-1-735002 Cooling Fan var1: Failure Detected.

  • %ASA-1-735003 Power Supply var1: OK.

  • %ASA-1-735004 Power Supply var1: Failure Detected.

  • %ASA-1-735005 Power Supply Unit Redundancy OK.

  • %ASA-1-735006 Power Supply Unit Redundancy Lost.

  • %ASA-1-735007 CPU var1: Temp: var2 var3, Critical.

  • %ASA-1-735008 IPMI: Chassis Ambient var1: Temp: var2 var3, Critical.

  • %ASA-1-735011: Power Supply var1: Fan OK

  • %ASA-1-735012: Power Supply var1: Fan Failure Detected

  • %ASA-1-735013: Voltage Channel var1: Voltage OK

  • %ASA-1-735014: Voltage Channel var1: Voltage Critical

  • %ASA-1-735017: Power Supply var1: Temp: var2 var3, OK

  • %ASA-1-735020: CPU var1: Temp: var2 var3, OK

  • %ASA-1-735021: Chassis Ambient var1: Temp: var2 var3, OK

  • %ASA-1-735022: CPUnum is running beyond the max thermal operating temperature and the device will be shutting down immediately to prevent permanent damage to the CPU

  • %ASA-1-735024: CPUvar1 Voltage Regulator is running beyond the max thermal operating temperature and the device will be shutting down immediately. The chassis and CPU need to be inspected immediately for ventilation issues

  • %ASA-1-735025: var1 was previously shutdown due to a CPU Voltage Regulator running beyond the max thermal operating temperature. The chassis and CPU need to be inspected immediately for ventilation issues

  • %ASA-1-735027: CPU cpu_num Voltage Regulator is running beyond the max thermal operating temperature and the device will be shutting down immediately. The chassis and CPU need to be inspected immediately for ventilation issues.

  • %ASA-1-735029: IO Hub is running beyond the max thermal operating temperature and the device will be shutting down immediately to prevent permanent damage to the circuit

  • %ASA-1-743000: The PCI device with vendor ID: vendor_id device ID: device_id located at bus:device.function (hex) bus_num:dev_num.func_num has a link link_attr_name of actual_link_attr_val when it should have a link link_attr_name of expected_link_attr_val

  • %ASA-1-743001: Backplane health monitoring detected link failure

  • %ASA-1-743002: Backplane health monitoring detected link OK

  • %ASA-1-743004: System is not fully operational - The PCI device with vendor ID: vendor_id (vendor_name) device ID: device_id (device_name) could not be found in the system.

  • %ASA-1-770002: Resource resource allocation is more than the permitted limit of limit, Device will be rebooted

Critical Messages, Severity 2

The following messages appear at severity 2, critical:

  • %ASA-2-105506: (Primary|Secondary) Unable to create socket for port port for failover connection | load balancer probes, error: error_string

  • %ASA-2-105507: (Primary|Secondary) Unable to bind socket for port port for failover connection | load balancer probes, error: error_string

  • %ASA-2-105508: (Primary|Secondary) Error creating failover connection socket for port port\n

  • %ASA-2-105525: (Primary|Secondary) Incomplete configuration to initiate access token change request

  • %ASA-2-105526: (Primary|Secondary) Unexpected status in response to access token request: status (status_string)

  • %ASA-2-105527: (Primary|Secondary) Failure reading response to access token request

  • %ASA-2-105528: (Primary|Secondary) No access token in response to access token request

  • %ASA-2-105529: (Primary|Secondary) Error creating authentication header from access token

  • %ASA-2-105530: (Primary|Secondary) No response to access token request from url

  • %ASA-2-105531: (Primary|Secondary) Failed to obtain route-table information needed for change request for route-table route_table_name

  • %ASA-2-105532: (Primary|Secondary) Unexpected status in response to route-table change request for route-table route_table_name: status (status_string)

  • %ASA-2-105533: (Primary|Secondary) Failure reading response to route-table change request for route-table route_table_name

  • %ASA-2-105534: (Primary|Secondary) No provisioning state in response to route-table change request route-table route_table_name

  • %ASA-2-105535: (Primary|Secondary) No response to route-table change request for route-table route_table_name from url

  • %ASA-2-105536: (Primary|Secondary) Failed to obtain Azure authentication header for route status request for route route_name

  • %ASA-2-105537: (Primary|Secondary) Unexpected status in response to route state request for route route_name: status (status_string)

  • %ASA-2-105538: (Primary|Secondary) Failure reading response to route state request for route route_name

  • %ASA-2-105539: (Primary|Secondary) No response to route state request for route route_name from url

  • %ASA-2-105540: (Primary|Secondary) No route-tables configured

  • %ASA-2-105541: (Primary|Secondary) Failed to update route-table route_table_name, provisioning state: state_string

  • %ASA-2-105544: (Primary|Secondary) Error creating load balancer probe socket for port port

  • %ASA-2-106001: Inbound TCP connection denied from IP_addressportIP_addressporttcp_flagsinterface_name

  • %ASA-2-106002: protocol Connection denied by outbound list acl_ID src inside_address dest outside_address

  • %ASA-2-106006: Deny inbound UDP from outside_addressoutside_portinside_addressinside_portinterface_name

  • %ASA-2-106007: Deny inbound UDP from outside_addressoutside_portinside_addressinside_port{Response|Query}

  • %ASA-2-106013: Dropping echo request from IP_addressIP_address

  • %ASA-2-106016: Deny IP spoof from (ip_address) to ip_address on interface interface_name

  • %ASA-2-106017: Deny IP due to Land Attack from IP_addressIP_address

  • %ASA-2-106018: ICMP packet type ICMP_typeacl_IDinside_addressoutside_address

  • %ASA-2-106020: Deny IP teardrop fragment (size = numbernumberIP_addressIP_address

  • %ASA-2-106024: Access rules memory exhausted. Aborting current compilation and continuing to use the existing access rules

  • %ASA-2-108002: SMTP replaced stringsource_addressinside_addressstring

  • %ASA-2-108003: Terminating ESMTP connection; malicious pattern detected in the mail address from source_interfacesource_addresssource_portdest_interfacedest_addressdset_portstring

  • %ASA-2-109011: Authen Session Start: user 'usernumber

  • %ASA-2-112001: Clear finished

  • %ASA-2-113022: AAA Marking protocol server {IP_address | hostname} in aaa-server group tag as FAILED

  • %ASA-2-113023: AAA Marking protocolip-addrtag

  • %ASA-2-113027: Error activating tunnel-group scripts

  • %ASA-2-115000: Critical assertion in process: process name fiber: fiber name, component: component name, subcomponent: subcomponent name, file: filename, line: line number, cond: condition

  • %ASA-2-199011: Close on bad channel in process/fiber process_name/fiber_name, channel ID p, channel state channel_state

  • %ASA-2-199014: syslog

  • %ASA-2-199020: System memory utilization has reached X%. System will reload if memory usage reaches the configured trigger level of Y%.

  • %ASA-2-201003: Embryonic limit exceeded nconnselimitoutside_addressoutside_portinside_addressglobal_addressinside_portinterface_name

  • %ASA-2-214001: Terminating manager session from IP_addressinterface_namenumbernumber

  • %ASA-2-215001:Bad route_compress() call, sdb= number

  • %ASA-2-217001: No memory for string in string

  • %ASA-2-218001: Failed Identification Test in slot# [fail#/res].

  • %ASA-2-218002: Module slot#Cisco

  • %ASA-2-218003: Module Version in slot#slot#Cisco

  • %ASA-2-218004: Failed Identification Test in slot#fail#res

  • %ASA-2-218005: Inconsistency detected in the system information programmed in non-volatile memory.

  • %ASA-2-304007: URL Server not responding, ENTERING ALLOW mode

  • %ASA-2-304008: LEAVING ALLOW mode, URL Server is up

  • %ASA-2-321005: System CPU utilization reached utilization %

  • %ASA-2-321006: System Memory usage reached utilization %

  • %ASA-2-410002: Dropped numsecsrc_ifcsipsportdest_ifcdipdport

  • %ASA-2-444004: Timebased activation key xxxxxxxxxxxxxxxpermanent licensexxxxxxxxxxxxxxx

  • %ASA-2-444007: Timebased activation key xxxxxxxxxxxxxxx

  • %ASA-2-444009: license-type

  • %ASA-2-444102: Shared license service inactive. License server is not responding.

  • %ASA-2-444105: Released valuelicensetype

  • %ASA-2-444111: Shared license backup service has been terminated due to the primary license server addressdays

  • %ASA-2-444302: %SMART_LIC-2-PLATFORM_ERROR: Platform error.

  • %ASA-2-709007: Configuration replication failed for command command_name

  • %ASA-2-713078: Group = groupname, Username = username, IP = peerIP Temp buffer for building mode config attributes exceeded: bufsize available_size, used value

  • %ASA-2-713176: Device_type memory resources are critical, IKE key acquire message on interface interface_number, for Peer IP_address ignored

  • %ASA-2-713901: Descriptive_text_string.

  • %ASA-2-716500: Fiber library cannot locate AK47 instance

  • %ASA-2-716501: Fiber library cannot attach AK47 instance

  • %ASA-2-716502: Fiber library cannot allocate default arena

  • %ASA-2-716503: Fiber library cannot allocate fiber descriptors pool

  • %ASA-2-716504: Fiber library cannot allocate fiber stacks pool

  • %ASA-2-716505: Fiber has joined fiber in unfinished state

  • %ASA-2-716506: Fiber has joined fiber waited upon by someone else

  • %ASA-2-716512: Non-joinable fiber being destroyed has waiters

  • %ASA-2-716513: Fiber in callback blocked on other channel

  • %ASA-2-716515: OCCAM failed to allocate memory for AK47 instance

  • %ASA-2-716517: OCCAM cached block has no associated arena

  • %ASA-2-716518: OCCAM pool has no associated arena

  • %ASA-2-716520: OCCAM pool has no block list

  • %ASA-2-716521: OCCAM no realloc allowed in named pool

  • %ASA-2-716522: OCCAM corrupted standalone block

  • %ASA-2-716525: SAL private data changed after callback in close

  • %ASA-2-716526: WebVPN session load failed: Failure to attach to a configured permanent storage server

  • %ASA-2-716527: WebVPN session store failed: Failure to attach to a configured permanent storage server

  • %ASA-2-717008: Insufficient memory to process_requiring_memory.

  • %ASA-2-717011: Unexpected event: eventevent_ID

  • %ASA-2-717040: Local CA Server has failed and is being disabled. Reason: reason.

  • %ASA-2-735009: Environment Monitoring has failed initialization and configuration. Environment Monitoring is not running.

  • %ASA-2-735023: device

  • %ASA-2-735028: ASA was previously shutdown due to a CPU Voltage Regulator running beyond the max thermal operating temperature. The chassis and CPU need to be inspected immediately for ventilation issues.

  • %ASA-2-736001: Unable to allocate enough memory at boot for jumbo-frame reservation. Jumbo-frame support has been disabled.

  • %ASA-2-747009: Fatal error due to failure to creat RPC server for module module name

  • %ASA-2-747011: Memory allocation failure. Failed to allocate bytes

  • %ASA-2-748007: Failed to de-bundle the ports for module slot_number in chassis chassis_number; traffic may be black holed

  • %ASA-2-752001: Tunnel Manager received invalid parameter to remove record

  • %ASA-2-752005: Tunnel Manager failed to dispatch a KEY_ACQUIRE message. Memory may be low. Map Tag = mapTag . Map Sequence Number = mapSeq.

  • %ASA-2-772003: PASSWORD: sessionusernameip

  • %ASA-2-772006: REAUTH: user 'username

  • %ASA-2-774001: POST: unspecified error

  • %ASA-2-774002: POST: error 'errfuncengalgmodedirlen

  • %ASA-2-775007: Scansafe: No reachable servers found

  • %ASA-2-815002: Denied packet, hard limit, hard limit value, for object-group search exceeded for UDP from source:source IP address/port to destination:destination IP address/port

Error Messages, Severity 3

The following messages appear at severity 3, errors:

  • %ASA-3-105010: (Primary) Failover message block alloc failed

  • %ASA-3-105050: (host) Number of Ethernet interfaces on Standby unit (int_number) is less than number on Active unit (int_number).

  • %ASA-3-105052: HA cipher in use algorithm name strong encryption is AVAILABLE, please reboot to use strong cipher and preferably change the key in use.

  • %ASA-3-105509: (Primary|Secondary) Error sending message_name message to peer unit peer-ip, error: error_string

  • %ASA-3-105510: (Primary|Secondary) Error receiving message from peer unit peer-ip, error: error_string

  • %ASA-3-105511: (Primary|Secondary) Incomplete read of message header of message from peer unit peer-ip: bytes bytes read of expected header_length header byte

  • %ASA-3-105512: (Primary|Secondary) Error receiving message body of message from peer unit peer-ip, error: error_string

  • %ASA-3-105513: (Primary|Secondary) Incomplete read of message body of message from peer unit peer-ip: bytes bytes read of expected message_length message body bytes

  • %ASA-3-105514: (Primary|Secondary) Error occurred when responding to message_name message received from peer unit peer-ip, error: error_string

  • %ASA-3-105515: (Primary|Secondary) Error receiving message_name message from peer unit peer-ip, error: error_string

  • %ASA-3-105516: (Primary|Secondary) Incomplete read of message header of message_name message from peer unit peer-ip: bytes bytes read of expected header_length header bytes

  • %ASA-3-105517: (Primary|Secondary) Error receiving message body of message_name message from peer unit peer-ip, error: error_string

  • %ASA-3-105518: (Primary|Secondary) Incomplete read of message body of message_name message from peer unit peer-ip: bytes bytes read of expected message_length message body bytes

  • %ASA-3-105519: (Primary|Secondary) Invalid response to message_name message received from peer unit peer-ip: type message_type, version message_version, length message_length

  • %ASA-3-105545: (Primary|Secondary) Error starting load balancer probe socket for port port, error code: error_code

  • %ASA-3-105546: (Primary|Secondary) Error starting load balancer probe handler

  • %ASA-3-105547: (Primary|Secondary) Error generating encryption key for Azure secret key

  • %ASA-3-105548: (Primary|Secondary) Error storing encryption key for Azure secret key

  • %ASA-3-105549: (Primary|Secondary) Error retrieving encryption key for Azure secret key

  • %ASA-3-105550: (Primary|Secondary) Error encrypting Azure secret key

  • %ASA-3-105551: (Primary|Secondary) Error decrypting Azure secret key

  • %ASA-3-106010: Deny inbound protocolsrc [interface_name : source_address/source_port ] [([idfw_user | FQDN_string ], sg_info )] dst [interface_name : dest_address /dest_port }[([idfw_user | FQDN_string ], sg_info )]

  • %ASA-3-106011: Deny inbound (No xlate) protocol src Interface:IP/port dst Interface-nameif:IP/port

  • %ASA-3-106014: Deny inbound src

  • %ASA-3-109010: Auth from inside_addressinside_portoutside_addressoutside_portinterface_name

  • %ASA-3-109013: User must authenticate before using this service

  • %ASA-3-109016: Cannot find authorization ACL 'acl_id' on 'server_name' for user 'user'

  • %ASA-3-109018: Downloaded ACL 'acl_ID

  • %ASA-3-109019: Downloaded ACL 'acl_IDstringstring

  • %ASA-3-109020: Downloaded ACL has config error; ACE

  • %ASA-3-109023: User from source_addresssource_portdest_addressdest_portoutside_interfaceservice_name

  • %ASA-3-109026: [ aaa protocol

  • %ASA-3-109032: Unable to install ACL 'access_listusernameace

  • %ASA-3-109035: Exceeded maximum number (999) of DAP attribute instances for user = user

  • %ASA-3-109037: Exceeded 5000attribute nameusername

  • %ASA-3-109038: Attribute internal-attribute-namestring-from-servertype

  • %ASA-3-109103: CoA action-typecoa-source-ipusernameaudit-session-id

  • %ASA-3-109104: CoA (Action type: action-typecoa-source-ipusernameaudit-session-id

  • %ASA-3-109105: Failed to determine the egress interface for locally generated traffic destined to protocol IP:port.

  • %ASA-3-109203: UAUTH: Session=session, User=username, Assigned IP=IP Address, Failed adding entry.

  • %ASA-3-109205: UAUTH: Session=session, User=username, Assigned IP=IP Address, Failed applying filter.

  • %ASA-3-109206: UAUTH: Session=session, User=username, Assigned IP=IP Address, Removing stale entry added hours ago.

  • %ASA-3-109208: UAUTH: Session=session, User=username, Assigned IP=IP Address, Failed updating entry - no entry.

  • %ASA-3-109209: UAUTH: Session=session, User=username, Assigned IP=IP Address, Failed updating filter for entry. Entry was allocated to Session=session, User=username hours ago.

  • %ASA-3-109212: UAUTH: Session=session, User=user_name, Assigned IP=ip_address, Failed removing entry - reason_string.

  • %ASA-3-109213: UAUTH: Session=session, User=username, Assigned IP=IP Address, Failed removing entry. Address was allocated to Session=session, User=username hours ago.

  • %ASA-3-113001: Unable to open AAA session. Session limit [limit

  • %ASA-3-113018: User: 'userACL_entryaction

  • %ASA-3-113020: Kerberos error : Clock skew with server ip_addresstime in seconds

  • %ASA-3-113021: Attempted console login failed user 'username

  • %ASA-3-114006: Failed to get port statistics in card-typeerror_string

  • %ASA-3-114007: Failed to get current msr in card-typeerror_string

  • %ASA-3-114008: Failed to enable port after link is up in card-typeerror_string

  • %ASA-3-114009: Failed to set multicast address in card-typeerror_string

  • %ASA-3-114010: Failed to set multicast hardware address in card-typeerror_string

  • %ASA-3-114011: Failed to delete multicast address in card-typeerror_string

  • %ASA-3-114012: Failed to delete multicast hardware address in card-typeerror_string

  • %ASA-3-114013: Failed to set mac address table in card-typeerror_string

  • %ASA-3-114014: Failed to set mac address in card-typeerror_string

  • %ASA-3-114015: Failed to set mode in card-typeerror_string

  • %ASA-3-114016: Failed to set multicast mode in card-typeerror_string

  • %ASA-3-114017: Failed to get link status in card-typeerror_string

  • %ASA-3-114018: Failed to set port speed in card-typeerror_string

  • %ASA-3-114019: Failed to set media type in card-typeerror_string

  • %ASA-3-114020: Port link speed is unknown in 4GE SSM

  • %ASA-3-114021: Failed to set multicast address table in 4GE SSMerror

  • %ASA-3-114022: Failed to pass broadcast traffic in 4GE SSM I/O card due to error_string

  • %ASA-3-114023: Failed to cache/flush mac table in 4GE SSMerror_string

  • %ASA-3-115001: Error in process: process name fiber: fiber name, component: component name, subcomponent: subcomponent name, file: filename, line: line number, cond: condition.

  • %ASA-3-120010: Call-Home commandclientreason

  • %ASA-3-199015: syslog

  • %ASA-3-201002: Too many TCP connections on {static|xlate} global_address! econns nconns

  • %ASA-3-201004: Too many udp connections on {static|xlate}global_addressudp connections limit

  • %ASA-3-201005: FTP data connection failed for IP_address

  • %ASA-3-201006: RCMD backconnection failed for IP_addressport

  • %ASA-3-201008: Disallowing new connections.

  • %ASA-3-201009: TCPnumberIP_addressinterface_name

  • %ASA-3-201011: Connection limit exceeded cntlimitdirsipsportdipdportif_name

  • %ASA-3-201013: Per-client connection limit exceeded curr_num/limit for [input|output] packet from ip_address/port to ip_address/port on interface interface_name

  • %ASA-3-202001: Out of address translation slots!

  • %ASA-3-202005: Non-embryonic in embryonic list outside_addressoutside_portinside_addressinside_port

  • %ASA-3-202010: {NAT | PAT} pool exhausted in pool'pool_name' IP ip_addressport_range [1-511 | 512-1023 | 1024-65535] Unable to create protocol connection from inside_interface:src_ip/src_port to outside_interface:dest_ip/dest_port.

  • %ASA-3-202010: NAT/PAT pool exhausted in pool 'pool_name' IP ip_address. Unable to create connection.

  • %ASA-3-202016: Unable to pre-allocate SIP ip_protocol secondary channel for message from src_ifname:src_ip_addr/src_port to dst_ifname:dest_ip_addr/dest_port with PAT and missing port information.

  • %ASA-3-208005: Clear (commandcode

  • %ASA-3-210001: LU sw_module_namenumber

  • %ASA-3-210002: LU allocate block (bytes

  • %ASA-3-210003: Unknown LU Object number

  • %ASA-3-210005: LU allocate secondary(optional) connection failed for protocol[TCP|UDP] connection from ingress interface name:Real IP Address/Real Port to egress interface name:Real IP Address/Real Port

  • %ASA-3-210006: LU look NAT for IP_address

  • %ASA-3-210007: LU allocate xlate failed for typestaticdynamicNATPATsecondary(optional)protocolingress interface nameReal IP Addressreal portMapped IP AddressMapped Portegress interface nameReal IP Address

  • %ASA-3-210008: LU no xlate for inside_addressinside_portoutside_addressoutside_port

  • %ASA-3-210010: LU make UDP connection for outside_addressoutside_portinside_addressinside_port

  • %ASA-3-210020: LU PAT port port

  • %ASA-3-210021: LU create static xlate global_addressinterface_name

  • %ASA-3-211001: Memory allocation Error

  • %ASA-3-211003: Error in computed percentage CPU usage value

  • %ASA-3-212001: Unable to open SNMP channel (UDP port portinterface_numbercode

  • %ASA-3-212002: Unable to open SNMP trap channel (UDP port portinterface_numbercode

  • %ASA-3-212003: Unable to receive an SNMP request on interface "interface_numbercode

  • %ASA-3-212004: Unable to send an SNMP response to IP_addressport

  • %ASA-3-212005: incoming SNMP request (numberinterface_name

  • %ASA-3-212006: Dropping SNMP request from src_addrsrc_portifcdst_addrdst_portreasonusername

  • %ASA-3-212010: Configuration request for SNMP user ssreason

  • %ASA-3-212011: engineBoots is set to maximum value. Reason: Reason

  • %ASA-3-212012: Unable to write engine data to persistent storage.

  • %ASA-3-213001: PPTP control daemon socket io stringnumber

  • %ASA-3-213002: PPTP tunnel hashtable insert failed, peer = IP_address

  • %ASA-3-213003: PPP virtual interface interface_number

  • %ASA-3-213004: PPP virtual interface interface_number

  • %ASA-3-213005: Dynamic-Access-Policy action (DAP) action aborted

  • %ASA-3-213006: L2TP: Dynamic-Access-Policy failure

  • %ASA-3-216002: Unexpected event (major: major_id, minor: minor_id) received by task_string in function at line: line_num

  • %ASA-3-216003: Unrecognized timer timer_ptr, timer_id received by task_string in function at line: line_num

  • %ASA-3-219002: I2C_API_nameslot_numberdevice_numberaddresscountreason_string

  • %ASA-3-302019: H.323 library_namenumber

  • %ASA-3-302302: ACL = deny; no sa created

  • %ASA-3-304003: URL Server IP_addressurl

  • %ASA-3-304006: URL Server IP_address

  • %ASA-3-305005: No translation group found for protocol src interface_name: source_address/source_port [(idfw_user)] dst interface_nam: dest_address/dest_port [(idfw_user)]

  • %ASA-3-305006: {outbound static|identity|portmap|regular) translation creation failed for protocol src interface_name:source_address/source_port [(idfw_user)] dst interface_name:dest_address/dest_port [(idfw_user)]

  • %ASA-3-305008: Detecting free unallocated global IP IP_ addressinterface_name

  • %ASA-3-305016: Unable to create protocol connection from source_interface_name:source_ip_address/source_port to destination_interface_name:destination_ip/destination_port due to reaching per-host PAT port block limit of threshold-limit.

  • %ASA-3-305016: Unable to create protocol connection from source_interface_name:source_ip_address/source_port to destination_interface_name:destination_ip_address/destination_port due to port block exhaustion in PAT pool 'pool_name' IP pool_ip_address.

  • %ASA-3-305016: Port blocks exhausted in PAT pool 'pool_name' IP pool_address. Unable to create connection.

  • %ASA-3-305017: Pba-interim-logging: Active Active ICMPsourcedevice IPdestinationdevice IPActive PortBlock

  • %ASA-3-305019: MAP node address ip/port has inconsistent Port Set ID encoding

  • %ASA-3-305020: MAP node with address ip is not allowed to use port port

  • %ASA-3-305023: Unable to create connection from inside:ip/port to outside:ip/port due to IP port block exhaustion in PAT pool pool_name IP port_address.

  • %ASA-3-313001: Denied ICMP type=numbercodeIP_addressinterface_name

  • %ASA-3-313008: Denied IPv6-ICMP type=numbercodeIP_addressinterface_name

  • %ASA-3-315004: Fail to establish SSH session because RSA host key retrieval failed.

  • %ASA-3-315012: Weak SSH typealgIP_addressInt

  • %ASA-3-316001: Denied new tunnel to IP_address. VPN peer limit (platform_vpn_peer_limit) exceeded

  • %ASA-3-316002: VPN Handle error: protocol=protocolin_if_numsrc_addrout_if_numdst_addr

  • %ASA-3-317001: No memory available for limit_slow

  • %ASA-3-317002: Bad path pointer of number for IP_address, number max

  • %ASA-3-317003: IP routing table creation failure - reason

  • %ASA-3-317004: IP routing table limit warning - limit_context

  • %ASA-3-317005: IP routing table limit exceeded - reason

  • %ASA-3-317006: Pdb index error %08x, %04x, pdb

  • %ASA-3-317012: Interface IP route counter negative -  nameif-string-value 

  • %ASA-3-318001: Internal error: reason

  • %ASA-3-318002: Flagged as being an ABR without a backbone area

  • %ASA-3-318003: Reached unknown state in neighbor state machine

  • %ASA-3-318004: DB already exist : area string lsid IP_address adv netmask type 0xnumber

  • %ASA-3-318005: No corresponding LSA in retransmission database for ip_address

  • %ASA-3-318006: if interface_name if_state number

  • %ASA-3-318008: Reconfigure virtual link

  • %ASA-3-318101: Internal error: REASON

  • %ASA-3-318102: Flagged as being an ABR without a backbone area

  • %ASA-3-318103: Reached unknown state in neighbor state machine

  • %ASA-3-318104: DB already exist : area AREA_ID_STR lsid i adv i type 0xx

  • %ASA-3-318105: No corresponding LSA in retransmission database for i

  • %ASA-3-318106: if IF_NAME if_state d

  • %ASA-3-318108: OSPF process d is changing router-id. Reconfigure virtual link neighbors with our new router-id

  • %ASA-3-318109: Received packet with wrong state x

  • %ASA-3-318110: Invalid encrypted key key_string.

  • %ASA-3-318111: IPSEC policy for area u already exists

  • %ASA-3-318112: IPSEC SPI u already in use for area d

  • %ASA-3-318113: IPSEC SPI s s reused for different policy on area u

  • %ASA-3-318114: IPSEC invalid key length spi_value

  • %ASA-3-318115: IPSEC create policy error s for area u

  • %ASA-3-318116: IPSEC policy does not exist for area u

  • %ASA-3-318117: IPSEC policy still in use for area u

  • %ASA-3-318118: IPSEC remove policy error s for area u

  • %ASA-3-318119: IPSEC close session error u for area s

  • %ASA-3-318120: OSPFv3 was unable to register with Ipsec

  • %ASA-3-318121: IPSEC general error s for area d

  • %ASA-3-318122: IPSEC error message retry for area s

  • %ASA-3-318123: IPSEC error message abort for area s

  • %ASA-3-318125: Interface IF_NAME initialization failed

  • %ASA-3-318126: Interface IF_NAME attached to multiple areas

  • %ASA-3-318127: Could not allocate or find the neighbor

  • %ASA-3-319001: Acknowledge for arp update for IP address dest_addressnumber

  • %ASA-3-319002: Acknowledge for route update for IP address dest_addressnumber

  • %ASA-3-319003: Arp update for IP address addressn

  • %ASA-3-319004: Route update for IP address dest_addressnumber

  • %ASA-3-320001: The subject name of the peer cert is not allowed for connection

  • %ASA-3-321007: System is low on free memory blocks of size block_sizefree_blocksmax_blocks

  • %ASA-3-322001: Deny MAC address MAC_addressinterface

  • %ASA-3-322002: ARP inspection check failed for arp {request|response}MAC_addressinterfaceMAC_address_1IP_address{statically|dynamically}MAC_address_2

  • %ASA-3-322003: ARP inspection check failed for arp {request|response}MAC_addressinterfaceMAC_address_1IP_address

  • %ASA-3-323001: Module module_id

  • %ASA-3-323002: Module module_id

  • %ASA-3-323003: Module module_id

  • %ASA-3-323004: Module in slot string onenewververreason

  • %ASA-3-323005: Module syslog_string can not be started completely.

  • %ASA-3-323005: Module syslog_string powerfail recovery is in progress.

  • %ASA-3-323007: Module in slot slot

  • %ASA-3-324000: Drop GTP message msg_typesource_interfacesource_addresssource_portdest_interfacedest_addressdest_portreason

  • %ASA-3-324001: GTPv0 packet parsing error from source_interface:source_address/source_port to dest_interface:dest_address/dest_port, TID: tid_value, Reason: reason

  • %ASA-3-324002: No PDP[MCB] exists to process GTPv0 msg_type from source_interface:source_address/source_port to dest_interface:dest_address/dest_port, TID: tid_value

  • %ASA-3-324003: msg_typesource_interfacesource_addresssource_portdest_interfacedest_addressdest_port

  • %ASA-3-324004: GTP packet with version Ver_numbersource_interfacesource_addresssource_portdest_interfacedest_addressdest_port

  • %ASA-3-324005: Unable to create tunnel from source_interfacesource_addresssource_portdest_interfacedest_addressdest_port

  • %ASA-3-324006: GSN IP_addresstunnel_limittid

  • %ASA-3-324007: Unable to create GTP connection for response from source_address0dest_address

  • %ASA-3-324008: No PDP exists to update the data sgsn [ggsn]teid_valueteid_valueIPaddressVPIfNumIPaddressVPIfNum

  • %ASA-3-324009: Drop GTP message G-PDU from inside_interface :inside_ip /inside_port to outside_interface :outside_ip /outside_port Reason>

  • %ASA-3-324300: Radius Accounting Request from from_addr

  • %ASA-3-324301: Radius Accounting Request has a bad header length hdr_lenpkt_len

  • %ASA-3-325001: Router ipv6_addressinterface

  • %ASA-3-326001: Unexpected error in the timer library: error_message

  • %ASA-3-326002: Error in error_message: error_message

  • %ASA-3-326004: An internal error occurred while processing a packet queue

  • %ASA-3-326005: Mrib notification failed for (IP_address, IP_address)

  • %ASA-3-326006: Entry-creation failed for (IP_address, IP_address)

  • %ASA-3-326007: Entry-update failed for (IP_address, IP_address)

  • %ASA-3-326008: MRIB registration failed

  • %ASA-3-326009: MRIB connection-open failed

  • %ASA-3-326010: MRIB unbind failed

  • %ASA-3-326011: MRIB table deletion failed

  • %ASA-3-326012: Initialization of string functionality failed

  • %ASA-3-326013: Internal error: string in string line %d (%s)

  • %ASA-3-326014: Initialization failed: error_message error_message

  • %ASA-3-326015: Communication error: error_message error_message

  • %ASA-3-326016: Failed to set un-numbered interface for interface_name (string)

  • %ASA-3-326017: Interface Manager error - string in string: string

  • %ASA-3-326019: string in string: string

  • %ASA-3-326020: List error in string: string

  • %ASA-3-326021: Error in string: string

  • %ASA-3-326022: Error in string: string

  • %ASA-3-326023: string - IP_address: string

  • %ASA-3-326024: An internal error occurred while processing a packet queue.

  • %ASA-3-326025: string

  • %ASA-3-326026: Server unexpected error: error_message

  • %ASA-3-326027: Corrupted update: error_message

  • %ASA-3-326028: Asynchronous error: error_message

  • %ASA-3-327001: IP SLA Monitor: Cannot create a new process

  • %ASA-3-327002: IP SLA Monitor: Failed to initialize, IP SLA Monitor functionality will not work

  • %ASA-3-327003: IP SLA Monitor: Generic Timer wheel timer functionality failed to initialize

  • %ASA-3-328001: Attempt made to overwrite a set stub function in string.

  • %ASA-3-329001: The string0 subblock named string1 was not removed

  • %ASA-3-331001: Dynamic DNS Update for 'fqdn_nameip_address

  • %ASA-3-332001: Unable to open cache discovery socket, WCCP V2

  • %ASA-3-332002: Unable to allocate message buffer, WCCP V2

  • %ASA-3-336001 Route desination_network stuck-in-active state in EIGRP-ddb_name as_num. Cleaning up

  • %ASA-3-336002: Handle not allocated in pool

  • %ASA-3-336003: Unable to alloc pkt buffer

  • %ASA-3-336004: Negative refcount in pakdesc

  • %ASA-3-336005: Flow control error

  • %ASA-3-336006: Peers exist on IIDB

  • %ASA-3-336007: Anchor Count negative

  • %ASA-3-336008: Lingering DRDB deleting IIDB

  • %ASA-3-336009 ddb_name as_id: Internal Error

  • %ASA-3-336018: process_name as_number: prefix_source threshold prefix level (prefix_threshold) reached

  • %ASA-3-338305: Failed to download dynamic filter data file from updater server url

  • %ASA-3-338306: Failed to authenticate with dynamic filter updater server url

  • %ASA-3-338307: Failed to decrypt downloaded dynamic filter data file

  • %ASA-3-338309: The license on this device

  • %ASA-3-338310: Failed to update from dynamic filter updater server url,reason string

  • %ASA-3-339001: DNSCRYPT certificate update failed for num_tries

  • %ASA-3-339002: Umbrella device registration failed with error code err_code

  • %ASA-3-339003: Umbrella device registration was successful.

  • %ASA-3-339004: Umbrella device registration failed due to missing token

  • %ASA-3-339005: Umbrella device registration failed after num_tries

  • %ASA-3-339006: Umbrella resolver current resolver ipv46 is reachable. Resuming redirect

  • %ASA-3-339007: Umbrella resolver current resolver ipv46 is unreachable, moving to fail-open. Starting probe to resolver

  • %ASA-3-339008: Umbrella resolver current resolver ipv46 is unreachable, moving to fail-close

  • %ASA-3-339011: Umbrella API token request received no responses.

  • %ASA-3-339012: Umbrella API token request failed with error code error code.

  • %ASA-3-339013: Umbrella API token request failed in response processing.

  • %ASA-3-339014: Umbrella API token request failed after retry_number retries.

  • %ASA-3-340001: Vnet-proxy handshake error error_stringcontext_idversion

  • %ASA-3-341003: Policy Agent failed to start for VNMC vnmc_ip_addr

  • %ASA-3-341004: Storage device not available. Attempt to shutdown module module_name

  • %ASA-3-341005: Storage device not available. Shutdown issued for module module_name

  • %ASA-3-341006: Storage device not available. Failed to stop recovery of module module_name

  • %ASA-3-341007: Storage device not available. Further recovery of module module_name

  • %ASA-3-341008: Storage device not found. Auto-boot of module module_name

  • %ASA-3-341011: Storage device with serial number ser_nobay_no

  • %ASA-3-342002: REST API Agent failed, reason: reason

  • %ASA-3-342003: REST API Agent failure notification received. Agent will be restarted automatically.

  • %ASA-3-342004: Failed to automatically restart the REST API Agent after num

  • %ASA-3-342006: Failed to install REST API image, reason: reason

  • %ASA-3-342008: Failed to uninstall REST API image, reason: reason

  • %ASA-3-402140: CRYPTO: RSAlen

  • %ASA-3-402141: CRYPTO: Key zeroization error: key set 'typereason

  • %ASA-3-402142: CRYPTO: Bulk data opalgmode

  • %ASA-3-402143: CRYPTO: alg typeop

  • %ASA-3-402144: CRYPTO: Digital signature error: signature algorithm 'sighash

  • %ASA-3-402145: CRYPTO: Hash generation error: algorithm 'hash

  • %ASA-3-402146: CRYPTO: Keyed hash generation error: algorithm 'hashlen

  • %ASA-3-402147: CRYPTO: HMAC generation error: algorithm 'alg

  • %ASA-3-402148: CRYPTO: Random Number Generator error

  • %ASA-3-402149: CRYPTO: Weak encryption typelength

  • %ASA-3-402150: CRYPTO: Deprecated hash algorithm used for RSA operationhash alg

  • %ASA-3-403501: PPPoE - Bad host-unique in PADO - packet dropped. AC:interface_name

  • %ASA-3-403502: PPPoE - Bad host-unique in PADS - packet dropped. AC:interface_name

  • %ASA-3-403503: Header_string:PPP link down[:reason string]

  • %ASA-3-403504: group_name

  • %ASA-3-403507: PPPoEinterfacegroup_name

  • %ASA-3-414001: Failed to save logging buffer to FTP server filenameftp_server_addressinterface_namefail_reason

  • %ASA-3-414002: Failed to save logging buffer to flash:/syslogfilenamefail_reason

  • %ASA-3-414003: TCP Syslog Server intfIP_Addressport[permitted|denied]

  • %ASA-3-414005: TCP Syslog Server intf: IP_Address/port connected, New connections are permitted based on logging permit-hostdown policy

  • %ASA-3-414006: TCP syslog server configured and logging queue is full. New connections denied based on logging permit-hostdown policy.

  • %ASA-3-418018: neighbor IP_Addressvrf_identifietopology_identifieraddress_familystate_change

  • %ASA-3-418019: received from IP_Address error_code/error_subcode(error_text) data_bytesbytes hex_data

  • %ASA-3-418040: Unsupported or malformed message: IP_Address

  • %ASA-3-418044: Connection closed remotely by IP_Address

  • %ASA-3-420001: IPS card not up and fail-close mode used, dropping ICMPifc_inSIPportifc_outDIPport

  • %ASA-3-420006: Virtual sensor not present and fail-close mode used, dropping protocolifc_inSIPSPORTifc_outDIPDPORT

  • %ASA-3-420008: IPS module license disabled and fail-close mode used, dropping packet.

  • %ASA-3-421001: TCP|UDP flow from interface_name:ip/port to interface_name:ip/port is dropped because application has failed.

  • %ASA-3-421003: Invalid data plane encapsulation

  • %ASA-3-421007: TCP|UDP flow from interface_name:IP_address/port to interface_name:IP_address/port is skipped because application has failed.

  • %ASA-3-425006 Redundant interface redundant_interface_name switch active member to interface_name failed.

  • %ASA-3-429001: CX card not up and fail-close mode used, dropping protocolinterface_nameip_addressportinterface_nameip_addressport

  • %ASA-3-429004: Unable to set up rule_nameinterface_namepolicy_type

  • %ASA-3-444303: %SMART_LIC-3-AGENT_REG_FAILED: Smart Agent for licensing registration with Cisco licensing cloud failed.

  • %ASA-3-444303: %SMART_LIC-3-AGENT_DEREG_FAILED: Smart Agent for licensing deregistration with CSSM failed.

  • %ASA-3-444303: %SMART_LIC-3-OUT_OF_COMPLIANCE: One or more entitlements are out of compliance.

  • %ASA-3-444303: %SMART_LIC-3-EVAL_EXPIRED: Evaluation period expired.

  • %ASA-3-444303: %SMART_LIC-3-BAD_MODE: An unknown mode was specified.

  • %ASA-3-444303: %SMART_LIC-3-BAD_NOTIF: A bad notification type was specified.

  • %ASA-3-444303: %SMART_LIC-3-ID_CERT_EXPIRED: Identity certificate expired. Agent will transition to the unidentified (not registered) state.

  • %ASA-3-444303: %SMART_LIC-3-ID_CERT_RENEW_NOT_STARTED: Identity certificate start date not reached yet.

  • %ASA-3-444303: %SMART_LIC-3-ID_CERT_RENEW_FAILED: Identity certificate renewal failed.

  • %ASA-3-444303: %SMART_LIC-3-ENTITLEMENT_RENEW_FAILED: Entitlement authorization with Cisco licensing cloud failed.

  • %ASA-3-444303: %SMART_LIC-3-COMM_FAILED: Communications failure with Cisco licensing cloud.

  • %ASA-3-444303: %SMART_LIC-3-CERTIFICATE_VALIDATION: Certificate validation failed by smart agent.

  • %ASA-3-444303: %SMART_LIC-3-AUTH_RENEW_FAILED: Authorization renewal with Cisco licensing cloud failed.

  • %ASA-3-444303: %SMART_LIC-3-INVALID_TAG: The entitlement tag is invalid.

  • %ASA-3-444303: %SMART_LIC-3-INVALID_ROLE_STATE: The current role is not allowed to move to the new role.

  • %ASA-3-444303: %SMART_LIC-3-EVAL_WILL_EXPIRE_WARNING: Evaluation period will expire in time.

  • %ASA-3-444303: %SMART_LIC-3-EVAL_EXPIRED_WARNING: Evaluation period expired on time.

  • %ASA-3-444303: %SMART_LIC-3-ID_CERT_EXPIRED_WARNING: This device's registration will expire in time.

  • %ASA-3-444303: %SMART_LIC-3-CONFIG_OUT_OF_SYNC: Trusted Store Enable flag not in sync with System Configuration, TS flag Config flag.

  • %ASA-3-444303: %SMART_LIC-3-REG_EXPIRED_CLOCK_CHANGE: Smart Licensing registration has expired because the system time was changed outside the validity period of the registration period. The agent will transition to the un-registered state in 60 minutes.

  • %ASA-3-444303: %SMART_LIC-3-ROOT_CERT_MISMATCH_PROD: Certificate type mismatch.

  • %ASA-3-444303: %SMART_LIC-3-HOT_STANDBY_OUT_OF_SYNC: Smart Licensing agent on hot standby is out of sync with active Smart Licensing agent.

  • %ASA-3-444714: Azure failed to retrieve Wireserver IPv4 address.

  • %ASA-3-505016: Module module_idnameversionstatenameversionstate

  • %ASA-3-500005: Connection terminated for protocolin_ifc_namesrc_adddresssrc_portout_ifc_namedest_addressdest_portinspect_namefilter_name

  • %ASA-3-507003: protocoloriginating interfacesrc_ipsrc_port dest_ifdest_ipdest_port reason

  • %ASA-3-520001: error_string

  • %ASA-3-520002: bad new ID table size

  • %ASA-3-520003: bad id in error_string (id: 0xid_num)

  • %ASA-3-520004: error_string

  • %ASA-3-520005: error_string

  • %ASA-3-520010: Bad queue elem – qelem_ptr: flink flink_ptr, blink blink_ptr, flink->blink flink_blink_ptr, blink->flink blink_flink_ptr

  • %ASA-3-520011: Null queue elem

  • %ASA-3-520013: Regular expression access check with bad list acl_ID

  • %ASA-3-520020: No memory available

  • %ASA-3-520021: Error deleting trie entry, error_message

  • %ASA-3-520022: Error adding mask entry, error_message

  • %ASA-3-520023: Invalid pointer to head of tree, 0xradix_node_ptr

  • %ASA-3-520024: Orphaned mask #radix_mask_ptr, refcount= radix_mask_ptr ‘s ref count at # radix_node_address, next=# radix_node_next

  • %ASA-3-520025: No memory for radix initialization: error_msg

  • %ASA-3-602305: IPSEC: SA creation error, source source addressdestination addresserror string

  • %ASA-3-602306: IPSEC: SA change peer IP error, SPI: IPsec SPI, (src original src IP address/original src port, dest original dest IP address/original dest port => src new src IP address/new src port, dest: new dest IP address/new dest port), reason failure reason.

  • %ASA-3-610001: NTP daemon interface interface_nameIP_address

  • %ASA-3-610002: NTP daemon interface interface_nameIP_address

  • %ASA-3-611313: VPNClient: Backup Server List Error: reason

  • %ASA-3-613004: Internal error: memory allocation failure

  • %ASA-3-613005: Flagged as being an ABR without a backbone area

  • %ASA-3-613006: Reached unknown state in neighbor state machine

  • %ASA-3-613007: area string lsid IP_address mask netmask type number

  • %ASA-3-613008: if inside if_state number

  • %ASA-3-613011: OSPF process number is changing router-id. Reconfigure virtual link neighbors with our new router-id

  • %ASA-3-613013: OSPF LSID IP_address adv IP_address type number gateway IP_address metric number forwarding addr route IP_address /mask type number has no corresponding LSA

  • %ASA-3-613029: Router-ID IP_address is in use by ospf process number%ASA-3-613016: Area string router-LSA of length number bytes plus update overhead bytes is too large to flood.

  • %ASA-3-613032: Init failed for interface inside, area is being deleted. Try again.%ASA-3-613033: Interface inside is attached to more than one area

  • %ASA-3-613034: Neighbor IP_address not configured

  • %ASA-3-613035: Could not allocate or find neighbor IP_address%ASA-4-613015: Process 1 flushes LSA ID IP_address type-number adv-rtr IP_address in area mask

  • %ASA-3-702305: IPSEC: An direction tunnel_typespi local_IPremote_IP

  • %ASA-3-710003: {TCP|UDP}source_IPsource_portinterface_namedest_IPservice

  • %ASA-3-713004: device scheduled for reboot, IKE key acquire message on interface interface num, for peer IP_address ignored

  • %ASA-3-713008: IP = peerIP Key ID in ID payload too big for pre-shared IKE tunnel

  • %ASA-3-713009: IP = peerIP OU in DN in ID payload too big for Certs IKE tunnel

  • %ASA-3-713012: Group = groupname, Username = username, IP = peerIP Unknown protocol (protocol ). Not adding SA w/spi= SPI value

  • %ASA-3-713014: Group = groupname, Username = username, IP = peerIP Unknown Domain of Interpretation (DOI): DOI value

  • %ASA-3-713016: Group = groupname, Username = username, IP = peerIP Unknown identification type, Phase 1 or 2, Type ID_Type

  • %ASA-3-713017: Group = groupname, Username = username, IP = peerIP Identification type not supported, Phase 1 or 2, Type ID_Type

  • %ASA-3-713018: IP = peerIP Unknown ID type during find of group name for certs, Type ID_Type

  • %ASA-3-713020: IP = peerIP No Group found by matching OU(s) from ID payload: OU_value

  • %ASA-3-713022: IP = peerIP No Group found matching peer_ID or IP_address for Pre-shared key peer IP_address

  • %ASA-3-713032: Group = groupname, Username = username, IP = peerIP Received invalid local Proxy Range IP_address - IP_address

  • %ASA-3-713033: Group = groupname, Username = username, IP = peerIP Received invalid remote Proxy Range IP_address - IP_address

  • %ASA-3-713042: IKE Initiator unable to find policy: Intf interface_number, Src: source_address, Dst: dest_address

  • %ASA-3-713043: Cookie/peer address IP_address session already in progress

  • %ASA-3-713047: Unsupported Oakley group: Group Diffie-Hellman group

  • %ASA-3-713048: Group = groupname, Username = username, IP = peerIP Error processing payload: Payload ID: id

  • %ASA-3-713056: Group = groupname, Username = username, IP = peerIP Tunnel rejected: SA (SA_name ) not found for group (group_name )!

  • %ASA-3-713060: Group = groupname, Username = username, IP = peerIP Tunnel Rejected: User (user ) not member of group (group_name ), group-lock check failed.

  • %ASA-3-713061: Group = groupname, Username = username, IP = peerIP Tunnel rejected: Crypto Map Policy not found for Src:source_address, Dst: dest_address !

  • %ASA-3-713062: IKE Peer address same as our interface address IP_address

  • %ASA-3-713063: IKE Peer address not configured for destination IP_address

  • %ASA-3-713065: IKE Remote Peer did not negotiate the following: proposal attribute

  • %ASA-3-713072: Group = groupname, Username = username, IP = peerIP Password for user (user ) too long, truncating to number characters

  • %ASA-3-713081: Group = groupname, Username = username, IP = peerIP Unsupported certificate encoding type encoding_type

  • %ASA-3-713082: Group = groupname, Username = username, IP = peerIP Failed to retrieve identity certificate

  • %ASA-3-713083: Group = groupname, Username = username, IP = peerIP Invalid certificate handle

  • %ASA-3-713084: Group = groupname, Username = username, IP = peerIP Received invalid phase 1 port value (port ) in ID payload

  • %ASA-3-713085: Group = groupname, Username = username, IP = peerIP Received invalid phase 1 protocol (protocol ) in ID payload

  • %ASA-3-713086: Group = groupname, Username = username, IP = peerIP Received unexpected Certificate payload Possible invalid Auth Method (Auth method (auth numerical value))

  • %ASA-3-713088: Group = groupname, Username = username, IP = peerIP Set Cert filehandle failure: no IPsec SA in group group_name

  • %ASA-3-713098: Group = groupname, Username = username, IP = peerIP Aborting: No identity cert specified in IPsec SA (SA_name )!

  • %ASA-3-713102: Group = groupname, Username = username, IP = peerIP Phase 1 ID Data length number too long - reject tunnel!

  • %ASA-3-713105: Group = groupname, Username = username, IP = peerIP Zero length data in ID payload received during phase 1 or 2 processing

  • %ASA-3-713107: Group = groupname, Username = username, IP = peerIP IP_Address request attempt failed!

  • %ASA-3-713109: Group = groupname, Username = username, IP = peerIP Unable to process the received peer certificate

  • %ASA-3-713112: Group = groupname, Username = username, IP = peerIP Failed to process CONNECTED notify (SPI SPI_value )!

  • %ASA-3-713014: Group = groupname, Username = username, IP = peerIP Unknown Domain of Interpretation (DOI): DOI value

  • %ASA-3-713016: Group = groupname, Username = username, IP = peerIP Unknown identification type, Phase 1 or 2, Type ID_Type

  • %ASA-3-713017: Group = groupname, Username = username, IP = peerIP Identification type not supported, Phase 1 or 2, Type ID_Type

  • %ASA-3-713118: Detected invalid Diffie-Helmann group_descriptor group_number, in IKE area

  • %ASA-3-713122: IP = peerIP Keep-alives configured keepalive_type but peer IP_address support keep-alives (type = keepalive_type )

  • %ASA-3-713123: Group = groupname, Username = username, IP = peerIP IKE lost contact with remote peer, deleting connection (keepalive type: keepalive_type )

  • %ASA-3-713127: Group = groupname, Username = username, IP = peerIP Xauth required but selected Proposal does not support xauth, Check priorities of ike xauth proposals in ike proposal list

  • %ASA-3-713129: Group = groupname, Username = username, IP = peerIP Received unexpected Transaction Exchange payload type: payload_id

  • %ASA-3-713132: Group = groupname, Username = username, IP = peerIP Cannot obtain an IP_address for remote peer

  • %ASA-3-713133: Group = groupname, Username = username, IP = peerIP Mismatch: Overriding phase 2 DH Group(DH group DH group_id ) with phase 1 group(DH group DH group_number

  • %ASA-3-713134: Group = groupname, Username = username, IP = peerIP Mismatch: P1 Authentication algorithm in the crypto map entry different from negotiated algorithm for the L2L connection

  • %ASA-3-713138: IP = peerIP Group group_name not found and BASE GROUP default preshared key not configured

  • %ASA-3-713140: Group = groupname, Username = username, IP = peerIP Split Tunneling Policy requires network list but none configured

  • %ASA-3-713141: IP = peerIP Client-reported firewall does not match configured firewall: action tunnel. Received -- Vendor: vendor(id), Product product(id), Caps: capability_value . Expected -- Vendor: vendor(id), Product: product(id), Caps: capability_value

  • %ASA-3-713142: IP = peerIP Client did not report firewall in use, but there is a configured firewall: action tunnel. Expected -- Vendor: vendor(id), Product product(id), Caps: capability_value

  • %ASA-3-713146: Group = groupname, Username = username, IP = peerIP Could not add route for Hardware Client in network extension mode, address: IP_address, mask: netmask

  • %ASA-3-713149: Group = groupname, Username = username, IP = peerIP Hardware client security attribute attribute_name was enabled but not requested.

  • %ASA-3-713152: IP = peerIP Unable to obtain any rules from filter ACL_tag to send to client for CPP, terminating connection.

  • %ASA-3-713159: TCP Connection to Firewall Server has been lost, restricted tunnels are now allowed full network access

  • %ASA-3-713161: Group = groupname, Username = username, IP = peerIP Remote user (session Id - id ) network access has been restricted by the Firewall Server

  • %ASA-3-713162: Group = groupname, Username = username, IP = peerIP Remote user (session Id - id ) has been rejected by the Firewall Server

  • %ASA-3-713163: Group = groupname, Username = username, IP = peerIP Remote user (session Id - id ) has been terminated by the Firewall Server

  • %ASA-3-713165: Group = groupname, Username = username, IP = peerIP Client IKE Auth mode differs from the group's configured Auth mode

  • %ASA-3-713166: Group = groupname, Username = username, IP = peerIP Headend security gateway has failed our user authentication attempt - check configured username and password

  • %ASA-3-713167: Group = groupname, Username = username, IP = peerIP Remote peer has failed user authentication - check configured username and password

  • %ASA-3-713168: Re-auth enabled, but tunnel must be authenticated interactively!

  • %ASA-3-713174: Group = groupname, Username = username, IP = peerIP Hardware Client connection rejected! Network Extension Mode is not allowed for this group!

  • %ASA-3-713182: Group = groupname, Username = username, IP = peerIP IKE could not recognize the version of the client! IPsec Fragmentation Policy will be ignored for this connection!

  • %ASA-3-713185: IP = peerIP Error: Username too long - connection aborted

  • %ASA-3-713186: Invalid secondary domain name list received from the authentication server. List Received: list_text Character index (value ) is illegal

  • %ASA-3-713189: Group = groupname, Username = username, IP = peerIP Attempted to assign network or broadcast IP_address, removing ( IP_address ) from pool.

  • %ASA-3-713191: IP = IP_address Maximum concurrent IKE negotiations exceeded!

  • %ASA-3-713193: Received packet with missing payload, Expected payload: payload_id

  • %ASA-3-713194: Group = groupname, Username = username, IP = peerIP Sending IKE |IPsec Delete With Reason message: termination_reason

  • %ASA-3-713195: Group = groupname, Username = username, IP = peerIP Tunnel rejected: Originate-Only: Cannot accept incoming tunnel yet!

  • %ASA-3-713198: Group = groupname, Username = username, IP = peerIP User Authorization failed: user User authorization failed. Username could not be found in the certificate

  • %ASA-3-713203: IKE Receiver: Error reading from socket.

  • %ASA-3-713205: Group = groupname, Username = username, IP = peerIP Could not add static route for client address: IP_address

  • %ASA-3-713206: Group = groupname, Username = username, IP = peerIP Tunnel Rejected: Conflicting protocols specified by tunnel-group and group-policy

  • %ASA-3-713208: Cannot create dynamic rule for Backup L2L entry rule rule_id

  • %ASA-3-713209: Cannot delete dynamic rule for Backup L2L entry rule id

  • %ASA-3-713210: Cannot create dynamic map for Backup L2L entry rule_id

  • %ASA-3-713212: Group = groupname, Username = username, IP = peerIP Could not add route for L2L peer coming in on a dynamic map. address:

  • %ASA-3-713214: Group = groupname, Username = username, IP = peerIP Could not delete route for L2L peer that came in on a dynamic map. address: IP_address, mask: netmask

  • %ASA-3-713217: Group = groupname, Username = username, IP = peerIP Skipping unrecognized rule: action: action client type: client_type client version: client_version

  • %ASA-3-713218: Group = groupname, Username = username, IP = peerIP Tunnel Rejected: Client Type or Version not allowed.

  • %ASA-3-713226: Connection failed with peer IP_address, no trust-point defined in tunnel-group tunnel_group

  • %ASA-3-713227: IP = IP_address Rejecting new IPsec SA negotiation for peer Peer_address . A negotiation was already in progress for local Proxy Local_address /Local_netmask, remote Proxy Remote_address /Remote_netmask

  • %ASA-3-713230: Internal Error, ike_lock trying to lock bit that is already locked for type type

  • %ASA-3-713231: Internal Error, ike_lock trying to unlock bit that is not locked for type type

  • %ASA-3-713232: SA lock refCnt = value, bitmask = hexvalue, p1_decrypt_cb = value, qm_decrypt_cb = value, qm_hash_cb = value, qm_spi_ok_cb = value, qm_dh_cb = value, qm_secret_key_cb = value, qm_encrypt_cb = value

  • %ASA-3-713238: Group = groupname, Username = username, IP = peerIP Invalid source proxy address: 0.0.0.0! Check private address on remote client

  • %ASA-3-713258: IP = var1 IP = var1, Attempting to establish a phase2 tunnel on var2 interface but phase1 tunnel is on var3 interface. Tearing down old phase1 tunnel due to a potential routing change.

  • %ASA-3-713254: Group = groupname, Username = username, IP = peerip Group = groupname, Username = username, IP = peerip, Invalid IPsec/UDP port = portnum, valid range is minport - maxport, except port 4500, which is reserved for IPsec/NAT-T

  • %ASA-3-713260: Output interface %d to peer was not found

  • %ASA-3-713262: IP = IP_address Rejecting new IPSec SA negotiation for peer Peer_address . A negotiation was already in progress for local Proxy Local_address /Local_prefix_len, remote Proxy Remote_address /Remote_prefix_len

  • %ASA-3-713266: Group = groupname, Username = username, IP = peerIP Could not add route for L2L peer coming in on a dynamic map. address: IP_address, mask: /prefix_len

  • %ASA-3-713268: Group = groupname, Username = username, IP = peerIP Could not delete route for L2L peer that came in on a dynamic map. address: IP_address, mask: /prefix_len

  • %ASA-3-713270: Group = groupname, Username = username, IP = peerIP Could not add route for Hardware Client in network extension mode, address: IP_address, mask: /prefix_len

  • %ASA-3-713274: Group = groupname, Username = username, IP = peerIP Could not delete static route for client address: IP_Address IP_Address address of client whose route is being removed

  • %ASA-3-713275: IKEv1 Unsupported certificate keytype %s found at trustpoint %s

  • %ASA-3-713276: IP = IP_address Dropping new negotiation - IKEv1 in-negotiation context limit of %u reached

  • %ASA-3-713902: Descriptive_event_string.

  • %ASA-3-716056: Group group-name User user-name IP IP_address Authentication to SSO server name: name type type failed reason: reason

  • %ASA-3-716057: Group groupuseriptype

  • %ASA-3-716061: Group DfltGrpPolicyuserip addrtempipv6

  • %ASA-3-716158: Failed to create SAML logout request, initiated by user. reason: reason.

  • %ASA-3-716159: Failed to process SAML logout request. reason: reason.

  • %ASA-3-716160: Failed to create SAML authentication request. reason: reason.

  • %ASA-3-716162: Failed to consume SAML assertion. reason: reason.

  • %ASA-3-716163: SAML response relay state failed data integrity check. Client IP: IP address

  • %ASA-3-716164: SAML response relay state missing data integrity hash. Client IP: IP address

  • %ASA-3-716600: Rejected size-recvsrc-ipdefaultconfigured

  • %ASA-3-716601: Rejected size-recvsrc-ipdefaultconfigured

  • %ASA-3-716602: Memory allocation error. Rejected size-recvsrc-ip

  • %ASA-3-717001: Querying keypair failed.

  • %ASA-3-717002: Certificate enrollment failed for trustpoint trustpoint_namereason_string

  • %ASA-3-717009: Certificate validation failed. reason_string

  • %ASA-3-717010: CRL polling failed for trustpoint trustpoint_name

  • %ASA-3-717012: Failed to refresh CRL cache entry from the server for trustpoint trustpoint_name at time_of_failure

  • %ASA-3-717015: CRL received from issuer is too large to process (CRL size = crl_size, maximum CRL size = max_crl_size)

  • %ASA-3-717017: Failed to query CA certificate for trustpoint trustpoint_nameenrollment_url

  • %ASA-3-717018: CRL received from issuer has too many entries to process (number of entries = number_of_entries, maximum number allowed = max_allowed)

  • %ASA-3-717019: Failed to insert CRL for trustpoint trustpoint_namefailure_reason

  • %ASA-3-717020: Failed to install device certificate for trustpoint labelreason string

  • %ASA-3-717021: Certificate data could not be verified. Reason: reason_stringserial number

  • %ASA-3-717023: SSL failed to set device certificate for trustpoint trustpoint namereason_string

  • %ASA-3-717027: Certificate chain failed validation. reason_string

  • %ASA-3-717032: OCSP status check failed. Reason: reason_string.

  • %ASA-3-717039: Local CA Server internal error detected: error.

  • %ASA-3-717042: Failed to enable Local CA Server. Reason: reason

  • %ASA-3-717044: Local CA Server certificate enrollment related error for user: usererror

  • %ASA-3-717046: Local CA Server CRL error: error

  • %ASA-3-717051: SCEP Proxy: Denied processing the request type typeclient ip addressusernametunnel group namegroup policy nameca ip addressmsg

  • %ASA-3-717057: Automatic import of trustpool certificate bundle has failed. Maximum retry attempts reached. Failed to reach CA server | Cisco root bundle signature validation failed | Failed to update trustpool bundle in flash | Failed to install trustpool bundle in memory

  • %ASA-3-717060: Peer certificate with serial number: serial, subject: subject_name, issuer: issuer_name failed to match the configured certificate map map_name

  • %ASA-3-717063: protocoltpnameca

  • %ASA-3-717069: ACME Certificate enrollment failed for the trustpoint tpname with CA ca

  • %ASA-3-717071: CRL signature validation failed. Issuer: issuer name. Last Update: date and time. Next Update: date and time.

  • %ASA-3-719002: Email Proxy session pointer from source_address has been terminated due to reason error.

  • %ASA-3-719008: Email Proxy service is shutting down.

  • %ASA-3-722007: Group groupuser-nameIP_addresstype-nummessage

  • %ASA-3-722008: Group groupuser-nameIP_addresstype-nummessage

  • %ASA-3-722009: Group groupuser-nameIP_addresstype-nummessage

  • %ASA-3-722020: TunnelGroup tunnel_groupgroup_policyuser-nameIP_address

  • %ASA-3-722021: Group groupuser-nameIP_address

  • %ASA-3-722035: Group groupuser-nameIP_addresslengthnum

  • %ASA-3-722045: Connection terminated: no SSL tunnel initialization data

  • %ASA-3-722046: Group groupuserip

  • %ASA-3-725015 Error verifying client certificate. Public key size in client certificate exceeds the maximum supported key size.

  • %ASA-3-730005: Group DfltGrpPolicyusernameIPvlan_id

  • %ASA-3-734004: DAP: Processing error: Code internal

  • %ASA-3-735010: Environment Monitoring has failed to update one or more of its records.

  • %ASA-3-737002: IPAA: Session=sessionnum

  • %ASA-3-737027: IPAA: Session=

  • %ASA-3-737202: VPNFIP: Pool=poolmessage

  • %ASA-3-737403: POOLIP: Pool=poolmessage

  • %ASA-3-742001: failed to read master key for password encryption from persistent store

  • %ASA-3-742002: failed to set master key for password encryption

  • %ASA-3-742003: failed to save master key for password encryption, reason=reason_text

  • %ASA-3-742004: failed to sync master key for password encryption, reason=reason_text

  • %ASA-3-742005: cipher text enc_pass

  • %ASA-3-742006: password decryption failed due to unavailable memory

  • %ASA-3-742007: password encryption failed due to unavailable memory

  • %ASA-3-742008: password enc_pass

  • %ASA-3-742009: password encryption failed due to encoding error

  • %ASA-3-742010: encrypted password enc_pass

  • %ASA-3-743010: EOBC RPC server failed to start for client module client name

  • %ASA-3-743011: EOBC RPC call failed, return code code

  • %ASA-3-746003: user-identity: user-to-IP address databasesreason

  • %ASA-3-746005: user-identity: The AD Agent AD agent IP addressreason action

  • %ASA-3-746010: user-identity: Update import-user domain_namegroup_name

  • %ASA-3-746016: user-identity: DNS lookup for ipreason

  • %ASA-3-746019: user-identity: UpdateRemoveAD agent IP Addressuser_IPdomain_name

  • %ASA-3-747001: Clustering: Recovered from state machine event queue depleted. Event (event-id, ptr-in-hex, ptr-in-hex) dropped. Current state state-name, stack ptr-in-hex, ptr-in-hex, ptr-in-hex, ptr-in-hex, ptr-in-hex, ptr-in-hex

  • %ASA-3-747010: Clustering: RPC call failed, message message-name, return code code-value.

  • %ASA-3-747012: Clustering: Failed to replicate global object id hex-id-value in domain domain-name to peer unit-name, continuing operation.

  • %ASA-3-747013: Clustering: Failed to remove global object id hex-id-value in domain domain-name from peer unit-name, continuing operation.

  • %ASA-3-747014: Clustering: Failed to install global object id hex-id-value in domain domain-name, continuing operation.

  • %ASA-3-747018: Clustering: State progression failed due to timeout in module module-name.

  • %ASA-3-747021: Clustering: Master unit unit-name is quitting due to interface health check failure on failed-interface.

  • %ASA-3-747022: Clustering: Asking slave unit unit-name to quit because it failed interface health check x times, rejoin will be attempted after y min. Failed interface: interface-name.

  • %ASA-3-747023: Clustering: Master unit unit-name is quitting due to card name card health check failure, and master Security Service Card state is state-name.

  • %ASA-3-747024: Clustering: Asking slave unit unit-name to quit due to card name card health check failure, and its Security Service Card state is state-name.

  • %ASA-3-747030: Clustering: Asking slave unit unit-name to quit because it failed interface health check x times (last failure on interface-name), Clustering must be manually enabled on the unit to re-join.

  • %ASA-3-747031: Clustering: Platform mismatch between cluster master (platform-type) and joining unit unit-name (platform-type). unit-name aborting cluster join.

  • %ASA-3-747032: Clustering: Service module mismatch between cluster master (module-name) and joining unit unit-name (module-name) in slot slot-number. unit-name aborting cluster join.

  • %ASA-3-747033: Clustering: Interface mismatch between cluster master and joining unit unit-name. unit-name aborting cluster join.

  • %ASA-3-747036: Application software mismatch between cluster master %s[Master unit name] (%s[Master application software name]) and joining unit (%s[Joining unit application software name]). %s[Joining member name] aborting cluster join.

  • %ASA-3-747037: Asking slave unit %s to quit due to its Security Service Module health check failure %d times, and its Security Service Module state is %s. Rejoin will be attempted after %d minutes.

  • %ASA-3-747038: Asking slave unit %s to quit due to Security Service Module health check failure %d times, and its Security Service Card Module is %s. Clustering must be manually enabled on this unit to rejoin.

  • %ASA-3-747039: Unit %s is quitting due to system failure for %d time(s) (last failure is %s[cluster system failure reason]). Rejoin will be attempted after %d minutes.

  • %ASA-3-747040: Unit %s is quitting due to system failure for %d time(s) (last failure is %s[cluster system failure reason]). Clustering must be manually enabled on the unit to rejoin.

  • %ASA-3-747041: Unit %s is quitting due to system failure for %d time(s) (last failure is %s[cluster system failure reason]). Clustering must be manually enabled on the unit to rejoin.Master unit %s is quitting due to interface health check failure on %s[interface name], %d times. Clustering must be manually enabled on the unit to rejoin.

  • %ASA-3-747042: Clustering: Master received the config hash string request message from an unknown member, id cluster-member-id

    >
  • %ASA-3-747043: Clustering: Get config hash string from master error.

  • %ASA-6-747044: Clustering: Configuration Hash string verification result.

  • %ASA-3-748005: Failed to bundle the ports for module slot_number in chassis chassis_number; clustering is disabled

  • %ASA-3-748006: Asking module slot_number in chassis chassis_number to leave the cluster due to a port bundling failure

  • %ASA-3-748100: application_name application status is changed from status to status.

  • %ASA-3-748101: Peer unit unit_id reported its application_name application status is status.

  • %ASA-3-748102: Master unit unit_id is quitting due to application_name Application health check failure, and master's application state is status.

  • %ASA-3-748103: Asking slave unit unit_id to quit due to application_name Application health check failure, and slave's application state is status.

  • %ASA-3-748202: Module module_id in chassis chassis id is leaving the cluster due to aplpication name application failure.

  • %ASA-3-750011: Tunnel Rejected: Selected IKEv2 encryption algorithm (IKEV2 encry algo ) is not strong enough to secure proposed IPSEC encryption algorithm (IPSEC encry algo ).

  • %ASA-3-751001: Failed to complete Diffie-Hellman operation. Error: error.

  • %ASA-3-751002: No pre-shared key or trustpoint configured for self in tunnel group group

  • %ASA-3-751004: No remote authentication method configured for peer in tunnel group group

  • %ASA-3-751005: AnyConnect client reconnect authentication failed. Session ID: session_id, Error: error

  • %ASA-3-751006: Certificate authentication failed. Error: error

  • %ASA-3-751008: Group=group, Tunnel rejected: IKEv2 not enabled in group policy

  • %ASA-3-751009: Unable to find tunnel group for peer.

  • %ASA-3-751010: Local: localIP:port Remote:remoteIP:port Username: username/group Unable to determine self-authentication method. No crypto map setting or tunnel group found.

  • %ASA-3-751011: Failed user authentication. Error: error

  • %ASA-3-751012: Failure occurred during Configuration Mode processing. Error: error

  • %ASA-3-751013: Failed to process Configuration Payload request for attribute attribute_id. Error: error

  • %ASA-3-751017: Configuration Error: error_description.

  • %ASA-3-751018: Terminating the VPN connection attempt from attempted group.

  • %ASA-3-751020: Local:%A:%u Remote:%A:%u Username:%s An %s remote access connection failed. Attempting to use an NSA Suite B crypto algorithm (%s) without an AnyConnect Premium license.

  • %ASA-3-751022: Tunnel rejected: Crypto Map Policy not found for remote traffic selector rem-ts-start/rem-ts-end/rem-ts.startport/rem-ts.endport/rem-ts.protocol local traffic selector local-ts-start/local-ts-end/local-ts.startport/local-ts.endport/local-ts.protocol!

  • %ASA-3-751024: IPv6 User Filter tempipv6 configured. This setting has been deprecated, terminating connection

  • %ASA-3-752006: Tunnel Manager failed to dispatch a KEY_ACQUIRE message. Probable mis-configuration of the crypto map or tunnel-group. Map Tag = Tag . Map Sequence Number = num, SRC Addr: address port: port Dst Addr: address port: port .

  • %ASA-3-752007: Tunnel Manager failed to dispatch a KEY_ACQUIRE message. Entry already in Tunnel Manager. Map Tag = mapTag . Map Sequence Number = mapSeq

  • %ASA-3-752015: Tunnel Manager has failed to establish an L2L SA. All configured IKE versions failed to establish the tunnel. Map Tag = mapTag . Map Sequence Number = mapSeq .

  • %ASA-3-768003: QUOTA: management session quota exceeded for user user name: current 3,user limit 3

  • %ASA-3-768004: QUOTA: management session quota exceeded for ssh/telnet/http protocol: current 2, protocol limit 2

  • %ASA-3-769006: UPDATE: ASAimage_name

  • %ASA-3-771003: CLOCK: Hardware clock UIP bit is set to 1, for duration secs, start time duration secs, end time duration secs. Read clock time from linux system clock

  • %ASA-3-776001: CTS SXP: Configured source IP source ip error

  • %ASA-3-776002: CTS SXP: Invalid message from peer peer IP: error

  • %ASA-3-776003: CTS SXP: Connection with peer peer IP failed: error

  • %ASA-3-776004: CTS SXP: Fail to start listening socket after TCP process restart.

  • %ASA-3-776005: CTS SXP: Binding Binding IP - SGname(SGT) from peer IP instance connection instance num error.

  • %ASA-3-776006: CTS SXP: Internal error: error

  • %ASA-3-776007: CTS SXP: Connection with peer peer IP (instance connection instance num) state changed from original state to Off.

  • %ASA-3-776020: CTS SXP: Unable to locate egress interface to peer peer IP.

  • %ASA-3-776202: CTS Env: PAC for Server IP_addressPAC issuer name

  • %ASA-3-776203: CTS Env: Unable to retrieve data from source_typesourcereason

  • %ASA-3-776204: CTS Env: Data from source

  • %ASA-3-776254: CTS SGT-MAP: Binding manager unable to action binding binding IP - SGname (SGT) from source name.

  • %ASA-3-776313: CTS Policy: Failure to update policies for security-group "sgnamesgt

  • %ASA-3-768001: QUOTA: resourcereqcurrlevel

  • %ASA-3-768002: QUOTA: resourcereqcurrlimit

  • %ASA-3-772002: PASSWORD: consoleusername

  • %ASA-3-772004: PASSWORD: sessionusernameip

  • %ASA-3-779003: STS: Failed to read tag-switching table - reason

  • %ASA-3-779004: STS: Failed to write tag-switching table - reason

  • %ASA-3-779005: STS: Failed to parse tag-switching request from http - reason

  • %ASA-3-779006: STS: Failed to save tag-switching table to flash - reason

  • %ASA-3-779007: STS: Failed to replicate tag-switching table to peer - reason

  • %ASA-3-840001: Failed to create the backup for an IKEv2 session Local IP, Remote IP

  • %ASA-3-850001: SNORT ID (snort-instance-id/snort-process-id) Automatic-Application-Bypass due to delay of delayms (threshold AAB-thresholdms) with connection-info

    >
  • %ASA-3-850002: SNORT ID (snort-instance-idsnort-process-idtimeout-delayAAB-threshold

  • %ASA-3-861001: AVC: Creating AVC app directory directory_name failed; reason_string.

  • %ASA-3-861002: AVC: Downloading file from link link to directory directory_name succeeded.

  • %ASA-3-861003: AVC: Downloading file from link link to directory directory_name failed; reason_string.

  • %ASA-3-861004: AVC: Getting VDB version from file file failed; reason_string.

  • %ASA-3-861005: AVC: Getting VDB file path from file file failed; reason_string.

  • %ASA-3-861006: AVC: Getting VDB file name from file file failed; reason_string.

  • %ASA-3-861008: AVC Loading network service (app) definition file (file) success.

  • %ASA-3-861010: AVC: Loading app category definition file warning; reason_string.

  • %ASA-3-861013: AVC: Installing visibility NSG success.

  • %ASA-3-8300003: Failed to send session redistribution message to variable 1

  • %ASA-3-8300005: Failed to receive session move response from variable 1

Warning Messages, Severity 4

The following messages appear at severity 4, warning:

  • %ASA-4-105505: (Primary|Secondary) Failed to connect to peer unit peer-ip:port

  • %ASA-4-105524: (Primary|Secondary) Transitioning to Negotiating state due to the presence of another Active HA unit

  • %ASA-4-105553: (Primary|Secondary) Detected another Active HA unit

  • %ASA-4-106023: Deny interface_namesource_addresssource_portidfw_user

  • %ASA-4-106027: Deny int_type src src_address:src_mac dst dst_address:dest_mac by access-group "access-list name".

  • %ASA-4-106103: access-list acl_IDdeniedprotocolusernamesource_addresssource_port interface_nameinterface_namedest_addressdest_portinterface_namenumberfirst hithash code1hashcode2

  • %ASA-4-108004: action_class: action req_resp src_ifcsipsport dest_ifc dipdportfurther_info

  • %ASA-4-109017: User at IP_addresslimit

  • %ASA-4-109022: HTTPS proxy resource limit reached.

  • %ASA-4-109027: [ aaa protocolserver_IP_addressuser

  • %ASA-4-109028: aaa bypassed for same-security traffic from ingress_interfacesource_addresssource_portegress_interfacedest_addressdest_port

  • %ASA-4-109030: Autodetect ACL convert wildcard did not convert ACL access_list sourcedestnetmask

  • %ASA-4-109031: NT Domain Authentication Failed: rejecting guest login for username

  • %ASA-4-109033: Authentication failed for admin user usersrc_IPprotocol

  • %ASA-4-109040: User at IP

  • %ASA-4-109034: Authentication failed for network user usersrc_IPportdst_IPportprotocol

  • %ASA-4-109102: Received CoA action-typecoa-source-ipaudit-session-id

  • %ASA-4-113019: Group = groupusernamepeer_addresstypedurationcountcountreason

  • %ASA-4-113026: Error errortunnel group

  • %ASA-4-113029: Group groupuseripaddrnum

  • %ASA-4-113030: Group groupuseripaddracl

  • %ASA-4-113031: Group groupuseripaddrAnyConnectfilter

  • %ASA-4-113032: Group groupuseripaddrAnyConnectfilter

  • %ASA-4-113034: Group groupuseripaddracl

  • %ASA-4-113035: Group group User user IP ip_address Session terminated: AnyConnect not enabled or invalid AnyConnect image on the device_name

  • %ASA-4-113036: Group groupuseripaddrname

  • %ASA-4-113038: Group groupuseripaddrAnyConnect parent

  • %ASA-4-113040: Group groupuseripaddrattempted grouplocked group.

  • %ASA-4-113041: Redirect ACL configured for assigned IP

  • %ASA-4-113042: Non-HTTP connection from src_ifsrc_ipsrc_portdest_ifdest_ipdest_port

  • %ASA-4-115002: Warning in process: process name fiber: fiber name, component: component name, subcomponent: subcomponent name, file: filename, line: line number, cond: condition

  • %ASA-4-120004: Call-Home grouptitlereason

  • %ASA-4-120005: Call-Home groupdestinationreason

  • %ASA-4-120006: Call-Home groupdestinationreason

  • %ASA-4-120011: To ensure Smart Call Home can properly communicate with Cisco, use the command \ to configure at least one DNS server.

  • %ASA-4-199016: syslog

  • %ASA-4-209003: Fragment database limit of number exceeded: src = source_address, dest = dest_address, proto = protocol, id = number

  • %ASA-4-209004: Invalid IP fragment, size = bytes exceeds maximum size = bytes: src = source_address, dest = dest_address, proto = protocol, id = number

  • %ASA-4-209005: Discard IP fragment set with more than number elements: src = Too many elements are in a fragment set.

  • %ASA-4-209006: Fragment queue threshold exceeded, dropped TCP fragment from IP address/port to IP address/port on outside interface.

  • %ASA-4-213007: L2TP: Failed to install Redirect URL: redirect URLnon_existassigned IP

  • %ASA-4-216004: prevented: error in function at file(line) - stack trace

  • %ASA-4-302034: Unable to Pre-allocate H323 GUP Connection for faddr interface_name:foreign_ip_address to laddr interface_name:local_ip_address/local_port

  • %ASA-4-302034: Unable to Pre-allocate H323 GUP Connection for faddr interface_name:foreign_ip_address/foreign_port to laddr interface_name:local_ip_address

  • %ASA-4-302310: SCTP packetsrc_ifcsrc_ipsrc_portdst_ifcdst_ipdst_port

  • %ASA-4-302311: Failed to create a new protocol connection from ingress_interface:source_ip/source_port to egress_interface:destination_ip/destination_port due to application cache memory allocation failure. The app-cache memory threshold level is threshold% and threshold check is enabled/disabled

  • %ASA-4-305021: Ports exhausted in pre-allocated PAT pool IP mapped_ip_address for host real_host_ip. Allocating from new PAT pool IP mapped_ip_address

  • %ASA-4-305022: Cluster unit unit_name has been allocated num_of_port_blocks port-blocks from ip_address on interface interface_name for PAT usage. All units should have at least min_num_of_port_blocks port-blocks

  • %ASA-4-308002: static global_addressinside_addressnetmaskglobal_addressinside_addressnetmask

  • %ASA-4-308003: WARNING: The enable password is not configured

  • %ASA-4-308004: The enable password has been configured by user admin

  • %ASA-4-313004: Denied ICMP type=icmp_type, from laddr source_ip_address on interface interface_name to destination_ip_address: no matching session

  • %ASA-4-313004: Denied ICMP type=icmp_type, from laddr source_ip_address on interface shared physical_interface_name to destination_ip_address: no matching session

  • %ASA-4-313005: No matching connection for ICMP error message: icmp_msg_infointerface_nameembedded_frame_info icmp_msg_info =

  • %ASA-4-313009: Denied invalid ICMP code icmp_code, for src_ifc:src_address/src_port (mapped_src_address/mapped_src_port) to dest_ifc:dest_address/dest_port (mapped_dest_address/mapped_dest_port) [(user)], ICMP id icmp_id, ICMP type icmp_type

  • %ASA-4-315009: SSH: connection timed out: username username , IP ip

  • %ASA-4-324302: Server=IPaddr:port, ID=id: Rejecting the RADIUS response: Reason.

  • %ASA-4-325002: Duplicate address ipv6_addressMAC_addressinterface

  • %ASA-4-325004: IPv6 Extension Header hdr_typeactionprotocolsrc_intsrc_ipv6_addrsrc_portdst_interfacedst_ipv6_addrdst_port

  • %ASA-4-325005: Invalid IPv6 Extension Header Content:stringdetail regarding protocolingress interfaceIPportegress interfaceIPport

  • %ASA-4-325006: IPv6 Extension Header not in order: Type hdr_typehdr_typeprotsrc_intsrc_ipv6_addrsrc_portdst_interfacedst_ipv6_addrdst_port

  • %ASA-4-335005: NAC Downloaded ACL parse failure - host-address

  • %ASA-4-337005: Phone Proxy SRTP: Media session not found for media_term_ip/media_term_port for packet from in_ifc:src_ip/src_port to out_ifc:dest_ip/dest_port

  • %ASA-4-338001: Dynamic Filter monitoredprotocolin_interfacesrc_ip_addrsrc_portmapped-ipmapped-port)out_interfacedest_ip_addrdest_portmapped-ipmapped-port), malicious addresslocal or dynamicdomain name level_value category_name

  • %ASA-4-338002: Dynamic Filter monitoredprotocolin_interfacesrc_ip_addrsrc_portmapped-ipmapped-portout_interfacedest_ip_addrdest_portmapped-ipmapped-portmalicious addresslocal or dynamicdomain namelevel_valuecategory_name

  • %ASA-4-338003: Dynamic Filter monitoredprotocolin_interfacesrc_ip_addrsrc_portmapped-ipmapped-port)out_interfacedest_ip_addrdest_portmapped-ipmapped-port) malicious addresslocal or dynamicip address netmask level_value category_name

  • %ASA-4-338004: Dynamic Filter monitoredprotocolin_interfacesrc_ip_addrsrc_portmapped-ipmapped-portout_interfacedest_ip_addrdest_portmapped-ipmapped-portmalicious addresslocal or dynamicip addressnetmasklevel_valuecategory_name

  • %ASA-4-338005: Dynamic Filter droppedprotocolin_interfacesrc_ip_addrsrc_portmapped-ipmapped-portout_interfacedest_ip_addrdest_portmapped-ipmapped-portmalicious addresslocal or dynamicdomain name level_valuecategory_name

  • %ASA-4-338006: Dynamic Filter droppedprotocolin_interfacesrc_ip_addrsrc_portmapped-ipmapped-portout_interfacedest_ip_addrdest_portmapped-ipmapped-portmalicious addresslocal or dynamicdomain name level_value category_name

  • %ASA-4-338007: Dynamic Filter droppedprotocolin_interfacesrc_ip_addrsrc_portmapped-ipmapped-portout_interfacedest_ip_addrdest_portmapped-ipmapped-portmalicious addresslocal or dynamicip addressnetmask level_value category_name

  • %ASA-4-338008: Dynamic Filter droppedprotocolin_interfacesrc_ip_addrsrc_portmapped-ipmapped-portout_interfacedest_ip_addrdest_portmapped-ipmapped-portmalicious addresslocal or dynamicip addressnetmask level_value category_name

  • %ASA-4-338101: Dynamic Filter action whitelisted protocol traffic from in_interface:src_ip_addr/src_port (mapped-ip/mapped-port) to out_interface:dest_ip_addr/dest_port (mapped-ip/mapped-port), source malicious address resolved from local or dynamic list: domain name

  • %ASA-4-338102: Dynamic Filter actionprotocolin_interfacesrc_ip_addrsrc_portmapped-ipmapped-portout_interfacedest_ip_addrdest_portmapped-ipmapped-portmalicious addresslocal or dynamicdomain name

  • %ASA-4-338103: Dynamic Filter actionprotocolin_interfacesrc_ip_addrsrc_portmapped-ipmapped-port)out_interfacedest_ip_addrdest_portmapped-ipmapped-portmalicious addresslocal or dynamicip addressnetmask

  • %ASA-4-338104: Dynamic Filter actionprotocolin_interfacesrc_ip_addrsrc_portmapped-ipmapped-portout_interfacedest_ip_addrdest_portmapped-ipmapped-portmalicious addresslocal or dynamicip addressnetmask

  • %ASA-4-338201: Dynamic Filter monitoredprotocolin_interfacesrc_ip_addrsrc_portmapped-ipmapped-port)out_interfacedest_ip_addrdest_portmapped-ipmapped-port) malicious addresslocal or dynamicdomain name level_value category_name

  • %ASA-4-338202: Dynamic Filter monitoredprotocolin_interfacesrc_ip_addrsrc_portmapped-ipmapped-portout_interfacedest_ip_addrdest_portmapped-ipmapped-portmalicious addresslocal or dynamicdomain name level_value category_name

  • %ASA-4-338203: Dynamic Filter droppedprotocolin_interfacesrc_ip_addrsrc_portmapped-ipmapped-portout_interfacedest_ip_addrdest_portmapped-ipmapped-portmalicious addresslocal or dynamicdomain name level_value category_name

  • %ASA-4-338204: Dynamic Filter droppedprotocolin_interfacesrc_ip_addrsrc_portmapped-ipmapped-portout_interfacedest_ip_addrdest_portmapped-ipmapped-portmalicious addresslocal or dynamicdomain name level_valuecategory_name

  • %ASA-4-338301: Intercepted DNS reply for name namein_interfacesrc_ip_addrsrc_portout_interfacedest_ip_addrdest_portlist

  • %ASA-4-4000nn: IPS:number string from IP_address to IP_address on interface interface_name

  • %ASA-4-401001: Shuns cleared

  • %ASA-4-401002: Shun added: IP_addressIP_addressport port

  • %ASA-4-401003: Shun deleted: IP_address

  • %ASA-4-401004: Shunned packet: IP_addressIP_addressinterface_name

  • %ASA-4-401005: Shun add failed: unable to allocate resources for IP_address IP_address portport

  • %ASA-4-402114: IPSEC: Received an protocolspiseq_numremote_IPlocal_IP

  • %ASA-4-402115: IPSEC: Received a packet from remote_IPlocal_IPact_protexp_prot

  • %ASA-4-402116: IPSEC: Received an protocol packet (SPI= spi, sequence number= seq_num) from remote_ip (user= username) to local_ip. The decapsulated inner packet doesn't match the negotiated policy in the SA. The packet specifies its destination as pkt_daddr, its source as pkt_saddr, and its protocol as pkt_prot. The SA specifies its local proxy as id_daddr/id_dmask/id_dprot/id_dport and its remote_proxy as id_saddr/id_smask/id_sprot/id_sport.

  • %ASA-4-402117: IPSEC: Received a non-IPSec packet (protocol= protocolremote_IPlocal_IP

  • %ASA-4-402118: IPSEC: Received an protocolspiseq_numremote_IPusernamelocal_IPfrag_lenfrag_offset

  • %ASA-4-402119: IPSEC: Received an protocolspiseq_numremote_IPusernamelocal_IP

  • %ASA-4-402120: IPSEC: Received an protocolspiseq_numremote_IPusernamelocal_IP

  • %ASA-4-402121: IPSEC: Received an protocolspiseq_numpeer_addrusernamelcl_addrdrop_reason

  • %ASA-4-402122: IPSEC: Received a cleartext packet from src_addrdest_addrdrop_reason

  • %ASA-4-402123: CRYPTO: The accel_typeeror_typeerror_stringcommand namecommand

  • %ASA-4-402124: CRYPTO: The platform hardware accelerator encountered an error (HWErrAddr= 0xerror_address, Core= error_core, HwErrCode= error_code, IstatReg= 0xIstat, PciErrReg= 0xPCI, CoreErrStat= 0xcore_error_stat, CoreErrAddr= 0xcore_err_address, Doorbell Size[0]= size, DoorBell Outstanding[0]= outstanding, Doorbell Size[1]= size, DoorBell Outstanding[1]= outstanding, SWReset= Reset_code)

  • %ASA-4-402124: CRYPTO: The platform hardware accelerator encountered an error (HWErrAddr= 0xerror_address, Core= error_core, HwErrCode= error_code, Queue= queue_string (0), IstatReg= 0xIstat, Station= core_station, CoreRptr= 0xcore_pointer, CoreConfig= 0xcore_config_pointer, SWReset= Reset_code)

  • %ASA-4-402125: The platform hardware accelerator ring_string ring timed out (Desc= 0xdescriptor_address, CtrlStat= 0xcontrol_or_status value, ResultP= 0xsuccess_pointer, ResultVal= success_value, Cmd= 0xcrypto_command, CmdSize= command_size, Param= 0xcommand_parameters, Dlen= Data_length, DataP= 0xData_pointer, CtxtP= 0xVPN_context_pointer, SWReset= reset_number)

  • %ASA-4-402126: CRYPTO: The platformArchive FilenameCisco

  • %ASA-4-402127: CRYPTO: The platformmax_numberarchive_directoryArchive Directory

  • %ASA-4-402131: CRYPTO: statusaccel_instanceold_config_biasnew_config_bias

  • %ASA-4-403101: PPTP session state not established, but received an XGRE packet, tunnel_id=numbernumber

  • %ASA-4-403102: PPP virtual interface interface_nameprotocolreason

  • %ASA-4-403103: PPP virtual interface max connections reached

  • %ASA-4-403104: PPP virtual interface interface_name

  • %ASA-4-403106: PPP virtual interface interface_name

  • %ASA-4-403107: PPP virtual interface interface_name

  • %ASA-4-403108: PPP virtual interface interface_name

  • %ASA-4-403109: Rec'd packet not a PPTP packet.\n\t(ip) dest_addr= ipdest_addresssource_address

  • %ASA-4-403110: PPP virtual interface interface_nameuser

  • %ASA-4-403505: PPPoEIP_addressinterface_nameinterface

  • %ASA-4-403506: PPPoEIP_addressnetmaskinterface interface_name

  • %ASA-4-405001: Received ARP {request | response} collision from ip_address/MAC_address on interface interface_name with existing ARP entry ip_address/MAC_address

  • %ASA-4-405002: Received mac mismatch packet from IP_address/{MAC_bytes|MAC_address} for authenticated host

  • %ASA-4-405003: IP address collision detected between host IP_address at MAC_address and interface interface_name, MAC_address.

  • %ASA-4-405101: Unable to Pre-allocate H225 Call Signalling Connection for faddr foreign_ip_address to laddr local_ip_address/local_port

  • %ASA-4-405101: Unable to Pre-allocate H225 Call Signalling Connection for faddr foreign_ip_address/foreign_port to laddr local_ip_address

  • %ASA-4-405102: Unable to Pre-allocate H245 Connection for faddr foreign_ip_address to laddr local_ip_address/local_port

  • %ASA-4-405102: Unable to Pre-allocate H245 Connection for faddr foreign_ip_address/foreign_port to laddr local_ip_address

  • %ASA-4-405103: H225 message from source_addresssource_portdest_addressdest_porthex

  • %ASA-4-405104: H225 message stringoutside_addressoutside_portinside_addressinside_port

  • %ASA-4-405105: H323 RAS message AdmissionConfirm received from source_addresssource_portdest_addressdest_port

  • %ASA-4-405106: H323 num channel is not created from %I/%d to %I/%d %s

  • %ASA-4-405107: H245 Tunnel is detected and connection dropped from %I/%d to %I/%d %s

  • %ASA-4-405201: ILS ILS_message_typeinside_interfacesource_IP_addressportoutside_interfacedestination_IP_addressportembedded_IP_address

  • %ASA-4-405300: Radius Accounting Request received from from_addr

  • %ASA-4-405301: Attribute attribute_numberuser_ip

  • %ASA-4-406001: FTP port command low port: IP_addressportIP_addressinterface_name

  • %ASA-4-406002: FTP port command different address: IP_addressIP_addressIP_addressinterface_name

  • %ASA-4-407001: Deny traffic for local-host interface_nameinside_addressnumber

  • %ASA-4-407002: Embryonic limit for through connections exceeded nconnselimitoutside_addressoutside_portglobal_addressinside_addressinside_portinterface_name

  • %ASA-4-407003: Established limit for RPC services exceeded

  • %ASA-4-408001: IP route counter negative

  • %ASA-4-408101: KEYMAN : Type encrption_type encryption unknown. Interpreting keystring as literal.

  • %ASA-4-408102: KEYMAN : Bad encrypted keystring for key id key id

  • %ASA-4-409014: No valid authentication [send] key is available on interface nameif

  • %ASA-4-409015: Key ID key-id received on interface nameif

  • %ASA-4-409016: Key chain name key-chain-name on nameif  is invalid

  • %ASA-4-409017: Key ID key-id in key chain key-chain-name is invalid.

  • %ASA-4-409023: Attempting AAA Fallback method method_namerequest_typeuserAuth-server

  • %ASA-4-410001: Dropped UDP DNS requestsource_interfacesource_addresssource_portdest_interfacedest_addressdest_portlabel | domain-name numberremaining packet lengthnumber

  • %ASA-4-410003: action_classactionquery_responsesrc_ifcsipsportdest_ifcdipdport

  • %ASA-4-411001: Line protocol on Interface interface_name

  • %ASA-4-411002: Line protocol on Interface interface_name

  • %ASA-4-411003: Interface interface_name

  • %ASA-4-411004: Interface interface_name

  • %ASA-4-411005: Interface variable 1

  • %ASA-4-412001: MAC MAC_addressinterface_1interface_2

  • %ASA-4-412002: Detected bridge table full while inserting MAC MAC_addressinterfacenum

  • %ASA-4-413001: Module module_iderrnummessage

  • %ASA-4-413002: Module module_iderrnum message

  • %ASA-4-413003: Module string one

  • %ASA-4-413004: Module in slot string onenewververreason

  • %ASA-4-413005: Module module_idapp_nameapp_versapp_type

  • %ASA-4-413006: prod-idslotprod-idrunning-versslotprod-idrequired-vers

  • %ASA-4-413009: internal interface

  • %ASA-4-415016: policy-map map_nameconnection_actionint_typeIP_addressport_numint_typeIP_addressport_num

  • %ASA-4-416001: Dropped UDP SNMP packet from source_interfacesource_IPsource_portdest_interfacedest_addressdest_portprot_version

  • %ASA-4-417001: Unexpected event received: number

  • %ASA-4-417004: Filter violation error: conn number (string:string) in string

  • %ASA-4-417006: No memory for string in string (warning)

  • %ASA-4-418001: Through-the-device packet to/from management-only network is denied: protocol_string

  • %ASA-4-419001: Dropping TCP packet from src_ifcsrc_IPsrc_portdest_ifcdest_IPdest_portreasonsizesize

  • %ASA-4-419002: Duplicate TCP SYN from in_interfacesrc_addresssrc_portout_interfacedest_addressdest_port

  • %ASA-4-419003: Cleared TCP urgent flag from out_ifc:src_ip/src_port to in_ifc:dest_ip/dest_port

  • %ASA-4-420002: IPS requested to drop ICMPifc_inSIPportifc_outDIPport

  • %ASA-4-420003: IPS requested to reset TCP connection from ifc_inSIPSPORTifc_outDIPDPORT

  • %ASA-4-420007: application-stringslot_idslot_id

  • %ASA-4-422004: IP SLA Monitor number0: Duplicate event received. Event number number1

  • %ASA-4-422005: IP SLA Monitor Probe(s) could not be scheduled because clock is not set.

  • %ASA-4-422006: IP SLA Monitor Probe number: string

  • %ASA-4-423001: {Allowed | Dropped}pkt_type_nameerror_reason_strifc_nameip_addressportifc_nameip_addressport

  • %ASA-4-423002: {Allowed | Dropped}pkt_type_nameerror_reason_strifc_nameip_addressportifc_nameip_addressport

  • %ASA-4-423003: {Allowed | Dropped}pkt_type_nameerror_reason_strifc_nameip_addressportifc_nameip_addressport

  • %ASA-4-423004: {Allowed | Dropped}pkt_type_nameerror_reason_strifc_nameip_addressportifc_nameip_addressport

  • %ASA-4-423005: {Allowed | Dropped}pkt_type_nameerror_reason_strifc_nameip_addressportifc_nameip_addressport

  • %ASA-4-424001: Packet denied: protocol_stringintf_in

  • %ASA-4-424002: Connection to the backup interface is denied: protocol_string

  • %ASA-4-426004: PORT-CHANNEL:Interface ifc_name1ifc_namespeed ofifc_name1 X MbpsY1000 Mbps

  • %ASA-4-429002: CX requested to drop protocolinterface_nameip_addressportinterface_nameip_addressport

  • %ASA-4-429003: CX requested to reset TCP connection from interface_nameip_addrportinterface_nameip_addrport

  • %ASA-4-429007: CXSC redirect will override Scansafe redirect for flow from interface_name:ip_address/port to interface_name:ip_address/port [(username)]

  • %ASA-4-429008: Unable to respond to VPN query from CX for session 0x%x. Reason %s

  • %ASA-4-431001: RTP conformance: Dropping RTP packet from in_ifc:src_ip/src_port to out_ifc:dest_ip/dest_port, Drop reason: drop_reason value

  • %ASA-4-431002: RTCP conformance: Dropping RTCP packet from in_ifc:src_ip/src_port to out_ifc:dest_ip/dest_port, Drop reason: drop_reason value

  • %ASA-4-434001: SFR card not up and fail-close mode used, dropping protocolingresssourceIP addresssource portegress interfacedestination IP address

  • %ASA-4-434002: SFR requested to drop protocolingress interfacesource IP addresssource portegress interfacedestination IP addressdestination port

  • %ASA-4-434003: SFR requested to reset TCP connection from ingress interfacesource IP addresssource port egressinterfacedestination IP address

  • %ASA-4-434007: SFR redirect will override Scansafe redirect for flow from inside_interface:source_ip_address/source_port to outside_interface:destination_IP_address/destination_port [(user)]

  • %ASA-4-444005: Timebased license key xxxxxxxxxxxxxxxnum

  • % ASA-4-444008: license-type license has expired, and the system is scheduled to reload in number days. Apply a new activation key to enable license-type license and prevent the automatic reload.

  • %ASA-4-444106: Shared license backup server address

  • %ASA-4-444109: Shared license backup server role change to state

  • %ASA-4-444110: Shared license server backup has days

  • %ASA-4-444304: %SMART_LIC-4-IN_OVERAGE: One or more entitlements are in overage.

  • %ASA-4-446001: Maximum TLS Proxy session limit of max_sess

  • %ASA-4-446003: Denied TLS Proxy session from src_int:src_ip/src_port to dst_int:dst_ip/dst_port, UC-IME license is disabled.

  • %ASA-4-447001: ASP DP to CP queue_name was full. Queue length length, limit limit

  • %ASA-4-448001: Denied SRTP crypto session setup on flow from src_intsrc_ipsrc_portdst_intdst_ipdst_portlimit

  • %ASA-4-450001: Deny traffic for protocol protocol_id src interface_name:IP_address/port dst interface_name:IP_address/port, licensed host limit of num exceeded.

  • %ASA-4-450002: Teardown string connection connection for interface:address/port to interface:address/port duration hh:mm:ss bytes bytes reason reason_string

  • %ASA-4-500004: Invalid transport field for protocol=protocolsource_addresssource_portdest_addressdest_port

  • %ASA-4-500006: For flow inside:IP Address/port to outside:IP Address/port :existing flow message:connection id

  • %ASA-4-507002: Data copy in proxy-mode exceeded the buffer limit

  • %ASA-4-603110: Failed to establish L2TP session, tunnel_id = tunnel_idpeer_ipusername

  • %ASA-4-604105: Unable to send DHCP reply to client hardware_addressinterface_nameoptions_field_sizenumber_of_octets

  • %ASA-4-607002: action_classactionreq_respreq_resp_infosrc_ifcsipsportdest_ifcdipdport

  • %ASA-4-607004: Phone Proxy: Dropping SIP message from src_ifsrc_ipsrc_portdest_ifdest_ipdest_portmac_address

  • %ASA-4-608002: Dropping Skinny message for in_ifcsrc_ipsrc_portout_ifcdest_ipdest_portvalue

  • %ASA-4-608003: Dropping Skinny message for in_ifcsrc_ipsrc_portout_ifcdest_ipdest_portvalue

  • %ASA-4-608004: Dropping Skinny message for in_ifcsrc_ipsrc_portout_ifcdest_ipdest_portvalue

  • %ASA-4-608005: Dropping Skinny message for in_ifcsrc_ipsrc_portout_ifcdest_ipdest_portvalue

  • %ASA-4-612002: Auto Update failed: filenamenumberreason

  • %ASA-4-612003: Auto Update failed to contact: urlreason

  • %ASA-4-613017: Bad LSA mask: Type number, LSID IP_address Mask mask from IP_address

  • %ASA-4-613018: Maximum number of non self-generated LSA has been exceeded “OSPF number” - number LSAs

  • %ASA-4-613019: Threshold for maximum number of non self-generated LSA has been reached "OSPF number" - number LSAs

  • %ASA-4-613021: Packet not written to the output queue

  • %ASA-4-613022: Doubly linked list linkage is NULL

  • %ASA-4-613023: Doubly linked list prev linkage is NULL number

  • %ASA-4-613024: Unrecognized timer number in OSPF string

  • %ASA-4-613025: Invalid build flag number for LSA IP_address, type number

  • %ASA-4-613026: Can not allocate memory for area structure

  • %ASA-4-613030: Router is currently an ASBR while having only one area which is a stub area

  • %ASA-4-613031: No IP address for interface inside

  • %ASA-4-613036: Can not use configured neighbor: cost and database-filter options are allowed only for a point-to-multipoint network

  • %ASA-4-613037: Can not use configured neighbor: poll and priority options are allowed only for a NBMA network

  • %ASA-4-613038: Can not use configured neighbor: cost or database-filter option is required for point-to-multipoint broadcast network

  • %ASA-4-613039: Can not use configured neighbor: neighbor command is allowed only on NBMA and point-to-multipoint networks

  • %ASA-4-613040: OSPF-1 Area string: Router IP_address originating invalid type number LSA, ID IP_address, Metric number on Link ID IP_address Link Type number

  • %ASA-4-613042: OSPF process number lacks forwarding address for type 7 LSA IP_address in NSSA string - P-bit cleared

  • %ASA-4-620002: Drop CTIQBE packet from interface_name:ip_address/port to interface_name:ip_address/port Reason: reason_string

  • %ASA-4-709008: (Primary | Secondary) Configuration sync in progress. Command: ‘command’ executed from (terminal/http) will not be replicated to or executed by the standby unit.

  • %ASA-4-709013: Failover configuration replication hash comparison timeout expired failover_state

  • %ASA-4-711002: Task ran for elapsed_timeprocess_namePCtraceback

  • %ASA-4-711004: Task ran for msecprocess_namepccall stack

  • %ASA-4-713154: DNS lookup for peer_description Server [server_name ] failed!

  • %ASA-4-713157: IP = peerIP Timed out on initial contact to server [server_name or IP_address ] Tunnel could not be established.

  • %ASA-4-713207: Group = groupname, Username = username, IP = peerIP Terminating connection: IKE Initiator and tunnel group specifies L2TP Over IPSec

  • %ASA-4-713241: IE Browser Proxy Method setting_number is Invalid

  • %ASA-4-713242: Group = groupname, Username = username, IP = peerIP Remote user is authenticated using Hybrid Authentication. Not starting IKE rekey.

  • %ASA-4-713243: META-DATA Unable to find the requested certificate

  • %ASA-4-713244: Group = groupname, Username = username, IP = peerIP META-DATA Received Legacy Authentication Method(LAM) type type is different from the last type received type .

  • %ASA-4-713245: Group = groupname, Username = username, IP = peerIP META-DATA Unknown Legacy Authentication Method(LAM) type type received.

  • %ASA-4-713246: Group = groupname, Username = username, IP = peerIP META-DATA Unknown Legacy Authentication Method(LAM) attribute type type received.

  • %ASA-4-713247: Group = groupname, Username = username, IP = peerIP META-DATA Unexpected error: in Next Card Code mode while not doing SDI.

  • %ASA-5-713248: Group = groupname, Username = username, IP = peerIP META-DATA Rekey initiation is being disabled during CRACK authentication.

  • %ASA-4-713249: Group = groupname, Username = username, IP = peerIP META-DATA Received unsupported authentication results: result

  • %ASA-4-713251: Group = groupname, Username = username, IP = peerIP META-DATA Received authentication failure message

  • %ASA-4-713255: IP = peer-IP IP = peer-IP, Received ISAKMP Aggressive Mode message 1 with unknown tunnel group name group-name

  • %ASA-4-713261: IPV6 address on output interface interface_number was not found

  • %ASA-4-713903: Group = group policy, Username = user name, IP = remote IP, ERROR: Failed to install Redirect URL: redirect URL Redirect ACL: non_exist for assigned IP.

  • %ASA-4-716007: Group groupuserIP

  • %ASA-4-716022: Unable to connect to proxy server reason

  • %ASA-4-716023: Group nameuseripmaximum_sessions

  • %ASA-4-716044: Group group-nameuser-nameIP_addressparam-nameparam-value

  • %ASA-4-716045: Group group-nameuser-nameIP_addressparam-name

  • %ASA-4-716046: Group group-nameuser-nameIP_addressaccess-list-name

  • %ASA-4-716047: Group group-nameuser-nameIP_addressaccess-list-name

  • %ASA-4-716048: Group group-nameuser-nameIP_address

  • %ASA-4-716052: Group group-nameuser-nameIP_address

  • %ASA-4-716165: SAML assertion cannot be replay protected because it does not contain time constraints

  • %ASA-4-717026: Name lookup failed for hostname hostname

  • %ASA-4-717031: Failed to find a suitable trustpoint for the issuer: issuer Reason: reason_string

  • %ASA-4-717035: OCSP status is being checked for certificate. certificate_identifier.

  • %ASA-4-717037: Tunnel group search using certificate maps failed for peer certificate: certificate_identifier

  • %ASA-4-717052: Group group nameuser nameIP Addressid subject nameid issuer nameid serial number

  • %ASA-4-720001: (VPN-unit) Failed to initialize with Chunk Manager.

  • %ASA-4-720007: (VPN-unit) Failed to allocate chunk from Chunk Manager.

  • %ASA-4-720008: (VPN-unit) Failed to register to High Availability Framework.

  • %ASA-4-720009: (VPN-unit) Failed to create version control block.

  • %ASA-4-720011: (VPN-unit) Failed to allocate memory

  • %ASA-4-720013: (VPN-unit) Failed to insert certificate in trust point trustpoint_name

  • %ASA-4-720022: (VPN-unit) Cannot find trust point trustpoint

  • %ASA-4-720033: (VPN-unit) Failed to queue add to message queue.

  • %ASA-4-720038: (VPN-unit) Corrupted message from active unit.

  • %ASA-4-720043: (VPN-unit) Failed to send type message id to standby unit

  • %ASA-4-720044: (VPN-unit) Failed to receive message from active unit

  • %ASA-4-720047: (VPN-unit) Failed to sync SDI node secret file for server IP_address on the standby unit.

  • %ASA-4-720051: (VPN-unit) Failed to add new SDI node secret file for server id on the standby unit.

  • %ASA-4-720052: (VPN-unit) Failed to delete SDI node secret file for server id on the standby unit.

  • %ASA-4-720053: (VPN-unit) Failed to add cTCP IKE rule during bulk sync, peer=IP_address, port=port

  • %ASA-4-720054: (VPN-unit) Failed to add new cTCP record, peer=IP_address, port=port.

  • %ASA-4-720055: (VPN-unit) VPN Stateful failover can only be run in single/non-transparent mode.

  • %ASA-4-720064: (VPN-unit) Failed to update cTCP database record for peer=IP_address, port=port during bulk sync.

  • %ASA-4-720065: (VPN-unit) Failed to add new cTCP IKE rule, peer=peer, port=port.

  • %ASA-4-720066: (VPN-unit) Failed to activate IKE database.

  • %ASA-4-720067: (VPN-unit) Failed to deactivate IKE database.

  • %ASA-4-720068: (VPN-unit) Failed to parse peer message.

  • %ASA-4-720069: (VPN-unit) Failed to activate cTCP database.

  • %ASA-4-720070: (VPN-unit) Failed to deactivate cTCP database.

  • %ASA-4-720073: VPN Session failed to replicate - ACL acl_name not found

  • %ASA-4-721007: (device) Fail to update access list list_name on standby unit.

  • %ASA-4-721011: (device) Fail to add access list rule list_name, line line_no on standby unit.

  • %ASA-4-721013: (device) Fail to enable APCF XML file file_name on the standby unit.

  • %ASA-4-721015: (device) Fail to disable APCF XML file file_name on the standby unit.

  • %ASA-4-721017: (device) Fail to create WebVPN session for user user_name, IP ip_address.

  • %ASA-4-721019: (device) Fail to delete WebVPN session for client user user_name, IP ip_address.

  • %ASA-4-722001: IP IP_address

  • %ASA-4-722002: IP IP_address

  • %ASA-4-722003: IP IP_address

  • %ASA-4-722004: Group groupuser-nameIP_address

  • %ASA-4-722015: Group groupuser-nameIP_addresstype-num

  • %ASA-4-722016: Group groupuser-nameIP_addresslengthexpected-length

  • %ASA-4-722017: Group groupuser-nameip_addressxxxxxxxx

  • %ASA-4-722018: Group groupuser-nameIP_addressversionexpected

  • %ASA-4-722019: Group groupuser-nameIP_addresslength

  • %ASA-4-722039: Group groupuseripacl

  • %ASA-4-722040: Group groupuseripacl

  • %ASA-4-722041: TunnelGroup tunnel_groupgroup_policyusernamepeer_address

  • %ASA-4-722042: Group groupuseripCisco

  • %ASA-4-722047: Group groupuseripASA

  • %ASA-4-722048: Group groupuserip

  • %ASA-4-722049: Group groupuseripASA

  • %ASA-4-722050: Group group User user IP ip Session terminated: SVC not enabled for the user.

  • %ASA-4-722054: Group group policyuser nameremote IPredirect URLnon_existassigned IP

  • %ASA-4-722057: Group group policy User username IP client IP SVC terminating connection: Failed to bind SGT tag with assigned IP: assigned IP.

  • %ASA-4-724001: Group group-nameuser-nameIP_address

  • %ASA-4-724002: Group group-nameuser-nameIP_address

  • %ASA-4-733100: [Objectrate_IDrate_valrate_valrate_valrate_valtotal_cnt

  • %ASA-4-733101: Object objectIPrate_valrate_valrate_valrate_valtotal_cnt.

  • %ASA-4-733102: Threat-detection adds host host

  • %ASA-4-733103: Threat-detection removes host host

  • %ASA-4-733104: TCP Intercept SYN flood attack detected to host_ip/host_port (real_ip/real_port). Average rate of avg_rate SYNs/sec exceeded the threshold of threshold_rate.

  • %ASA-4-733105: TCP Intercept SYN flood attack detected to host_ip/host_port (real_ip/real_port). Burst rate of burst_rate SYNs/sec exceeded the threshold of threshold_rate.

  • (For IKEv2 connection requests) %ASA-4-733201: Threat-detection: Service[remote-access-client-initiations] Peer[peer-ip]: failure threshold of threshold-value exceeded: adding shun to interface interface. IKEv2: RA excessive client initiation requests

  • (For SSL connection requests) %ASA-4-733201: Threat-detection: Service[remote-access-client-initiations] Peer[peer-ip]: failure threshold of value exceeded: adding shun to interface interface. SSL: RA excessive client initiation requests.

  • %ASA-4-735015: CPU var1var2var3

  • %ASA-4-735016: Chassis Ambient var1var2var3

  • %ASA-4-735018: Power Supply var1var2var3

  • %ASA-4-735019: Power Supply var1var2var3

  • %ASA-4-735026: IO Hub var1var2var3

  • %ASA-4-737012: IPAA: Session=session

  • %ASA-4-737013: IPAA: Session=sessionip-address

  • %ASA-4-737019: IPAA: Session=session

  • %ASA-4-737028: IPAA: Session= session

  • %ASA-4-737030: IPAA: Session=session, Unable to send {ip_address | ipv6_address} to standby: address in use

  • %ASA-4-737032: IPAA: Session= session

  • %ASA-4-737033: IPAA: Session= sessionaddr_allocatorip_addr

  • %ASA-4-737038: IPAA: Session=session, specified address ip-address was in-use, trying to get another.

  • % ASA-4-737203: VPNFIP: Pool=pool, WARN: message

  • % ASA-4-737402: POOLIP: Pool=pool, Failed to return ip-address to pool (recycle=recycle). Reason: message

  • % ASA-4-737404: POOLIP: POOLIP: Pool=pool, WARN: message

  • %ASA-4-741005: Coredump operation 'variable 1 variable 2 variable 3

  • %ASA-4-741006: Unable to write Coredump Helper configuration, reason variable 1

  • %ASA-4-746004: user-identity: Total number of activated user groups exceeds the maximum number of max_groups

  • %ASA-4-746006: user-identity: Out of sync with AD Agent, start bulk download

  • %ASA-4-746011: user-identity: Total number of users created exceeds the maximum number of max_users

  • %ASA-4-747008: Clustering: New cluster member name with serial number serial-number-A rejected due to name conflict with existing unit with serial number serial-number-B.

  • %ASA-4-747015: Clustering: Forcing stray member unit-name to leave the cluster.

  • %ASA-4-747016: Clustering: Found a split cluster with both unit-name-A and unit-name-B as master units. Master role retained by unit-name-A, unit-name-B will leave, then join as a slave.

  • %ASA-4-747017: Clustering: Failed to enroll unit unit-name due to maximum member limit limit-value reached.

  • %ASA-4-747019: Clustering: New cluster member name rejected due to Cluster Control Link IP subnet mismatch (ip-address/ip-mask on new unit, ip-address/ip-mask on local unit).

  • %ASA-4-747020: Clustering: New cluster member unit-name rejected due to encryption license mismatch.

  • %ASA-4-747025: Clustering: New cluster member unit-name rejected due to firewall mode mismatch.

  • %ASA-4-747026: Clustering: New cluster member unit-name rejected due to cluster interface name mismatch (ifc-name on new unit, ifc-name on local unit).

  • %ASA-4-747027: Clustering: Failed to enroll unit unit-name due to insufficient size of cluster pool pool-name in context-name.

  • %ASA-4-747028: Clustering: New cluster member unit-name rejected due to interface mode mismatch (mode-name on new unit, mode-name on local unit).

  • %ASA-4-747029: Clustering: Unit unit-name is quitting due to Cluster Control Link down.

  • %ASA-4-747034: Unit %s is quitting due to Cluster Control Link down (%d times after last rejoin). Rejoin will be attempted after %d minutes.

  • %ASA-4-747035: Unit %s is quitting due to Cluster Control Link down. Clustering must be manually enabled on the unit to rejoin.

  • %ASA-4-748002: Clustering configuration on the chassis is missing or incomplete; clustering is disabled.

  • %ASA-4-748003: Module slot_number in chassis chassis_number is leaving the cluster due to a chassis health check failure

  • %ASA-4-748201: Application name application on module module id in chassis chassis id is status.

  • %ASA-4-750003: Local: local IP:local port Remote: remote IP:remote port Username: username Negotiation aborted due to ERROR: error

  • %ASA-4-750012: Selected IKEv2 encryption algorithm (IKEV2 encry algo ) is not strong enough to secure proposed IPSEC encryption algorithm (IPSEC encry algo ).

  • %ASA-4-750014: Local:self ip:self port Remote:peer ip:peer port Username:TG or Username IKEv2 Session aborted. Reason: Initial Contact received for Local ID: self ID, Remote ID: peer ID from remote peer:peer ip:peer port to self ip:self port

  • %ASA-4-750015: Local:self ip:self port Remote:peer ip:peer port Username:TG or Username deleting IPSec SA. Reason: invalid SPI notification received for SPI 0xSPI; local traffic selector = Address Range: start address-end address Protocol: protocol number Port Range: start port-end port ; remote traffic selector = Address Range: start address-end address Protocol: protocol number Port Range: start port-end port

  • %ASA-4-751014: Warning Configuration Payload request for attribute attribute_id could not be processed. Error: error

  • %ASA-4-751015: SA request rejected by CAC. Reason: reason

  • %ASA-4-751016: Remote L2L Peer initiated a tunnel with same outer and inner addresses. Peer could be Originate Only - Possible misconfiguration!

  • %ASA-4-751019: Failed to obtain an licenseType license. Maximum license limit limit exceeded.

  • %ASA-4-751021: variable_1 variable_2 with variable_3 encryption is not supported with this version of the AnyConnect Client. Please upgrade to the latest Anyconnect Client.

  • %ASA-4-751027: Local:local IP:local port Remote:peer IP:peer port Username:username IKEv2 Received INVALID_SELECTORS Notification from peer. Peer received a packet (SPI=spi). The decapsulated inner packet didn’t match the negotiated policy in the SA. Packet destination pkt_daddr, port pkt_dest_port, source pkt_saddr, port pkt_src_port, protocol pkt_prot.

  • %ASA-4-752009: IKEv2 Doesn't support Multiple Peers

  • %ASA-4-752010: IKEv2 Doesn't have a proposal specified

  • %ASA-4-752011: IKEv1 Doesn't have a transform set specified

  • %ASA-4-752012: IKEv protocol was unsuccessful at setting up a tunnel. Map Tag = mapTag . Map Sequence Number = mapSeq .

  • %ASA-4-752013: Tunnel Manager dispatching a KEY_ACQUIRE message to IKEv2 after a failed attempt. Map Tag = mapTag . Map Sequence Number = mapSeq .

  • %ASA-4-752014: Tunnel Manager dispatching a KEY_ACQUIRE message to IKEv1 after a failed attempt. Map Tag = mapTag . Map Sequence Number = mapSeq .

  • %ASA-4-752017: IKEv2 Backup L2L tunnel initiation denied on interface interface matching crypto map name, sequence number number . Unsupported configuration.

  • %ASA-4-753001: Unexpected IKEv2 packet received from IP:port. Error: reason

  • %ASA-4-768003: SSH: connection timed out: username username, IP ip

  • %ASA-4-769009: UPDATE: Image booted image_name is different from boot images

  • %ASA-4-770001: ResourcelimitASA

  • %ASA-4-770003: Resource resource allocation is less than the minimum requirement of value for this platform. If this condition persists, performance will be lower than normal.

  • %ASA-4-775002: Scansafe: Reasonprotocol conn_id interface_namereal_addressreal_port idfw_userinterface_namereal_addressreal_port action

  • %ASA-4-775004: Scansafe: Primary server server-nameip_address

  • %ASA-4-776201: CTS Env: PAC for Server IP_addressPAC issuer namenumber

  • %ASA-4-776304: CTS Policy: Unresolved security-group name "sgname

  • %ASA-4-776305: CTS Policy: Security-group table cleared, all polices referencing security-group names will be deactivated

  • %ASA-4-776312: CTS Policy: Previously resolved security-group name "sgname

  • %ASA-4-802006: IP ip_address MDM request details has been rejected: details.

  • %ASA-4-812005: Link-State-Propagation activated on inline-pair due to failure of interface interface-name bringing down pair interface interface-name

  • %ASA-4-812006: Link-State-Propagation de-activated on inline-pair due to recovery of interface interface-name bringing up pair interface interface-name

  • %ASA-4-815003: Object-Group-Search threshold exceeded current value threshold (10000) for packet UDP from source IP address/port to destination IP address/port

  • %ASA-4-861011: AVC: Loading app category definition file file success.

  • %ASA-4-870001: policy-route path-monitoring, remote peer interface_name:IP_Address reachable_status.

  • %ASA-4-880002: Internal-Data no-buffer counter stats: counter stats

Notification Messages, Severity 5

The following messages appear at severity 5, notifications:

  • %ASA-5-105500: (Primary|Secondary) Started HA

  • %ASA-5-105501: (Primary|Secondary) Stopping HA

  • %ASA-5-105503: (Primary|Secondary) Internal state changed from previous_state to new_state

  • %ASA-5-105504: (Primary|Secondary) Connected to peer peer-ip:port

  • %ASA-5-105520: (Primary|Secondary) Responding to Azure Load Balancer probes

  • %ASA-5-105521: (Primary|Secondary) No longer responding to Azure Load Balancer probes

  • %ASA-5-105522: (Primary|Secondary) Updating route-table route_table_name

  • %ASA-5-105523: (Primary|Secondary) Updated route-table route_table_name

  • %ASA-5-105542: (Primary|Secondary) Enabling load balancer probe responses

  • %ASA-5-105543: (Primary|Secondary) Disabling load balancer probe responses

  • %ASA-5-105552: (Primary|Secondary) Stopped HA

  • %ASA-5-109012: Authen Session End: user 'usernumbernumber

  • %ASA-5-109029: Parsing downloaded ACL: string

  • %ASA-5-109039: AAA Authentication: Dropping an unsupported IPv6/IP46/IP64 packet from lifcladdrfifcfaddr

  • %ASA-5-109201: UAUTH: Session=session, User=username, Assigned IP=IP Address, Succeeded adding entry.

  • %ASA-5-109204: UAUTH: Session=session, User=username, Assigned IP=IP Address, Succeeded applying filter.

  • %ASA-5-109207: UAUTH: Session=session, User=username, Assigned IP=IP Address, Succeeded updating entry.

  • %ASA-5-109210: UAUTH: Session=session, User=username, Assigned IP=IP Address, Succeeded removing entry.

  • %ASA-5-111001: Begin configuration: IP_addressdevice

  • %ASA-5-111002: Begin configuration: ip_address reading from device

  • %ASA-5-111003: IP_address

  • %ASA-5-111004: IP_address{FAILED|OK}

  • %ASA-5-111005: IP_address

  • %ASA-5-111007: Begin configuration: IP_addressdevice

  • %ASA-5-111008: User 'userstring

  • %ASA-5-111010: User 'usernameapplication-nameip addrcmd

  • %ASA-5-113024: Group tgtypeipuser_name

  • %ASA-5-113025: Group tgfields connection typeip

  • %ASA-5-120001: Call-Home Module started.

  • %ASA-5-120002: Call-Home Module terminated.

  • %ASA-5-120008: Call-Home client client

  • %ASA-5-120009: Call-Home client client

  • %ASA-5-120012: User "usernamechoice

  • %ASA-5-121001: id

  • %ASA-5-121002: status.

  • %ASA-5-199001: Reloaded at time by user. Reload reason: reload reason

  • %ASA-5-199017: syslog

  • %ASA-5-199027: Restore operation was aborted at HH:MM:SS UTC DD:MM:YY.

  • %ASA-5-212009: Configuration request for SNMP group groupnameusernamereason

  • %ASA-5-303004: FTP cmd_stringsource_interfacesource_addresssource_portdest_interfacedest_addressdest_interface

  • %ASA-5-303005: Strict FTP inspection matched match_stringpolicy-nameaction_stringsrc_ifcsipsportdest_ifcdipdport

  • %ASA-5-304001: URLuser@source_addressidfw_userURLdest_addressurl

  • %ASA-5-304002: Access denied URL url SRC (user)(sip)(user) DEST dip on interface int_name

  • (ICMP) %ASA-5-305013: Asymmetric NAT rules matched for forward and reverse flows; Connection for icmp src interface_name:source_ip_addresssource_user dst interface_name:destination_ip_addressdestination_user (type type, code code) denied due to NAT reverse path failure

  • (TCP, UDP, SCTP) %ASA-5-305013: Asymmetric NAT rules matched for forward and reverse flows; Connection for "protocol" src interface_name:source_ip_address/source_portsource_user dst interface_name:destination_ip_address/destination_portdestination_user denied due to NAT reverse path failure


    Note


    Protocol in this error message can be TCP, UDP, or SCTP.


  • (Any Protocol) %ASA-5-305013: Asymmetric NAT rules matched for forward and reverse flows; Connection for protocol protocol_name src interface_name:source_ip_addresssource_user dst interface_name:destination_ip_addressdestination_user denied due to NAT reverse path failure

  • %ASA-5-321001: Resource var1 limit of var2 reached.

  • %ASA-5-321002: Resource var1 rate limit of var2 reached.

  • %ASA-5-324010: Subscriber IMSI PDP Context activated on network mcc

  • %ASA-5-324011: Subscriber IMSI location changed during mcc from mnc IE type

  • %ASA-5-324012: GTP_PARSE: GTP IE TYPE[GTP IE TYPE NUMBER]: Invalid Length Received Length: Length Received, Minimum Expected Length: Expected Length

  • %ASA-5-331002: Dynamic DNS typefqdn_nameip_address ip_address

  • %ASA-5-332003: Web Cache IP_addressservice_ID

  • %ASA-5-333002: Timeout waiting for EAP response - context:EAP-context

  • %ASA-5-333010: EAP-SQ response Validation Flags TLV indicates PV request - context:EAP-context

  • %ASA-5-334002: EAPoUDP association successfully established - host-address

  • %ASA-5-334003: EAPoUDP association failed to establish - host-address

  • %ASA-5-334005: Host put into NAC Hold state - host-address

  • %ASA-5-334006: EAPoUDP failed to get a response from host - host-address

  • %ASA-5-335002: Host is on the NAC Exception List - host-address, OS:oper-sys

  • %ASA-5-335003: NAC Default ACL applied, ACL:ACL-name - host-address

  • %ASA-5-335008: NAC IPSec terminate from dynamic ACL:ACL-name - host-address

  • %ASA-5-336010 EIGRP-ddb_name tableid as_id: Neighbor address (%interface) is event_msg: msg

  • %ASA-5-338302: Address ipaddrnamelist

  • %ASA-5-338303: Address ipaddrname)

  • %ASA-5-338308: Dynamic Filter updater server dynamically changed from old_server_hostold_server_portnew_server_hostnew_server_port

  • %ASA-5-402128: CRYPTO: An attempt to allocate a large memory block failed, size: sizelimit

  • %ASA-5-415004: HTTP - matched matched_stringmap_nameconnection_actionint_typeIP_addressport_numint_typeIP_addressport_num

  • %ASA-5-415005: HTTP - matched matched_stringmap_nameconnection_actionint_typeIP_addressport_numint_typeIP_addressport_num

  • %ASA-5-415006: HTTP - matched matched_stringmap_nameconnection_actionint_typeIP_addressport_numint_typeIP_addressport_num

  • %ASA-5-415007: HTTP - matched matched_stringmap_nameconnection_actionint_typeIP_addressport_numint_typeIP_addressport_num

  • %ASA-5-415008: HTTP - matched matched_stringmap_nameconnection_actionint_typeIP_addressport_numint_typeIP_addressport_num

  • %ASA-5-415009: HTTP - matched matched_stringmap_nameconnection_actionint_typeIP_addressport_numint_typeIP_addressport_num

  • %ASA-5-415010: matched matched_string in policy-map map_name, transfer encoding matched connection_action from int_type:IP_address/port_num to int_type:IP_address/port_num

  • %ASA-5-415011: HTTP - policy-map map_nameconnection_actionint_typeIP_addressport_numint_typeIP_addressport_num

  • %ASA-5-415012: HTTP - matched matched_stringmap_nameconnection_actionint_typeIP_addressport_numint_typeIP_addressport_num

  • %ASA-5-415013: HTTP - policy-map map-nameconnection_actionint_typeIP_addressport_numint_typeIP_addressport_num

  • %ASA-5-415014: HTTP - matched matched_stringmap_nameconnection_actionint_typeIP_addressport_numint_typeIP_addressport_num

  • %ASA-5-415015: HTTP - matched matched_stringmap_nameconnection_actionint_typeIP_addressport_numint_typeIP_addressport_num

  • %ASA-5-415018: HTTP - matched matched_stringmap_nameconnection_actionint_typeIP_addressport_numint_typeIP_addressport_num

  • %ASA-5-415019: HTTP - matched matched_stringmap_nameconnection_actionint_typeIP_addressport_numint_typeIP_addressport_num

  • %ASA-5-415020: HTTP - matched matched_stringmap_nameconnection_actionint_typeIP_addressport_numint_typeIP_addressport_num

  • %ASA-5-425005 Interface interface_name become active in redundant interface redundant_interface_name

  • %ASA-5-434004: SFR requested device to bypass further packet redirection and process protocol flow from inside_ifc_name:src_ip/src_port to outside_ifc_name:dst_ip/dst_port locally

  • %ASA-5-444100: Shared license requestreason

  • %ASA-5-444101: Shared license service is active. License server address: address

  • %ASA-5-444305: %SMART_LIC-5-SYSTEM_CLOCK_CHANGED: Smart Agent for Licensing System clock has been changed.

  • %ASA-5-444305: %SMART_LIC-5-IN_COMPLIANCE: All entitlements are authorized.

  • %ASA-5-444305: %SMART_LIC-5-EVAL_START: Entering evaluation period.

  • %ASA-5-444305: %SMART_LIC-5-AUTHORIZATION_EXPIRED: Authorization expired.

  • %ASA-5-444305: %SMART_LIC-5-COMM_RESTORED: Communications with Cisco licensing cloud restored.

  • %ASA-5-444305: %SMART_LIC-5-COMM_INIT_FAILED: Failed to initialize communications with the Cisco Licensing Cloud.

  • %ASA-5-500001: ActiveX content modified src forward_ip_address dest reverse_ip_address on interface interface_name

  • %ASA-5-500001: ActiveX content in java script is modified: src forward_ip_address dest reverse_ip_address on interface interface_name

  • %ASA-5-500002: Java content modified: src forward_ip_address dest reverse_ip_address on interface interface_name

  • %ASA-5-500002: Java content in java script is modified: src forward_ip_address dest reverse_ip_address on interface interface_name

  • %ASA-5-500003: Bad TCP hdr length (hdrlen=bytes, pktlen=bytes) from source_address/source_port to dest_address/dest_port, flags: tcp_flags, on interface interface_name

  • %ASA-5-501101: User transitioning priv level

  • %ASA-5-502101: New user added to local dbase: Uname: userprivilege_level

  • %ASA-5-502102: User deleted from local dbase: Uname: userprivilege_level

  • %ASA-5-502103: User priv level changed: Uname: userprivilege_levelprivilege_level

  • %ASA-5-502111: New group policy added: name: policy_namepolicy_type

  • %ASA-5-502112: Group policy deleted: name: policy_namepolicy_type

  • %ASA-5-503001: Process process_number, Nbr IP_address on interface_name from old_state to new_state, reason

  • %ASA-5-503002: Last valid authentication key for neighbor nameif expires

  • %ASA-5-503003: Expired key ID sent | received used by neighbor nameif

  • %ASA-5-503004: No key ID key-id for neighbor key-chain-name

  • %ASA-5-503005: No crypto algorithm for neighbor key-id key ID key-chain-name

  • %ASA-5-504001: Security context context_name

  • %ASA-5-504002: Security context context_name

  • %ASA-5-505001: Module string one

  • %ASA-5-505002: Module ips

  • %ASA-5-505003: Module string one

  • %ASA-5-505004: Module string one

  • %ASA-5-505005: Module module_name

  • %ASA-5-505006: Module string one

  • %ASA-5-505007: Module module_id

  • %ASA-5-505008: Module module_idnewverver

  • %ASA-5-505009: Module in slot string onenewverprevver

  • %ASA-5-505010: Module in slot slot

  • %ASA-5-505012: Module module_idapplicationver_numversion

  • %ASA-5-505013: Module module_idapplicationversionnewapplication

  • %ASA-5-506001: event_source_string event_string

  • %ASA-5-507001: Terminating TCP-Proxy connection from interface_insidesource_addresssource_portinterface_outsidedest_addressdest_portlimit

  • %ASA-5-508001: DCERPC message_typeversion_typeversion_numbersrc_ifsrc_ipsrc_portdest_ifdest_ipdest_port

  • %ASA-5-508002: DCERPC response has low endpoint port port_numbersrc_ifsrc_ipsrc_portdest_ifdest_ipdest_port

  • %ASA-5-509001: Connection attempt was prevented by \ command: src_intf

  • %ASA-5-503101: Process d, Nbr i on s from s to s, s

  • %ASA-5-611103: User logged out: Uname: user

  • %ASA-5-611104: Serial console idle timeout exceeded

  • %ASA-5-612001: Auto Update succeeded: filenamenumber

  • %ASA-5-711005: call_stack

  • %ASA-5-713006: Group = groupname, Username = username, IP = peerIP Failed to obtain state for message Id message_number, Peer Address: IP_address

  • %ASA-5-713010: Group = groupname, Username = username, IP = peerIP IKE area: failed to find centry for message Id message_number

  • %ASA-5-713041: Group = groupname, Username = username, IP = peerIP IKE Initiator: new or rekey Phase 1 or 2, Intf interface_number, IKE Peer IP_address local Proxy Address IP_address, remote Proxy Address IP_address, Crypto map (crypto map tag )

  • %ASA-5-713049: Group = groupname, Username = username, IP = peerIP Security negotiation complete for tunnel_type type (group_name ) Initiator /Responder, Inbound SPI = SPI, Outbound SPI = SPI

  • %ASA-5-713050: Group = groupname, Username = username, IP = peerIP Connection terminated for peer IP_address . Reason: termination reason Remote Proxy IP_address, Local Proxy IP_address

  • %ASA-5-713068: Group = groupname, Username = username, IP = peerIP Received non-routine Notify message: notify_type (notify_value)

  • %ASA-5-713073: Group = groupname, Username = username, IP = peerIP Responder forcing change of Phase 1 /Phase 2 rekeying duration from larger_value to smaller_value seconds

  • %ASA-5-713074: Group = groupname, Username = username, IP = peerIP Responder forcing change of IPsec rekeying duration from larger_value to smaller_value Kbs

  • %ASA-5-713075: Group = groupname, Username = username, IP = peerIP Overriding Initiator's IPsec rekeying duration from larger_value to smaller_value seconds

  • %ASA-5-713076: Group = groupname, Username = username, IP = peerIP Overriding Initiator's IPsec rekeying duration from larger_value to smaller_value Kbs

  • %ASA-5-713092: Group = groupname, Username = username, IP = peerIP Failure during phase 1 rekeying attempt due to collision

  • %ASA-5-713115: Group = groupname, Username = username, IP = peerIP Client rejected NAT enabled IPsec request, falling back to standard IPsec

  • %ASA-5-713119: Group = groupname, Username = username, IP = peerIP Group group IP ip PHASE 1 COMPLETED

  • %ASA-5-713120: Group = groupname, Username = username, IP = peerIP PHASE 2 COMPLETED (msgid=msg_id )

  • %ASA-5-713130: Group = groupname, Username = username, IP = peerIP Received unsupported transaction mode attribute: attribute id

  • %ASA-5-713131: Group = groupname, Username = username, IP = peerIP Received unknown transaction mode attribute: attribute_id

  • %ASA-5-713135: Group = groupname, Username = username, IP = peerIP message received, redirecting tunnel to IP_address .

  • %ASA-5-713136: Group = groupname, Username = username, IP = peerIP IKE session establishment timed out [IKE_state_name ], aborting!

  • %ASA-5-713137: Group = groupname, Username = username, IP = peerIP Reaper overriding refCnt [ref_count] and tunnelCnt [tunnel_count] -- deleting SA!

  • %ASA-5-713139: IP = peerIP group_name not found, using BASE GROUP default preshared key

  • %ASA-5-713144: IP = peerIP Ignoring received malformed firewall record; reason - error_reason TLV type attribute_value correction

  • %ASA-5-713148: Group = groupname, Username = username, IP = peerIP Terminating tunnel to Hardware Client in network extension mode, unable to delete static route for address: IP_address, mask: netmask

  • %ASA-5-713155: DNS lookup for Primary VPN Server [server_name ] successfully resolved after a previous failure. Resetting any Backup Server init.

  • %ASA-5-713156: Initializing Backup Server [server_name or IP_address ]

  • %ASA-5-713158: Group = groupname, Username = username, IP = peerIP Client rejected NAT enabled IPsec Over UDP request, falling back to IPsec Over TCP

  • %ASA-5-713178: Group = groupname, Username = username, IP = peerIP IKE Initiator received a packet from its peer without a Responder cookie

  • %ASA-5-713179: Group = groupname, Username = username, IP = peerIP IKE AM Initiator received a packet from its peer without a payload_type payload

  • %ASA-5-713196: Group = groupname, Username = username, IP = peerIP Remote L2L Peer IP_address initiated a tunnel with same outer and inner addresses. Peer could be Originate Only - Possible misconfiguration!

  • %ASA-5-713197: Group = groupname, Username = username, IP = peerIP The configured Confidence Interval of number seconds is invalid for this tunnel_type connection. Enforcing the second default.

  • %ASA-5-713199: Group = groupname, Username = username, IP = peerIP Reaper corrected an SA that has not decremented the concurrent IKE negotiations counter ( counter_value )!

  • %ASA-5-713201: Group = groupname, Username = username, IP = peerIP Duplicate Phase Phase packet detected. Action

  • %ASA-5-713202: IP = IP_address Duplicate IP_addr packet detected.

  • %ASA-5-713216: Group = groupname, Username = username, IP = peerIP Rule: action [Client type]: version Client: type version allowed/not allowed

  • %ASA-5-713229: Group = groupname, Username = username, IP = peerIP Auto Update - Notification to client client_ip of update string: message_string .

  • %ASA-5-713237: Group = groupname, Username = username, IP = peerIP ACL update (access_list ) received during re-key re-authentication will not be applied to the tunnel.

  • %ASA-5-713239: Group = groupname, Username = username, IP = peerIPIP_Address : Tunnel Rejected: The maximum tunnel count allowed has been reached

  • %ASA-5-713240: Received DH key with bad length: received length=rlength expected length=elength

  • %ASA-5-713248: Group = groupname, Username = username, IP = peerIP META-DATA Rekey initiation is being disabled during CRACK authentication.

  • %ASA-5-713250: Group = groupname, Username = username, IP = peerIP META-DATA Received unknown Internal Address attribute: attribute

  • %ASA-5-713252: Group = group, Username = user, IP = ip Group = group, Username = user, IP = ip, Integrity Firewall Server is not available. VPN Tunnel creation rejected for client.

  • %ASA-5-713253: Group = group, Username = user, IP = ip Group = group, Username = user, IP = ip, Integrity Firewall Server is not available. Entering ALLOW mode. VPN Tunnel created for client.

  • %ASA-5-713257: Phase var1 failure: Mismatched attribute types for class var2 : Rcv'd: var3 Cfg'd: var4

  • %ASA-5-713259: Group = groupname, Username = username, IP = peerIP Group = groupname, Username = username, IP = peerIP, Session is being torn down. Reason: reason

  • %ASA-5-713272: Group = groupname, Username = username, IP = peerIP Terminating tunnel to Hardware Client in network extension mode, unable to delete static route for address: IP_address, mask: /prefix_len

  • %ASA-5-713904: Descriptive_event_string.

  • %ASA-5-716053: SAML Server added: Name: nameSP

  • %ASA-5-716054: SAML Server deleted: Name: nameSP

  • %ASA-5-717013: Removing a cached CRL to accommodate an incoming CRL Issuer: issuer

  • %ASA-5-717014: Unable to cache a CRL received from CDPsizespace

  • %ASA-5-717050: SCEP Proxy: Processed request type typeclient ip addressusernametunnel_group namegroup-policy nameca ip address

  • %ASA-5-717053: Group group nameuser nameIP Addressid subject nameid issuer nameid serial number

  • %ASA-5-717061: Starting protocoltpnameca_nametypemode

  • %ASA-5-717062: protocoltpnamecasubjectissuerserial

  • %ASA-5-717064: Keypair keynametpnamemodeprotocol

  • %ASA-5-717067: Starting ACME certificate enrollment for the trustpoint tpname with CA ca_name. Mode mode

  • %ASA-5-717068: ACME Certificate enrollment succeeded for trustpoint tpname with CA ca. Received a new certificate with Subject Name subject Issuer Name issuer Serial Number serial

  • %ASA-5-717070: Keypair keyname in the trustpoint tpname is regenerated for mode ACME certificate enrollment

  • %ASA-5-717072: A CRL with an older version than the currently cached one was downloaded.

  • %ASA-5-718002: Create peer IP_addressnumber_of_peers

  • %ASA-5-718005: Fail to send to IP_addressport

  • %ASA-5-718006: Invalid load balancing state transition [cur=state_numberevent_number

  • %ASA-5-718007: Socket open failure [failure_codefailure_text

  • %ASA-5-718008: Socket bind failure [failure_codefailure_text

  • %ASA-5-718009: Send HELLO response failure to [IP_address

  • %ASA-5-718010: Sent HELLO response to [IP_address

  • %ASA-5-718011: Send HELLO request failure to [IP_address

  • %ASA-5-718012: Sent HELLO request to [IP_address

  • %ASA-5-718014: Master peer[IP_address

  • %ASA-5-718015: Received HELLO request from [IP_address

  • %ASA-5-718016: Received HELLO response from [IP_address

  • %ASA-5-718024: Send CFG UPDATE failure to [IP_address

  • %ASA-5-718028: Send OOS indicator failure to [IP_address

  • %ASA-5-718031: Received OOS obituary for [IP_address

  • %ASA-5-718032: Received OOS indicator from [IP_address

  • %ASA-5-718033: Send TOPOLOGY indicator failure to [IP_address

  • %ASA-5-718042: Unable to ARP for [IP_address

  • %ASA-5-718043: Updating/removing duplicate peer entry [IP_address

  • %ASA-5-718044: Deleted peer[IP_address

  • %ASA-5-718045: Created peer[IP_address

  • %ASA-5-718048: Create of secure tunnel failure for peer [IP_address

  • %ASA-5-718050: Delete of secure tunnel failure for peer [IP_address

  • %ASA-5-718052: Received GRAT-ARP from duplicate control node[MAC_address

  • %ASA-5-718053: Detected duplicate control node, mastership stolen[MAC_address

  • %ASA-5-718054: Detected duplicate control node[MAC_address

  • %ASA-5-718055: Detected duplicate control node[MAC_address

  • %ASA-5-718057: Queue send failure from ISR, msg type failure_code

  • %ASA-5-718060: Inbound socket select fail: context=context_ID

  • %ASA-5-718061: Inbound socket read fail: context=context_ID

  • %ASA-5-718062: Inbound thread is awake (context=context_ID

  • %ASA-5-718063: Interface interface_name

  • %ASA-5-718064: Admin. interface interface_name

  • %ASA-5-718065: Cannot continue to run (public=updownupdownLB_state

  • %ASA-5-718066: Cannot add secondary address to interface interface_nameIP_address

  • %ASA-5-718067: Cannot delete secondary address to interface interface_nameIP_address

  • %ASA-5-718068: Start VPN Load Balancing in context context_ID

  • %ASA-5-718069: Stop VPN Load Balancing in context context_ID

  • %ASA-5-718070: Reset VPN Load Balancing in context context_ID

  • %ASA-5-718071: Terminate VPN Load Balancing in context context_ID

  • %ASA-5-718072: Becoming control node of Load Balancing in context context_ID

  • %ASA-5-718073: Becoming data node of Load Balancing in context context_ID

  • %ASA-5-718074: Fail to create access list for peer context_ID

  • %ASA-5-718075: Peer IP_address

  • %ASA-5-718076: Fail to create tunnel group for peer IP_address

  • %ASA-5-718077: Fail to delete tunnel group for peer IP_address

  • %ASA-5-718078: Fail to create crypto map for peer IP_address

  • %ASA-5-718079: Fail to delete crypto map for peer IP_address

  • %ASA-5-718080: Fail to create crypto policy for peer IP_address

  • %ASA-5-718081: Fail to delete crypto policy for peer IP_address

  • %ASA-5-718082: Fail to create crypto ipsec for peer IP_address

  • %ASA-5-718083: Fail to delete crypto ipsec for peer IP_address

  • %ASA-5-718084: Public/cluster IP not on the same subnet: public IP_addressnetmaskIP_address

  • %ASA-5-718085: Interface interface_name

  • %ASA-5-718086: Fail to install LB NP rules: type rule_typeinterface_nameport

  • %ASA-5-718087: Fail to delete LB NP rules: type rule_typerule_ID

  • %ASA-5-719014: Email Proxy is changing listen port from old_port to new_port for mail protocol protocol.

  • %ASA-5-720016: (VPN-unit) Failed to initialize default timer #index.

  • %ASA-5-720017: (VPN-unit) Failed to update LB runtime data

  • %ASA-5-720018: (VPN-unit) Failed to get a buffer from the underlying core high availability subsystem. Error code code.

  • %ASA-5-720019: (VPN-unit) Failed to update cTCP statistics.

  • %ASA-5-720020: (VPN-unit) Failed to send type timer message.

  • %ASA-5-720021: (VPN-unit) HA non-block send failed for peer msg message_number. HA error code.

  • %ASA-5-720035: (VPN-unit) Fail to look up CTCP flow handle

  • %ASA-5-720036: (VPN-unit) Failed to process state update message from the active peer.

  • %ASA-5-720071: (VPN-unit) Failed to update cTCP dynamic data.

  • %ASA-5-720072: Timeout waiting for Integrity Firewall Server [interface,ip] to become available.

  • %ASA-5-722037: Group groupuser-nameip_addressreason

  • %ASA-5-722038: Group groupnameuser-namereason

  • %ASA-5-722005: Group groupuser-nameIP_address

  • %ASA-5-722006: Group groupuser-nameip_addressip_address

  • %ASA-5-722010: Group groupuser-nameIP_addresstype-nummessage

  • %ASA-5-722011: Group groupuser-nameIP_addresstype-nummessage

  • %ASA-5-722012: Group groupuser-nameIP_addresstype-nummessage

  • %ASA-5-722028: Group groupuser-nameIP_address

  • %ASA-5-722032: Group group User user_name IP ip_address New TCP|UDP SVC connection replacing old connection.

  • %ASA-5-722033: Group group User user_name IP ip_address First TCP|UDP SVC connection established for SVC session.

  • %ASA-5-722034: Group group User user_name IP ip_address New TCP|UDP SVC connection, no existing connection.

  • %ASA-5-722037: Group groupuser-nameip_addressreason

  • %ASA-5-722038: Group groupnameuser-namereason

  • %ASA-5-722043: Group groupuserip

  • %ASA-5-722044: Group groupuseripver

  • %ASA-5-730009: Group groupname, User username, IP ipaddr, CAS casaddr, capacity exceeded, terminating connection.

  • %ASA-5-734002: DAP: User user, ipaddr

  • %ASA-5-737003: IPAA: Session=sessiontunnel-group

  • %ASA-5-737004: IPAA: Session=session'tunnel-group'

  • %ASA-5-737007: IPAA: Session=sessiontunnel-group

  • %ASA-5-737008: IPAA: Session=session'tunnel-group'

  • %ASA-5-737011: IPAA: Session=sessionip-address

  • %ASA-5-737018: IPAA: Session=sessionnum

  • %ASA-5-737021: IPAA: Address from local pool (ip-address) duplicates address from DHCP

  • %ASA-5-737022: IPAA: Address from local pool (ip-address) duplicates address from AAA

  • %ASA-5-737023: IPAA: Session=sessionip-address

  • %ASA-5-737024: IPAA: Session= :

  • %ASA-5-737025: IPAA: Not releasing local pool ip-address, due to local pool duplicate issue

  • %ASA-5-737034: IPAA: Session=session, IP version address: explanation

  • % ASA-5-737204: VPNFIP: Pool=poolmessage

  • %ASA-5-737405: POOLIP: Pool=poolmessage

  • %ASA-5-746007: user-identity: NetBIOS response failed from User user_nameuser_ip

  • %ASA-5-746012: user-identity: Add IP-User mapping IP Address - domain_name\user_name result - reason

  • %ASA-5-746013: user-identity: Delete IP-User mapping IP Address - domain_name\user_name result - reason

  • %ASA-5-746014: user-identity: [FQDN] fqdnIP Address

  • %ASA-5-746015: user-identity: [FQDN] fqdnIP address

  • %ASA-5-747002: Clustering: Recovered from state machine dropped event (event-id, ptr-in-hex, ptr-in-hex). Intended state: state-name. Current state: state-name.

  • %ASA-5-747003: Clustering: Recovered from state machine failure to process event (event-id, ptr-in-hex, ptr-in-hex) at state state-name.

  • %ASA-5-747007: Clustering: Recovered from finding stray config sync thread, stack ptr-in-hex, ptr-in-hex, ptr-in-hex, ptr-in-hex, ptr-in-hex, ptr-in-hex.

  • %ASA-5-748001: Module slot_numberchassis_number

  • %ASA-5-748004: Module slot_numberchassis_number

  • %ASA-5-748203: Module module_id in chassis chassis id is re-joining the cluster due to a service chain application recovery.

  • %ASA-5-750001: Local:local IP :local port Remote:remote IP : remote port Username: username Received request to request an IPsec tunnel; local traffic selector = local selectors: range, protocol, port range ; remote traffic selector = remote selectors: range, protocol, port range

  • %ASA-5-750002: Local:local IP :local port Remote: remote IP : remote port Username: username Received a IKE_INIT_SA request

  • %ASA-5-750004: Local: local IP: local port Remote: remote IP: remote port Username: username Sending COOKIE challenge to throttle possible DoS

  • %ASA-5-750005: Local: local IP: local port Remote: remote IP: remote port Username: username IPsec rekey collision detected. I am lowest nonce initiator, deleting SA with inbound SPI SPI

  • %ASA-5-750006: Local: local IP: local port Remote: remote IP: remote port Username: username SA UP. Reason: reason

  • %ASA-5-750007: Local: local IP: local port Remote: remote IP: remote port Username: username SA DOWN. Reason: reason

  • %ASA-5-750008: Local: local IP: local port Remote: remote IP: remote port Username: username SA rejected due to system resource low

  • %ASA-5-750009: Local: local IP: local port Remote: remote IP: remote port Username: username SA request rejected due to CAC limit reached: Rejection reason: reason

  • %ASA-5-750010: Local: local-ip Remote: remote-ip Username:username IKEv2 local throttle-request queue depth threshold of threshold reached; increase the window size on peer peer for better performance

  • %ASA-5-750013 - IKEv2 SA (iSPI ISPI rRSP rSPI) Peer Moved: Previous prev_remote_ip:prev_remote_port/prev_local_ip:prev_local_port. Updated new_remote_ip:new_remote_port/new_local_ip:new_local_port

  • %ASA-5-751007: Configured attribute not supported for IKEv2. Attribute: attribute

  • %ASA-5-751025: Group:group-policy IPv4 Address=assigned_IPv4_addr IPv6 address=assigned_IPv6_addr assigned to session

  • %ASA-5-751028: Overriding configured keepalive values of threshold:config_threshold/retry:config_retry to threshold:applied_threshold/retry:applied_retry.

  • %ASA-5-752003: Tunnel Manager dispatching a KEY_ACQUIRE message to IKEv2. Map Tag = mapTag . Map Sequence Number = mapSeq

  • %ASA-5-752004: Tunnel Manager dispatching a KEY_ACQUIRE message to IKEv1. Map Tag = mapTag . Map Sequence Number = mapSeq

  • %ASA-5-752016: IKEv protocol was successful at setting up a tunnel. Map Tag = mapTag . Map Sequence Number = mapSeq.

  • %ASA-5-776009: CTS SXP: password changed.

  • %ASA-5-776010: CTS SXP: SXP default source IP is changed original source IP final source IP.

  • %ASA-5-776011: CTS SXP: operational state.

  • %ASA-5-776252: CTS SGT-MAP: CTS SGT-MAP: Binding binding IP - SGname(SGT) from source name deleted from binding manager.

  • %ASA-5-776309: CTS Policy: Previously known security-group tag sgt

  • %ASA-5-776310: CTS Policy: Security-group name "sgnameold_sgtnew_sgt

  • %ASA-5-769001: UPDATE: ASAsrc

  • %ASA-5-769002: UPDATE: ASAsrcdest

  • %ASA-5-769003: UPDATE: ASAsrcdest

  • %ASA-5-769004: UPDATE: ASA image src_file failed verification, reason: failure_reason

  • %ASA-5-769005: UPDATE: ASAimage_name

  • %ASA-5-771001: CLOCK: System clock set, source: srctimetime

  • %ASA-5-771002: CLOCK: System clock set, source: srciptimetime

  • %ASA-5-771002: CLOCK: System clock set, source: srciptimetime

  • %ASA-5-8300006: Cluster topology change detected. VPN session redistribution aborted.

Informational Messages, Severity 6

The following messages appear at severity 6, informational:

  • %ASA-6-106012: Deny IP from IP_addressIP_addresshex

  • %ASA-6-106015: Deny TCP (no connection) from IP_address/port to IP_address/port flags tcp_flags on interface interface_name.

  • %ASA-6-106025: Failed to determine security context for packet: vlansourceVlansource_addresssource_portdest_addressdest_port protocol

  • %ASA-6-106026: Failed to determine the security context for the packet:sourceVlan:source_address dest_address source_port dest_port protocol

  • %ASA-6-106100: access-list acl_ID protocolinterface_namesource_addresssource_portidfw_usersg_infointerface_namedest_addressdest_portidfw_usersg_infonumbernumber

  • %ASA-6-106102: access-list acl_ID {permitted | denied} protocol for user username interface_name/source_address source_port interface_name/dest_address dest_port hit-cnt number {first hit | number-second interval} hash codes

  • %ASA-6-108005: action_class: Receivedreq_resp src_ifcsipsport dest_ifc dipdportfurther_info

  • %ASA-6-108007: TLS started on ESMTP session between client client-side interface-nameclient IP addressclient portserver-side interface-nameserver IP addressserver port

  • %ASA-6-109001: Auth start for user 'userinside_addressinside_portoutside_addressoutside_port

  • %ASA-6-109002: Auth from inside_addressinside_portoutside_addressoutside_portIP_addressinterface_name

  • %ASA-6-109003: Auth from inside_addressinside_portoutside_addressoutside_portinterface_name

  • %ASA-6-109005: Authentication succeeded for user 'userinside_addressinside_portoutside_addressoutside_portinterface_name

  • %ASA-6-109006: Authentication failed for user 'userinside_addressinside_portoutside_addressoutside_portinterface_name

  • %ASA-6-109007: Authorization permitted for user 'userinside_addressinside_portoutside_addressoutside_portinterface_name

  • %ASA-6-109008: Authorization denied for user 'useroutside_addressoutside_portinside_addressinside_portinterface_name

  • %ASA-6-109024: Authorization denied from source_addresssource_portdest_addressdest_portinterface_nameprotocol

  • %ASA-6-109025: Authorization denied (acl=acl_IDusersource_addresssource_portdest_addressdest_portinterface_nameprotocol

  • %ASA-6-109036: Exceeded 1000attribute nameusername

  • %ASA-6-109100: Received CoA update from coa-source-ipusernameaudit-session-id

  • %ASA-6-109101: Received CoA disconnect request from coa-source-ipusernameaudit-session-id

  • %ASA-6-109202: UAUTH: Session=session, User=username, Assigned IP=IP Address, Succeeded incrementing entry use

  • %ASA-6-109211: UAUTH: Session=session, User=username, Assigned IP=IP Address, Succeeded decrementing entry use.

  • %ASA-6-110002: Failed to locate egress interface for protocol from src_interface:src_ip/src_port to dest_ip/dest_port

  • %ASA-6-110003: Routing failed to locate next hop for protocol from src_interface:src_ip/src_port to dest_interface:dest_ip/dest_port

  • %ASA-6-110004: Egress interface changed from old_active_ifc to new_active_ifc on ip_protocol connection conn_id for outside_zone/parent_outside_ifc:outside_addr/outside_port (mapped_addr/mapped_port) to inside_zone/parent_inside_ifc:inside_addr/inside_port (mapped_addr/mapped_port)

  • %ASA-6-110005: Routing failed to locate next hop for protocol from interface:address/port to interface:address/port

  • %ASA-6-113003: AAA group policy for user userpolicy_name

  • %ASA-6-113004: AAA user aaa_typeserver_IP_addressuser

  • %ASA-6-113005: AAA user authentication Rejected : reason = reason : server = ip_address : user =user_name : user IP = ip_address

  • %ASA-6-113005: AAA user authorization Rejected : reason = reason : server = ip_address : user =user_name : user IP = ip_address

  • %ASA-6-113006: User 'usernumber

  • %ASA-6-113007: User 'useradministrator

  • %ASA-6-113008: AAA transaction status ACCEPTuser

  • %ASA-6-113009: AAA retrieved default group policy (policyusername

  • %ASA-6-113010: AAA challenge received for user userserver_IP_address

  • %ASA-6-113011: AAA retrieved user specific group policy (policyuser

  • %ASA-6-113012: AAA user authentication Successful : local database : user = user

  • %ASA-6-113013: AAA unable to complete the request Error : reason = reasonuser

  • %ASA-6-113014: AAA authenticationserver_IP_addressuser

  • %ASA-6-113015: AAA user authentication Rejected : reason = reasonuser: xxx.xxx.xxx.xxx

  • %ASA-6-113016: AAA credentials rejected : reason = reasonserver_IP_addressuser: xxx.xxx.xxx.xxx

  • %ASA-6-113017: AAA credentials rejected : reason = reasonuser: xxx.xxx.xxx.xxx

  • %ASA-6-113033: Group groupuseripaddrAnyConnect

  • %ASA-6-113037: Group group User user IP ip_address Reboot pending, new sessions disabled. Denied user login.

  • %ASA-6-113039: Group groupuseripaddrAnyConnect parent

  • %ASA-6-113045: AAA SDI server IP_address in aaa-server group group_name: status changed from previous-state to current-state

  • %ASA-6-114004: 4GE SSM

  • %ASA-6-114005: 4GE SSM

  • %ASA-6-120003: Call-Home is processing grouptitle

  • %ASA-6-120007: Call-Home groupdestination

  • %ASA-6-121003: id

  • %ASA-6-199002: Startup completed. Beginning operation.

  • %ASA-6-199003: Reducing Link MTU dec

  • %ASA-6-199005: Startup begin

  • %ASA-6-199018: syslog

  • %ASA-6-201010: Embryonic connection limit exceeded econnslimitdirsource_addresssource_portdest_addressdest_portinterface_name

  • %ASA-6-201012: Per-client embryonic connection limit exceeded curr_num/limit for [input|output] packet from ip_address/port to ip_address/port on interface interface_name

  • %ASA-6-210022: LU missed number

  • %ASA-6-302003: Built H245 connection for faddr foreign_ip_address laddr local_ip_address/local_port

  • %ASA-6-302003: Built H245 connection for faddr foreign_ip_address/foreign_port laddr local_ip_address

  • %ASA-6-302004: Pre-allocate H323 {TCP | UDP} backconnection for faddr foreign_ip_address to laddr local_ip_address/local_port

  • %ASA-6-302004: Pre-allocate H323 {TCP | UDP} backconnection for faddr foreign_ip_address/foreign_port to laddr local_ip_address

  • %ASA-6-302010: connectionsconnections

  • %ASA-6-302012: Pre-allocate H225 Call Signalling Connection for faddr foreign_ip_address to laddr local_ip_address/local_port

  • %ASA-6-302012: Pre-allocate H225 Call Signalling Connection for faddr foreign_ip_address/foreign_port to laddr local_ip_address

  • %ASA-6-302013: Built {inbound | outbound}[Probe] TCP connection connection_id for interface:real-address/real-port ((mapped-address/mapped-port))idfw_user to interface:real-address/real-port (mapped-address/mapped-port)inside_idfw_and_sg_info id_port_num rx_ring_num [(user)]

  • %ASA-6-302014: Teardown [Probe]TCP connection connection_id for interface:real_address/real_portidfw_user to interface:real_address/real_portidfw_user duration hh:mm:ss bytes bytes reason_stringteardown_initiatorinitiator port_num rx_ring_num [(user)]

  • %ASA-6-302015: Built {inbound | outbound} UDP connection connection_id for interface:real_address/real_port (mapped_address/mapped_port)idfw_user to interface:real_address/real_port (mapped_address/mapped_port)idfw_user id_port_num rx_ring_num [(user)]

  • %ASA-6-302016: Teardown UDP connection connection_id for interface:real_address/real_portidfw_user to interface:real_address/real_portidfw_user duration hh:mm:ss bytes bytes id_port_num rx_ring_num [(user)]

  • %ASA-6-302017: Built {inbound | outbound} GRE connection id from interface:real_address (translated_address)idfw_user to interface:real_address/real_cid (translated_address/translated_cid)idfw_user id_port_num rx_ring_num [(user)]

  • %ASA-6-302018: Teardown GRE connection id from interface:real_addresstranslated_address to interface:real_address/real_cididfw_user duration hh:mm:ss bytes bytes id_port_num rx_ring_num [(user)]

  • (Inbound) %ASA-6-302020: Built inbound ICMP connection for faddr src_ip_address/src_portoutside_idfw_user gaddr dest_ip_address/dest_port laddr dest_ip_address/dest_portinside_idfw_user [(user)] type type code code Internal-Data0/port_num:RX[rx_ring_num]

  • (Outbound) %ASA-6-302020: Built outbound ICMP connection for faddr dest_ip_address/dest_portoutside_idfw_user gaddr src_ip/src_port laddr src_ip/src_portinside_idfw_user[(user)] type type code code Internal-Data0/port_num:RX[rx_ring_num]

  • %ASA-6-302021: Teardown ICMP connection for faddr src_ip_address/src_portoutside_idfw_user gaddr dest_ip_address/dest_port laddr dest_ip_address/dest_portinside_idfw_user [(user)] type type code code Internal-Data0/port_num:RX[rx_ring_num]

  • %ASA-6-302022: Built roleinterfacereal-addressreal-portmapped-addressmapped-portinterfacereal-addressreal-portmapped-addressmapped-port)

  • %ASA-6-302023: Teardown stubinterfacereal-addressreal-portinterfacereal-addressreal-porthh:mm:ssbytesreason

  • %ASA-6-302024: Built roleinterfacereal-addressreal-portmapped-addressmapped-portinterfacereal-addressreal-portmapped-addressmapped-port

  • %ASA-6-302025: Teardown stubinterfacereal-addressreal-portinterfacereal-addressreal-porthh:mm:ssbytesreason

  • %ASA-6-302026: Built roleinterfacereal-addressreal-portmapped-addressinterfacereal-addressreal-portmapped-address

  • %ASA-6-302027: Teardown stubinterfacereal-addressreal-portinterfacereal-addressreal-porthh:mm:ssbytesreason

  • %ASA-6-302033: Pre-allocated H323 GUP Connection for faddr interface_name:foreign_ip_address to laddr interface_name:local_address/local_port

  • %ASA-6-302033: Pre-allocated H323 GUP Connection for faddr interface_name:foreign_ip_address/foreign_port to laddr interface_name:local_address

  • %ASA-6-302035: Built {inbound | outbound} SCTP connection conn_id for outside_interface:outside_ip/outside_port (mapped_outside_ip/mapped_outside_port)outside_idfw_user to inside_interface:inside_ip/inside_port (mapped_inside_ip/mapped_inside_port)inside_idfw_user port_num rx_ring_num [(user)]

  • %ASA-6-302036: Teardown SCTP connection conn_id for inside_interface:inside_ip_address/inside_portoutside_idfw_user to outside_interface:outside_ip_address/outside_portinside_idfw_user duration time_value bytes bytes reason_string id_port_num rx_ring_num [(user)]

  • %ASA-6-302037: Built {inbound|outbound} IPINIP connection conn_id from outside_interface:outside_ip/{outside_mapped_ip|outside_port} outside_idfw_user to inside_interface_name:inside_ip/{inside_mapped_ip|inside_port} inside_idfw_user [(user)]

  • (Inbound flow)%ASA-6-302038: Teardown IPINIP connection conn_id for inside_interface:inside_ip/inside_portoutside_idfw_user to outside_interface:outside_ip/outside_portinside_idfw_user duration time_value bytes bytes [(user)]

  • (Outbound flow)%ASA-6-302038: Teardown IPINIP connection conn_id for outside_interface:outside_ip/outside_portoutside_idfw_user to inside_interface:inside_ip/inside_portinside_idfw_user duration time_value bytes bytes [(user)]

  • %ASA-6-302303: Built TCP state-bypass connection conn_id from initiator_interface:real_ip/real_port(mapped_ip/mapped_port) to responder_interface:real_ip/real_port (mapped_ip/mapped_port)

  • %ASA-6-302304: Teardown TCP state-bypass connection conn_id from initiator_interface:ip/port to responder_interface:ip/port duration, bytes, teardown reason.

  • %ASA-6-302305: Built SCTP state-bypass connection conn_idoutside_interfaceoutside_ipoutside_portmapped_outside_ipmapped_outside_portoutside_idfw_useroutside_sg_infoinside_interfaceinside_ipinside_portmapped_inside_ipmapped_inside_portinside_idfw_userinside_sg_info

  • %ASA-6-302306: Teardown SCTP state-bypass connection conn_idoutside_interfaceoutside_ipoutside_portoutside_idfw_useroutside_sg_infoinside_interfaceinside_ipinside_portinside_idfw_userinside_sg_infotimebytesreason

  • %ASA-6-303002: FTP connection from src_ifcsrc_ipsrc_portdst_ifcdst_ipdst_portusernameactionfilename

  • %ASA-6-304004: URL Server IP_addressurl

  • %ASA-6-305007: addrpool_freeIP_addressinterface_number

  • %ASA-6-305009: Built {dynamic|static}interface_name [(acl-name)]real_addressidfw_userinterfacenamemapped_address

  • %ASA-6-305010: Teardown {dynamic|static}interface_namereal_address idfw_userinterfacenamemapped_addresstime

  • %ASA-6-305011: Built {dynamic|static}{TCP|UDP|ICMP}interface_namereal_addressreal_portidfw_userinterfacenamemapped_addressmapped_port

  • %ASA-6-305012: Teardown interface_nameacl-namereal_addressreal_portreal_ICMP_IDidfw_userinterface_namemapped_addressmapped_portmapped_ICMP_IDtime

  • %ASA-6-305014: Allocated num_of_blocks block of ports for translation from real_interface:real_host_ip to real_dest_interface:real_dest_ip/real_dest_port_start-real_dest_port_end

  • %ASA-6-305015: Released block_size block of ports for translation from real_interface:real_host_ip to real_destination_interface:real_dest_ip/port_start-port_end

  • %ASA-6-305018: MAP translation from src_ifc:src_ip/src_port-dst_ifc:dst_ip/dst_port to src_ifc:translated_src_ip/src_port-dst_ifc:translated_dst_ip/dst_port

  • %ASA-6-308001: Console enable password incorrect for numberIP_address

  • %ASA-6-311001: LU loading standby start

  • %ASA-6-311002: LU loading standby end

  • %ASA-6-311003: LU recv thread up

  • %ASA-6-311004: LU xmit thread up

  • %ASA-6-312001: RIP hdr failed from IP_addressstringnumberstringinterface_name

  • %ASA-6-314001: Pre-allocate RTSP UDP backconnection for src_intfsrc_IPdst_intfdst_IPdst_port.

  • %ASA-6-314002: RTSP failed to allocate UDP media connection from src_intfsrc_IPdst_intfdst_IPdst_portreason_string.

  • %ASA-6-314003: Dropped RTSP traffic from src_intfsrc_ipreason

  • %ASA-6-314004: RTSP client src_intfsrc_IP RTSP URL

  • %ASA-6-314005: RTSP client src_intfsrc_IP RTSP_URL.

  • %ASA-6-314006: RTSP client src_intfsrc_IPrate request_method

  • %ASA-6-315011: SSH session from remote_ip_address on interface interface_name for user \'user_name\' terminated normally

  • %ASA-6-315011: SSH session from remote_ip_address on interface interface_name for user \'user_name\' terminated

  • %ASA-6-315011: SSH session from remote_ip_address on interface interface_name for user \'user_name\' disconnected by SSH server, reason: \'reason_string\' (reason_state)

  • %ASA-6-315013: SSH session from SSH client addressinterface nameuser name

  • %ASA-6-317007: Added route_type route dest_address netmask via gateway_address [distance/metric] on interface_name route_type

  • %ASA-6-317008: Community list check with bad list list_number

  • %ASA-6-317077: Added protocol_name route destination_address subnet-mask via gateway-address [admin_distance/metric] on [inf_name] [vrf_name] tableid [table_id]

  • %ASA-6-317078: Deleted protocol_name route destination_address subnet-mask via gateway-address [admin_distance/metric] on [inf_name] [vrf_name] tableid [table_id]

  • %ASA-6-317079: Added static route destination_address [admin_distance/metric] via inf_name tableid [table_id]

  • %ASA-6-317080: Deleted static route destination_address [admin_distance/metric] via inf_name tableid [table_id]

  • %ASA-6-321003: Resource var1 log level of var2 reached.

  • %ASA-6-321004: Resource var1 rate log level of var2 reached

  • %ASA-6-322004: No management IP address configured for transparent firewall. Dropping protocol protocolinterface_insource_addresssource_portinterface_outdest_addressdest_port

  • %ASA-6-324303: Server=IPaddr:port ID=id The RADIUS server supports and included the Message-Authenticator payload in its response. To prevent Man-In-The-Middle attacks, consider enabling ‘ message-authenticator’ on the aaa-server-group configuration for this server as a security best practice.

  • %ASA-6-333001: EAP association initiated - context:EAP-context

  • %ASA-6-333003: EAP association terminated - context:EAP-context

  • %ASA-6-333009: EAP-SQ response MAC TLV is invalid - context:EAP-context

  • %ASA-6-334001: EAPoUDP association initiated - host-address

  • %ASA-6-334004: Authentication request for NAC Clientless host - host-address

  • %ASA-6-334007: EAPoUDP association terminated - host-address

  • %ASA-6-334008: NAC EAP association initiated - host-address, EAP context:EAP-context

  • %ASA-6-334009: Audit request for NAC Clientless host - Assigned_IP.

  • %ASA-6-335001: NAC session initialized - host-address

  • %ASA-6-335004: NAC is disabled for host - host-address

  • %ASA-6-335006: NAC Applying ACL:ACL-name - host-address

  • %ASA-6-335009: NAC 'Revalidate' request by administrative action - host-address

  • %ASA-6-335010: NAC 'Revalidate All' request by administrative action - num sessions

  • %ASA-6-335011: NAC 'Revalidate Group' request by administrative action for group-name group - num sessions

  • %ASA-6-335012: NAC 'Initialize' request by administrative action - host-address

  • %ASA-6-335013: NAC 'Initialize All' request by administrative action - num sessions

  • %ASA-6-335014: NAC 'Initialize Group' request by administrative action for group-name group - num sessions

  • %ASA-6-336011: hw or sw error occurred

  • %ASA-6-337000: Session created, NeighAddr: Created BFD session with local discriminator id, SrcAddr: real_interface

  • %ASA-6-337001: Session destroyed, NeighAddr: Terminated BFD session with local discriminator id, SrcAddr: real_interface

  • %ASA-6-338304: Successfully downloaded dynamic filter data file from updater server url

  • %ASA-6-339010: Umbrella API token request was successful.

  • %ASA-6-340002: Vnet-proxy data relay error error_stringcontext_idversionrequest_typeaddress_typeclient_address_internalclient_port_internal

  • %ASA-6-341001: Policy Agent started successfully for VNMC vnmc_ip_addr

  • %ASA-6-341002: Policy Agent stopped successfully for VNMC vnmc_ip_addr

  • %ASA-6-341010: Storage device with serial number ser_no[inserted into | removed from]bay_no

  • %ASA-6-402129: CRYPTO: An attempt to release a DMA memory block failed, location: address

  • %ASA-6-402130: CRYPTO: Received an ESP packet (SPI = xxxxxxxxxx, sequence number=xxxx) from 172.16.0.1 (user=user) to 192.168.0.2 with incorrect IPsec padding.

  • %ASA-6-403500: PPPoE - Service name 'any' not received in interface_nameac_name

  • %ASA-6-410004: action_classactionquery_responsesrc_ifcsipsportdest_ifcdipdport

  • %ASA-6-414004: TCP Syslog Server intfIP_Addressport

  • %ASA-6-414007: TCP syslog server connection restored. New connections allowed.

  • %ASA-6-414008: New connections are now allowed due to change of logging permit-hostdown policy.

  • %ASA-6-414009: TCP syslog server connection removed. New connections allowed.

  • %ASA-6-415001: HTTP - matched matched_stringmap_nameconnection_actionint_typeIP_addressport_numint_typeIP_addressport_num

  • %ASA-6-415002: HTTP - matched matched_stringmap_nameconnection_actionint_typeIP_addressport_numint_typeIP_addressport_num

  • %ASA-6-415003: HTTP - matched matched_stringmap_nameconnection_actionint_typeIP_addressport_numint_typeIP_addressport_num

  • %ASA-6-415017: HTTP - matched matched_stringmap_nameconnection_actionint_typeIP_addressport_numint_typeIP_addressport_num

  • %ASA-6-419004: TCP connection ID from src_ifc:src_ip/src_port (src_ip/src_port) to dst_ifc:dst_ip/dst_port (dst_ip/dst_port) is probed by DCD

  • %ASA-6-419005: TCP connection ID from src_ifc:src_ip/src_port (src_ip/src_port) to dest_ifc:des_ip/des_port (des_ip/des_port) duration hh:mm:ss data bytes, is kept open by DCD as valid connection

  • %ASA-6-419006: Teardown TCP connection ID from src_ifc:src_ip/src_port (src_ip/src_port) to dst_ifc:dst_ip/dst_port (dst_ip/dst_port) duration hh:mm:ss data bytes, DCD probe was not responded from client/server interface ifc_name

  • %ASA-6-420004: Virtual Sensor sensor_name

  • %ASA-6-420005: Virtual Sensor sensor_name

  • %ASA-6-421002: TCP|UDP flow from interface_name:IP_address/port to interface_nam:IP_address/port bypassed application checking because the protocol is not supported.

  • %ASA-6-421005: interface_nameIP_addressapplication

  • %ASA-6-421006: There are numberapplication

  • %ASA-6-425001 Redundant interface redundant_interface_name created.

  • %ASA-6-425002 Redundant interface redundant_interface_name removed.

  • %ASA-6-425003 Interface interface_name added into redundant interface redundant_interface_name.

  • %ASA-6-425004 Interface interface_name removed from redundant interface redundant_interface_name.

  • %ASA-6-426001: PORT-CHANNEL:Interface ifc_namenum

  • %ASA-6-426002: PORT-CHANNEL:Interface ifc_namenum

  • %ASA-6-426003: PORT-CHANNEL:Interface ifc_name1num

  • %ASA-6-426101: PORT-CHANNEL:Interface ifc_nameport-channel id

  • %ASA-6-426102: PORT-CHANNEL:Interface ifc_nameport-channel id

  • %ASA-6-426103: PORT-CHANNEL:Interface ifc_nameport-channel id

  • %ASA-6-426104: PORT-CHANNEL:Interface ifc_nameport-channel id

  • %ASA-6-428001: WAAS confirmed from in_interface:src_ip_addr/src_port to out_interface:dest_ip_addr/dest_port, inspection services bypassed on this connection

  • %ASA-6-429005: Set up protocol_typeinterface_nameip_addressportpolicy_type

  • %ASA-6-429006: Cleaned up authentication-proxy rule for the cxsc action on interface interface_nameip_addresspolicy_type

  • %ASA-6-444103: Shared licensetype

  • %ASA-6-444104: Shared licensetypevalue

  • %ASA-6-444107: Shared license service statusifname

  • %ASA-6-444108: Shared license stateid

  • %ASA-6-444306: %SMART_LIC-6-AGENT_READY: Smart Agent for Licensing is initialized.

  • %ASA-6-444306: %SMART_LIC-6-AGENT_ENABLED: Smart Agent for Licensing is enabled.

  • %ASA-6-444306: %SMART_LIC-6-AGENT_REG_SUCCESS: Smart Agent for Licensing Registration with Cisco licensing cloud successful.

  • %ASA-6-444306: %SMART_LIC-6-AGENT_DEREG_SUCCESS: Smart Agent for Licensing De-registration with Cisco licensing cloud successful.

  • %ASA-6-444306: %SMART_LIC-6-DISABLED: Smart Agent for Licensing disabled.

  • %ASA-6-444306: %SMART_LIC-6-ID_CERT_RENEW_SUCCESS: Identity certificate renewal successful.

  • %ASA-6-444306: %SMART_LIC-6-ENTITLEMENT_RENEW_SUCCESS: Entitlement authorization renewal with Cisco licensing cloud successful.

  • %ASA-6-444306: %SMART_LIC-6-AUTH_RENEW_SUCCESS: Authorization renewal with Cisco licensing cloud successful.

  • %ASA-6-444306: %SMART_LIC-6-HA_ROLE_CHANGED: Smart Agent HA role changed to role.

  • %ASA-6-444306: %SMART_LIC-6-HA_CHASSIS_ROLE_CHANGED: Smart Agent HA chassis role changed to role.

  • %ASA-6-444306: %SMART_LIC-6-AGENT_ALREADY_REGISTER: Smart Agent is already registered with the Cisco licensing cloud.

  • %ASA-6-444306: %SMART_LIC-6-AGENT_ALREADY_DEREGISTER: Smart Agent is already Deregistered with the CSSM.

  • %ASA-6-444306: %SMART_LIC-6-EXPORT_CONTROLLED: Usage of export controlled features is status.

  • %ASA-6-602101: PMTU-D packet numbernumberdest_addresssource_addressprotocol

  • %ASA-6-602103: IPSEC: Received an ICMP Destination Unreachable from src_addrrcvd_mtupeer_addrspiusernameold_mtunew_mtu

  • %ASA-6-602104: IPSEC: Received an ICMP Destination Unreachable from src_addrrcvd_mtucurr_mtupeer_addrspiusername

  • %ASA-6-602303: IPSEC: An direction tunnel_typespilocal_IPremote_IPusername

  • %ASA-6-602304: IPSEC: An directiontunnel_typespilocal_IPremote_IPusername

  • %ASA-6-603101: PPTP received out of seq or duplicate pkt, tnl_id=numbernumbernumber

  • %ASA-6-603102: PPP virtual interface interface_nameuser

  • %ASA-6-603103: PPP virtual interface interface_nameuserstatus

  • %ASA-6-603104: PPTP Tunnel created, tunnel_id is numberremote_addressnumberIP_addressuserstring

  • %ASA-6-603105: PPTP Tunnel deleted, tunnel_id = numberremote_address

  • %ASA-6-603106: L2TP Tunnel created, tunnel_id is numberremote_addressnumberIP_addressuser

  • %ASA-6-603107: L2TP Tunnel deleted, tunnel_id = numberremote_address

  • %ASA-6-603108: Built PPPOE Tunnel, tunnel_id = interface_namenumberIP_addressnumberIP_address

  • %ASA-6-603109: Teardown PPPOE Tunnel, tunnel_id = interface_namenumber

  • %ASA-6-604101: DHCP client interface interface_nameIP_address netmaskgateway_address

  • %ASA-6-604102: DHCP client interface interface_name

  • %ASA-6-604103: DHCP daemon interface interface_nameMAC_addressIP_address

  • %ASA-6-604104: DHCP daemon interface interface_namebuild_numberIP_address

  • %ASA-6-604201: DHCPv6 PD client on interface pd-client-iface received delegated prefix prefix/prefix from DHCPv6 PD server server-address with preferred lifetime in-seconds seconds and valid lifetime in-seconds seconds

  • %ASA-6-604202: DHCPv6 PD client on interface pd-client-iface releasing delegated prefix prefix/prefix received from DHCPv6 PD server server-address

  • %ASA-6-604203: DHCPv6 PD client on interface pd-client-iface renewed delegated prefix prefix/prefix from DHCPv6 PD server server-address with preferred lifetime in-seconds seconds and valid lifetime in-seconds seconds

  • %ASA-6-604204: DHCPv6 delegated prefix delegated prefix/prefix got expired on interface pd-client-iface, received from DHCPv6 PD server server-address

  • %ASA-6-604205: DHCPv6 client on interface client-iface allocated address ipv6-address from DHCPv6 server server-address with preferred lifetime in-seconds seconds and valid lifetime in-seconds seconds

  • %ASA-6-604206: DHCPv6 client on interface client-iface releasing address ipv6-address received from DHCPv6 server server-address

  • %ASA-6-604207: DHCPv6 client on interface client-iface renewed address ipv6-address from DHCPv6 server server-address with preferred lifetime in-seconds seconds and valid lifetime in-seconds seconds

  • %ASA-6-604208: DHCPv6 client address ipv6-address got expired on interface client-iface, received from DHCPv6 server server-address

  • %ASA-6-605004: Login denied from source_ip_address/source_port to interface:destination_ip_address/service_name for user \'username\'

  • %ASA-6-605004: Login denied from serial to console for user \'username\'

  • %ASA-6-605005: Login permitted from source_ip_address/source_port to interface:destination_ip_address/service_name for user \'username\'

  • %ASA-6-605005: Login permitted from serial to console for user \'username\'

  • %ASA-6-606001: ASDM session number numberIP_address

  • %ASA-6-606002: ASDM session number numberIP_address

  • %ASA-6-606003: ASDM logging session number idIP_address

  • %ASA-6-606004: ASDM logging session number idIP_address

  • %ASA-6-607001: Pre-allocate SIP connection_type secondary channel for interface_name:ip_address to interface_name:ip_address/port from message_string message

  • %ASA-6-607001: Pre-allocate SIP connection_type secondary channel for interface_name:ip_address/port to interface_name:ip_address from message_string message

  • %ASA-6-607003: action_classreq_respreq_resp_infosrc_ifcsipsportdest_ifcdipdportfurther_info

  • %ASA-6-608001: Pre-allocate Skinny connection_type secondary channel for interface_name:IP_address to interface_name:IP_address from string message

  • %ASA-6-610101: Authorization failed: Cmd: commandcommand_modifier

  • %ASA-6-611101: User authentication succeeded: IP address: IP addressuser

  • %ASA-6-611102: User authentication failed: IP address: IP address, user

  • %ASA-6-611301: VPNClient: NAT configured for Client Mode with no split tunneling: NAT addr: mapped_address

  • %ASA-6-611302: VPNClient: NAT exemption configured for Network Extension Mode with no split tunneling

  • %ASA-6-611303: VPNClient: NAT configured for Client Mode with split tunneling: NAT addr: mapped_addressIP_address

  • %ASA-6-611304: VPNClient: NAT exemption configured for Network Extension Mode with split tunneling: Split Tunnel Networks: IP_address

  • %ASA-6-611305: VPNClient: DHCP Policy installed: IP_address

  • %ASA-6-611306: VPNClient: Perfect Forward Secrecy Policy installed

  • %ASA-6-611307: VPNClient: Head end : IP_address

  • %ASA-6-611308: VPNClient: Split DNS Policy installed: List of domains: string string

  • %ASA-6-611309: VPNClient: Disconnecting from head end and uninstalling previously downloaded policy: Head End : IP_address

  • %ASA-6-611310: VPNClient: XAUTH Succeeded: Peer: IP_address

  • %ASA-6-611311: VPNClient: XAUTH Failed: Peer: IP_address

  • %ASA-6-611312: VPNClient: Backup Server List: reason

  • %ASA-6-611314: VPNClient: Load Balancing Cluster with Virtual IP: IP_addressIP_address

  • %ASA-6-611315: VPNClient: Disconnecting from Load Balancing Cluster member IP_address

  • %ASA-6-611316: VPNClient: Secure Unit Authentication Enabled

  • %ASA-6-611317: VPNClient: Secure Unit Authentication Disabled

  • %ASA-6-611318: VPNClient: User Authentication Enabled: Auth Server IP: IP_addressporttime

  • %ASA-6-611319: VPNClient: User Authentication Disabled

  • %ASA-6-611320: VPNClient: Device Pass Through Enabled

  • %ASA-6-611321: VPNClient: Device Pass Through Disabled

  • %ASA-6-611322: VPNClient: Extended XAUTH conversation initiated when SUA disabled

  • %ASA-6-611323: VPNClient: Ignoring duplicate split network entry network_address/network_mask

  • %ASA-6-613001: Bad checksum string from IP_address on number

  • %ASA-6-613002: Interface interface_name has zero bandwidth configuration

  • %ASA-6-613003: Network range IP_address netmask changed from area string to string

  • %ASA-6-613014: Base topology enabled on interface string attached to MTR compatible mode area string

  • %ASA-6-613027: OSPF process number removed from interface interface_name

  • %ASA-6-613028: Unrecognized virtual interface intetface_name. Treat it as loopback stub route

  • %ASA-6-613041: OSPF-100 Areav string: LSA ID IP_address, Type number, Adv-rtr IP_address, LSA counter DoNotAge

  • %ASA-6-613043:

  • %ASA-6-613104: Unrecognized virtual interface %IF_NAME.

  • %ASA-6-614001: Split DNS: request patched from server: IP_address IP_address

  • %ASA-6-614002: Split DNS: reply from server: IP_addressIP_address

  • %ASA-6-615001: vlan number

  • %ASA-6-615002: vlan number

  • %ASA-6-616001: Pre-allocate MGCP data_channelinside_interfaceinside_addressoutside_interfaceoutside_addressportmessage_type message

  • %ASA-6-617001: GTPv(version) msg_type from dest_interface:dest_address/dest_port not accepted by source_interface:source_address/source_port, Cause: value cause_info (cause_string)

  • %ASA-6-617002: Removing v0 PDP Context with TID tid from GGSN ip_address and SGSN ip_address, Cause: value error_code (string), Reason: reason

  • %ASA-6-617002: Removing v1 {primary | secondary} PDP Context with TID tid from GGSN ip_address and SGSN ip_address, Cause: value error_code (string), Reason: reason

  • %ASA-6-617002: Removing v2 {primary | secondary} PDP Context with TID tid from PGW ip_address and SGW ip_address, Cause: value error_code (string), Reason: reason

  • %ASA-6-617003: GTP Tunnel created from source_interfacesource_addresssource_portsource_interfacedest_address

  • %ASA-6-617004: GTP connection created for response from source_interfacesource_address0source_interfacedest_address

  • %ASA-6-617100: Teardown num_connsuser_ip

  • %ASA-6-618001: Denied STUN packet msg_type from inside_ifc:source_addr/source_port to outside_ifc:destination_addr/destination_port for connection conn_id, malformed message header

  • %ASA-6-618001: Denied STUN packet msg_type from inside_ifc:source_addr/source_port to outside_ifc:destination_addr/destination_port for connection conn_id, translation id doesn't match previous entry

  • %ASA-6-620001: Pre-allocate CTIQBE {RTP | RTCP} channel for interface_name:outside_address to interface_name:inside_address/inside_port from message_name message

  • %ASA-6-620001: Pre-allocate CTIQBE {RTP | RTCP} channel for interface_name:outside_address/outside_port to interface_name:inside_address from message_name message

  • %ASA-6-621001: Interface interface_name does not support multicast, not enabled

  • %ASA-6-621002: Interface interface_name does not support multicast, not enabled

  • %ASA-6-621003: The event queue size has exceeded number

  • %ASA-6-621006: Mrib disconnected, (IP_address, IP_address) event cancelled

  • %ASA-6-621007: Bad register from interface_name:IP_address to IP_address for (IP_address, IP_address)

  • %ASA-6-622001: action tracked route destination_network netmask nexthop_address, distance admin_distance, table routing_table_name, on interface interface_name

  • %ASA-6-622101: Starting regex table compilation for match_command, table entries = regex_num entries

  • %ASA-6-622102: Completed regex table compilation for match_command, table size = num bytes

  • %ASA-6-634001: DAP: User user, Addr ipaddr, Connection connection; The following DAP records were selected for this connection: DAP Record names

  • %ASA-6-709009: (unit-role) Configuration on Active and Standby is matching. No config sync. Time elapsed time-elapsed ms

  • %ASA-6-709010: Configuration between units doesn't match. Going for config sync (sync-string). Time elapsed time-elapsed ms

  • %ASA-6-709011: Failover configuration replication completed in time ms

  • %ASA-6-709012: Skip configuration replication from mate as configuration on Active and Standby is matching

  • %ASA-6-713124: Group = groupname, Username = username, IP = peerIP Received DPD sequence number rcv_sequence_# in DPD Action, description expected seq #

  • %ASA-6-713128: IP = peerIP Connection attempt to VCPIP redirected to VCA peer IP_address via load balancing

  • %ASA-6-713145: Group = groupname, Username = username, IP = peerIP Detected Hardware Client in network extension mode, adding static route for address: IP_address, mask: netmask

  • %ASA-6-713147: Group = groupname, Username = username, IP = peerIP Terminating tunnel to Hardware Client in network extension mode, deleting static route for address: IP_address, mask: netmask

  • %ASA-6-713172: Group = groupname, Username = username, IP = peerIP Automatic NAT Detection Status: Remote end is |is not behind a NAT device This end is |is not behind a NAT device

  • %ASA-6-713177: Group = groupname, Username = username, IP = peerIP Received remote Proxy Host FQDN in ID Payload: Host Name: host_name Address IP_address, Protocol protocol, Port port

  • %ASA-6-713184: Group = groupname, Username = username, IP = peerIP Client Type: Client_type Client Application Version: Application_version_string

  • %ASA-6-713211: Group = groupname, Username = username, IP = peerIP Adding static route for L2L peer coming in on a dynamic map. address: IP_address, mask: netmask

  • %ASA-6-713213: Group = groupname, Username = username, IP = peerIP Deleting static route for L2L peer that came in on a dynamic map. address: IP_address, mask: netmask

  • %ASA-6-713215: Group = groupname, Username = username, IP = peerIP No match against Client Type and Version rules. Client: type version is /is not allowed by default

  • %ASA-6-713219: Group = groupname, Username = username, IP = peerIP Queuing KEY-ACQUIRE messages to be processed when P1 SA is complete.

  • %ASA-6-713220: Group = groupname, Username = username, IP = peerIP De-queuing KEY-ACQUIRE messages that were left pending.

  • %ASA-6-713228: Group = group, Username = uname, IP = remote_IP_address Assigned private IP address assigned_private_IP to remote user

  • %ASA-6-713235: Group = groupname, Username = username, IP = peerIP Attempt to send an IKE packet from standby unit. Dropping the packet!

  • %ASA-6-713256: IP = peer-IP IP = peer-IP, Sending spoofed ISAKMP Aggressive Mode message 2 due to receipt of unknown tunnel group. Aborting connection.

  • %ASA-6-713265: Group = groupname, Username = username, IP = peerIP Adding static route for L2L peer coming in on a dynamic map. address: IP_address, mask: /prefix_len

  • %ASA-6-713267: Group = groupname, Username = username, IP = peerIP Deleting static route for L2L peer that came in on a dynamic map. address: IP_address, mask: /prefix_len

  • %ASA-6-713269: Group = groupname, Username = username, IP = peerIP Detected Hardware Client in network extension mode, adding static route for address: IP_address, mask: /prefix_len

  • %ASA-6-713271: Group = groupname, Username = username, IP = peerIP Terminating tunnel to Hardware Client in network extension mode, deleting static route for address: IP_address, mask:/prefix_len

  • %ASA-6-713273: Group = groupname, Username = username, IP = peerIP Deleting static route for client address: IP_Address IP_Address address of client whose route is being removed

  • %ASA-6-713905: Descriptive_event_string.

  • %ASA-6-716001: Group groupuserip

  • %ASA-6-716002: Group GroupPolicyusernameipUser Requested

  • %ASA-6-716003: Group groupuseripurlstringstring

  • %ASA-6-716004: Group groupuseripurlstringstring

  • %ASA-6-716005: Group groupuseripreasonstring

  • %ASA-6-716006: Group nameuseriP

  • %ASA-6-716009: Group groupuserIP

  • %ASA-6-716038: Group groupuserip

  • %ASA-6-716039: Group nameuseripsession-type

  • %ASA-6-716040: Reboot pending, new sessions disabled. Denied user login.

  • %ASA-6-716041: access-list acl_ID actionurlcount

  • %ASA-6-716042: access-list acl_IDactionsource_interfacesource_addresssource_portdest_interfacedest_addressdest_portcount

  • %ASA-6-716043 Group group-name, User user-name, IP IP_address: WebVPN Port Forwarding Java applet started. Created new hosts file mappings

  • %ASA-6-716049: Group group-nameuser-nameIP_address

  • %ASA-6-716050: Error adding to ACL: ace_command_line

  • %ASA-6-716051: Group group-nameuser-nameIP_address

  • %ASA-6-716055: Group group-name User user-name IP IP_address Authentication to SSO server name: name type type succeeded

  • %ASA-6-716058: Group groupuserip

  • %ASA-6-716059: Group groupuseripip2

  • %ASA-6-716060: Group groupuserip

  • %ASA-6-717003: Certificate received from Certificate Authority for trustpoint trustpoint_name

  • %ASA-6-717004: PKCS #12 export failed for trustpoint trustpoint_name

  • %ASA-6-717005: PKCS #12 export succeeded for trustpoint trustpoint_name

  • %ASA-6-717006: PKCS #12 import failed for trustpoint trustpoint_name

  • %ASA-6-717007: PKCS #12 import succeeded for trustpoint trustpoint_name

  • %ASA-6-717016: Removing expired CRL from the CRL cache. Issuer: issuer

  • %ASA-6-717022: Certificate was successfully validated. certificate_identifiers

  • %ASA-6-717028: Certificate chain was successfully validated additional info

  • %ASA-6-717033: OCSP response received.

  • %ASA-6-717043: Local CA Server certificate enrollment related info for user: userinfo

  • %ASA-6-717047: Revoked certificate issued to user: username,serial number

  • %ASA-6-717048: Unrevoked certificate issued to user: username,serial number

  • %ASA-6-717056: Attempting typeSrcInterfaceSrcIPSrc PortDst IP

  • %ASA-6-717058: Automatic import of trustpool certificate bundle is successful: No change in trustpool bundle | Trustpool updated in flash

  • %ASA-6-717059: Peer certificate with serial number: serial, subject: subject_name, issuer: issuer_name matched the configured certificate map map_name

  • %ASA-6-718003: Got unknown peer message [message_numberIP_addressversion_numberversion_number

  • %ASA-6-718004: Got unknown internal message [message_number

  • %ASA-6-718013: Peer[IP_address

  • %ASA-6-718027: Received unexpected KEEPALIVE request from [IP_address

  • %ASA-6-718030: Received planned OOS from [IP_address

  • %ASA-6-718037: Master processed number_of_timeouts

  • %ASA-6-718038: Slave processed number_of_timeouts

  • %ASA-6-718039: Process dead peer[IP_address

  • %ASA-6-718040: Timed-out exchange ID[exchange_ID

  • %ASA-6-718051: Deleted secure tunnel to peer[IP_address

  • %ASA-6-719001: Email Proxy session could not be established: session limit of maximum_sessions has been reached.

  • %ASA-6-719003: Email Proxy session pointer resources have been freed for source_address.

  • %ASA-6-719004: Email Proxy session pointer has been successfully established for source_address.

  • %ASA-6-719010: protocol Email Proxy feature is disabled on interface interface_name.

  • %ASA-6-719011: Protocol Email Proxy feature is enabled on interface interface_name.

  • %ASA-6-719012: Email Proxy server listening on port port for mail protocol protocol.

  • %ASA-6-719013: Email Proxy server closing port port for mail protocol protocol.

  • %ASA-6-719017: WebVPN user: vpnuser invalid dynamic ACL.

  • %ASA-6-719018: WebVPN user: vpnuser ACL ID acl_ID not found

  • %ASA-6-719019: WebVPN user: vpnuser authorization failed.

  • %ASA-6-719020: WebVPN user vpnuser authorization completed successfully.

  • %ASA-6-719021: WebVPN user: vpnuser is not checked against ACL.

  • %ASA-6-719022: WebVPN user vpnuser has been authenticated.

  • %ASA-6-719023: WebVPN user vpnuser has not been successfully authenticated. Access denied.

  • %ASA-6-719024: Email Proxy piggyback auth fail: session = pointer user=vpnuser addr=source_address

  • %ASA-6-719025: Email Proxy DNS name resolution failed for hostname.

  • %ASA-6-719026: Email Proxy DNS name hostname resolved to IP_address.

  • %ASA-6-720002: (VPN-unit) Starting VPN Stateful Failover Subsystem...

  • %ASA-6-720003: (VPN-unit) Initialization of VPN Stateful Failover Component completed successfully

  • %ASA-6-720004: (VPN-unit) VPN failover main thread started.

  • %ASA-6-720005: (VPN-unit) VPN failover timer thread started.

  • %ASA-6-720006: (VPN-unit) VPN failover sync thread started.

  • %ASA-6-720010: (VPN-unit) VPN failover client is being disabled

  • %ASA-6-720012: (VPN-unit) Failed to update IPSec failover runtime data on the standby unit.

  • %ASA-6-720014: (VPN-unit) Phase 2 connection entry (msg_id=message_number, my cookie=mine, his cookie=his) contains no SA list.

  • %ASA-6-720015: (VPN-unit) Cannot found Phase 1 SA for Phase 2 connection entry (msg_id=message_number, my cookie=mine, his cookie=his).

  • %ASA-6-720023: (VPN-unit) HA status callback: Peer is not present.

  • %ASA-6-720024: (VPN-unit) HA status callback: Control channel is status.

  • %ASA-6-720025: (VPN-unit) HA status callback: Data channel is status.

  • %ASA-6-720026: (VPN-unit) HA status callback: Current progression is being aborted.

  • %ASA-6-720027: (VPN-unit) HA status callback: My state state.

  • %ASA-6-720028: (VPN-unit) HA status callback: Peer state state.

  • %ASA-6-720029: (VPN-unit) HA status callback: Start VPN bulk sync state.

  • %ASA-6-720030: (VPN-unit) HA status callback: Stop bulk sync state.

  • %ASA-6-720032: (VPN-unit) HA status callback: id=ID, seq=sequence_#, grp=group, event=event, op=operand, my=my_state, peer=peer_state.

  • %ASA-6-720037: (VPN-unit) HA progression callback: id=id,seq=sequence_number,grp=group,event=event,op=operand, my=my_state,peer=peer_state.

  • %ASA-6-720039: (VPN-unit) VPN failover client is transitioning to active state

  • %ASA-6-720040: (VPN-unit) VPN failover client is transitioning to standby state.

  • %ASA-6-720045: (VPN-unit) Start bulk syncing of state information on standby unit.

  • %ASA-6-720046: (VPN-unit) End bulk syncing of state information on standby unit

  • %ASA-6-720056: (VPN-unit) VPN Stateful failover Message Thread is being disabled.

  • %ASA-6-720057: (VPN-unit) VPN Stateful failover Message Thread is enabled.

  • %ASA-6-720058: (VPN-unit) VPN Stateful failover Timer Thread is disabled.

  • %ASA-6-720059: (VPN-unit) VPN Stateful failover Timer Thread is enabled.

  • %ASA-6-720060: (VPN-unit) VPN Stateful failover Sync Thread is disabled.

  • %ASA-6-720061: (VPN-unit) VPN Stateful failover Sync Thread is enabled.

  • %ASA-6-720062: (VPN-unit) Active unit started bulk sync of state information to standby unit.

  • %ASA-6-720063: (VPN-unit) Active unit completed bulk sync of state information to standby.

  • %ASA-6-721001: (device) WebVPN Failover SubSystem started successfully.(device) either WebVPN-primary or WebVPN-secondary.

  • %ASA-6-721002: (device) HA status change: event event, my state my_state, peer state peer.

  • %ASA-6-721003: (device) HA progression change: event event, my state my_state, peer state peer.

  • %ASA-6-721004: (device) Create access list list_name on standby unit.

  • %ASA-6-721005: (device) Fail to create access list list_name on standby unit.

  • %ASA-6-721006: (device) Update access list list_name on standby unit.

  • %ASA-6-721008: (device) Delete access list list_name on standby unit.

  • %ASA-6-721009: (device) Fail to delete access list list_name on standby unit.

  • %ASA-6-721010: (device) Add access list rule list_name, line line_no on standby unit.

  • %ASA-6-721012: (device) Enable APCF XML file file_name on the standby unit.

  • %ASA-6-721014: (device) Disable APCF XML file file_name on the standby unit.

  • %ASA-6-721016: (device) WebVPN session for client user user_name, IP ip_address has been created.

  • %ASA-6-721018: (device) WebVPN session for client user user_name, IP ip_address has been deleted.

  • %ASA-6-722013: Group groupuser-nameIP_addresstype-nummessage

  • %ASA-6-722014: Group groupuser-nameIP_addresstype-nummessage

  • %ASA-6-722022: Group group-nameuser-nameaddr(TCP | UDP)(with | without)

  • %ASA-6-722023: Group group User user_name IP ip_address conn_type SVC connection terminated with|without compression

  • %ASA-6-722024: SVC Global Compression Enabled

  • %ASA-6-722025: SVC Global Compression Disabled

  • %ASA-6-722026: Group groupuser-nameIP_address

  • %ASA-6-722027: Group groupuser-nameIP_address

  • %ASA-6-722036: Group groupuser-nameIP_addresslengthnum

  • %ASA-6-722051: Group group-policy User username IP public-ip IPv4 Address assigned-ip IPv6 address assigned-ip assigned to session

  • %ASA-6-722053: Group guipuser-agent

  • %ASA-6-722055: Group group-policyusernamepublic-ipuser-agent

  • %ASA-6-723001: Group group-nameuser-nameIP_addressconnection

  • %ASA-6-723002: Group group-nameuser-nameIP_addressconnection

  • %ASA-6-725001: Starting SSL handshake with peer-typeinterfacesrc-ipsrc-portdst-ipdst-portprotocol

  • %ASA-6-725002: Device completed SSL handshake with peer-typeinterfacesrc-ipsrc-portdst-ipdst-portprotocol-version

  • %ASA-6-725003: SSL client peer-typeinterfacesrc-ipsrc-portdst-ip

  • %ASA-6-725004: Device requesting certificate from SSL client peer-typeinterfacesrc-ipsrc-portdst-ip

  • %ASA-6-725005: SSL server peer-typeinterfacesrc-ipsrc-portdst-ip

  • %ASA-6-725006: Device failed SSL handshake with peer-typeinterfacesrc-ipsrc-portdst-ipdst-port

  • %ASA-6-725007: SSL session with peer-typeinterfacesrc-ipsrc-portdst-ipdst-port

  • %ASA-6-725025: SSL Pre-auth connection rate limit hit s watermark

  • %ASA-6-726001: Inspected im_protocolim_serviceim_client_1im_client_2src_ifcsipsportdest_ifcdipdportaction

  • %ASA-6-730002: Group groupname, User username, IP ipaddr: VLAN Mapping to VLAN vlanid failed.

  • %ASA-6-730004: Group groupnameusernameipaddrvlanid

  • %ASA-6-730005: Group groupname User username IP ipaddr VLAN ID vlanid from AAA is invalid.

  • %ASA-6-730008: Group groupname, User username, IP ipaddr, VLAN MAPPING timeout waiting NACApp.

  • %ASA-6-725016: Device selects trust-point trustpointpeer-typeinterfacesrc-ipsrc-portdst-ipdst-port

  • %ASA-6-731001: NAC policy added: name: policyname Type: policytype.

  • %ASA-6-731002: NAC policy deleted: name: policyname Type: policytype.

  • %ASA-6-731003: nac-policy unused: name: policyname Type: policytype.

  • %ASA-6-732001: Group groupname, User username, IP ipaddr, Fail to parse NAC-SETTINGS nac-settings-id, terminating connection.

  • %ASA-6-732002: Group groupname, User username, IP ipaddr, NAC-SETTINGS settingsid from AAA ignored, existing NAC-SETTINGS settingsid_inuse used instead.

  • %ASA-6-732003: Group groupname, User username, IP ipaddr, NAC-SETTINGS nac-settings-id from AAA is invalid, terminating connection.

  • %ASA-6-734001: DAP: User useripaddrconnection

  • %ASA-6-737005: IPAA: Session=sessiontunnel-group

  • %ASA-6-737006: IPAA: Session=sessiontunnel-group

  • %ASA-6-737009: IPAA: Session=sessionip-address

  • %ASA-6-737010: IPAA: Session=sessionip-address

  • %ASA-6-737014: IPAA: Session=sessionip-address

  • %ASA-6-737015: IPAA: Session=sessionip-address

  • %ASA-6-737016: IPAA: Session=sessionpool-nameip-address

  • %ASA-6-737017: IPAA: Session=sessionnum

  • %ASA-6-737026: IPAA: Session= sessionip-address

  • %ASA-6-737029: IPAA: Session=session, Added {ip_address | ipv6_address} to standby

  • %ASA-6-737031: IPAA: Session= session

  • %ASA-6-737035: IPAA: Session=sessionaddress

  • %ASA-6-737036: IPAA: Session=session, Client assigned address from DHCP

  • %ASA-6-737205: VPNFIP: Pool=poolmessage

  • %ASA-6-737406: POOLIP: Pool=poolmessage

  • %ASA-6-741000: Coredump filesystem image created on variable 1variable 2

  • %ASA-6-741001: Coredump filesystem image on variablevariablevariable

  • %ASA-6-741002: Coredump log and filesystem contents cleared on variable 1

  • %ASA-6-741003: Coredump filesystem and it's contents removed on variable 1

  • %ASA-6-741004: Coredump configuration reset to default values

  • %ASA-6-746001: user-identity: user-to-IP address databases

  • %ASA-6-746002: user-identity: user-to-IP address databases

  • %ASA-6-746008: user-identity: NetBIOS Logout Probe Process started

  • %ASA-6-746009: user-identity: NetBIOS Logout Probe Process stopped

  • %ASA-6-746017: user-identity: Update import-user domain_name

  • %ASA-6-746018: user-identity: Update import-user domain_name

  • %ASA-6-747004: Clustering: state machine changed from state state-name to state-name.

  • %ASA-6-748008: [CPU load percentagepercentageslot_numberchassis_numbermember-namepercentagepercentage

  • %ASA-6-748009: [CPU load percentage | memory load percentage] of chassis chassis_number exceeds overflow protection threshold [CPU percentage | memory percentage}. System may be oversubscribed on chassis failure.

  • %ASA-6-780005: RULE ENGINE: Started compilation for session transaction - description of the transaction

  • %ASA-6-780006: RULE ENGINE: Finished compilation for session transaction - description of the transaction

  • %ASA-6-803001: bypass is continuing after power up, no protection will be provided by the system for traffic over Interface

  • %ASA-6-803002: no protection will be provided by the system for traffic over Interface

  • %ASA-6-751023: Unknown client connection.

  • %ASA-6-751026: Client OS: client-os Client: client-name client-version

  • %ASA-6-767001: Inspect-name: Dropping an unsupported IPv6/IP46/IP64 packet from interface:IP Addr to interface:IP Addr (fail-close)

  • %ASA-6-769007: UPDATE: Image version is version_number

  • %ASA-6-776008: CTS SXP: Connection with peer IP (instance connection instance num) state changed from original state to final state.

  • %ASA-6-776251: CTS SGT-MAP: Binding binding IP - SGname(SGT) from source name added to binding manager.

  • %ASA-6-776253: CTS SGT-MAP: Binding binding IP - new SGname(SGT) from new source name changed from old sgt: old SGname(SGT) from old source old source name.

  • %ASA-6-776303: CTS Policy: Security-group name "sgnamesgt

  • %ASA-6-776311: CTS Policy: Previously unresolved security-group name "sgnamesgt

  • %ASA-6-775001: Scansafe: protocolconn_idinterface_namereal_addressreal_portidfw_userinterface_namereal_addressreal_portserver_interface_nameserver_ip_address

  • %ASA-6-775003: Scansafe: protocolconn_idinterface_namereal_addressreal_portidfw_userinterface_namereal_addressreal_port

  • %ASA-6-775006: Scansafe: Reachable backup server interfaceip_address

  • %ASA-6-772005: REAUTH: user 'username

  • %ASA-6-775005: Scansafe: Primary server server-nameip_address

  • %ASA-6-778001: VXLAN: Packet was discarded with invalid segment-id segment_id for protocol from ifc_name:ip_address/port to ip_address/port

  • %ASA-6-778002: VXLAN: There is no VNI interface for segment-id. Packet was discarded segment_id

  • %ASA-6-778003: VXLAN: Invalid VXLAN segment-id segment-id for protocol from ifc-name:(IP-address/port) to ifc-name:(IP-address/port) in FP.

  • %ASA-6-778004: VXLAN: Invalid VXLAN header for protocol from ifc-name:(IP-address/port) to ifc-name:(IP-address/port) in FP.

  • %ASA-6-778005: VXLAN: Packet with VXLAN segment-id segment-id from ifc-name is denied by FP L2 check.

  • %ASA-6-778006: VXLAN: Invalid VXLAN UDP checksum from ifc-name:(IP-address/port) to ifc-name:(IP-address/port) in FP.

  • %ASA-6-778007: VXLAN: Packet from ifc-name:IP-address/port to IP-address/port was discarded due to invalid NVE peer.

  • %ASA-6-778008: VXLAN: There is no VNI interface for segment-id. Packet was discarded

  • %ASA-6-779001: STS: Out-tag lookup failed for in-tag segment-id of protocol from ifc-name:IP-address/port to IP-address/port.

  • %ASA-6-779002: STS: STS and NAT locate different egress interface for segment-id segment-idprotocolifc-nameIP-addressportIP-addressport

  • %ASA-6-780001: RULE ENGINE: Started compilation for access-group transaction - description of the transaction.

  • %ASA-6-780002: RULE ENGINE: Finished compilation for access-group transaction - description of the transaction.

  • %ASA-6-780003: RULE ENGINE: Started compilation for nat transaction - description of the transaction

  • %ASA-6-780004: RULE ENGINE: Finished compilation for nat transaction - description of the transaction

  • %ASA-6-801001: Dropping UDP from address/port to address/port on interface interface_name.

  • %ASA-6-801002: Dropping TCP from address/port to address/port flags on interface interface_name

  • %ASA-6-801003: Dropping ICMP type=number, code=code from address to address on interface interface_name

  • %ASA-6-802005: IP ip_address Received MDM request details.

  • %ASA-6-803001: bypass is continuing after power up, no protection will be provided by the system for traffic over Interface

  • %ASA-6-803002: no protection will be provided by the system for traffic over Interface

  • %ASA-6-803003: User disabled bypass manually on Interface

  • %ASA-6-804001: Interface GigabitEthernet1/31000BaseSX

  • %ASA-6-804002: Interface GigabitEthernet1/3

  • %ASA-6-805001: Offloaded conn Flow for connection conn_id from outside_ifc:outside_addr/outside_port (mapped_addr/mapped_port) to inside_ifc:inside_addr/inside_port (mapped_addr/mapped_port)

  • %ASA-6-805002: conn Flow is no longer offloaded for connection conn_id from outside_ifc:outside_addr/outside_port (mapped_addr/mapped_port) to inside_ifc:inside_addr/inside_port (mapped_addr/mapped_port)

  • %ASA-6-805003: TCP Flow could not be offloaded for connection conn_id from outside_ifc:outside_addr/outside_port (mapped_addr/mapped_port) to inside_ifc:inside_addr/inside_port (mapped_addr/mapped_port) reason

  • %ASA-6-806001: Primary alarm CPU temperature is High temp

  • %ASA-6-806002: Primary alarm for CPU high temperature is cleared

  • %ASA-6-806003: Primary alarm CPU temperature is Low temp

  • %ASA-6-806004: Primary alarm for CPU Low temperature is cleared

  • %ASA-6-806005: Secondary alarm CPU temperature is High temp

  • %ASA-6-806006: Secondary alarm for CPU High temperature is cleared

  • %ASA-6-806007: Secondary alarm CPU temperature is Low temp

  • %ASA-6-806008: Secondary alarm for CPU Low temperature is cleared

  • %ASA-6-806009: Alarm asserted for ALARM_IN_1 description

  • %ASA-6-806010: Alarm cleared for ALARM_IN_1 description

  • %ASA-6-806011: Alarm asserted for ALARM_IN_2 description

  • %ASA-6-806012: Alarm cleared for ALARM_IN_2 description

  • %ASA-6-812007: Inline-set hardware-bypass mode configuration status

  • %ASA-6-861012: AVC: Installing visibility NSG failed; error_string.

  • %ASA-6-880001: Ingress ifc Ingress interfacesource ipaddress destination ipaddressoutside interface 1metric-typeoutside interface 2

  • %ASA-6-8300001: VPN session redistribution variable 1

  • %ASA-6-8300002: Moved variable 1 sessions to variable 2

  • %ASA-6-8300004: variable 1 request to move variable 2 sessions from variable 3 to variable 4

Debugging Messages, Severity 7

The following messages appear at severity 7, debugging:

  • %ASA-7-108006: Detected ESMTP size violation from src_ifcsipsportdest_ifcdipdportdecl_sizeact_size

  • %ASA-7-109014: A non-telnet connection was denied to the configured Virtual Telnet IP Address

  • %ASA-7-109021: Uauth null proxy error (uap number

  • %ASA-7-111009: User 'userstring

  • %ASA-7-113028: Extraction of username from VPN client certificate has string.num

  • %ASA-7-199019: syslog

  • %ASA-7-304005: URL Server IP_addressurl

  • %ASA-7-304009: Ran out of buffer blocks specified by url-block command

  • %ASA-7-325007: IPv6 security check failed. Dropped packet from interface:address/port to address/port with source MAC address MAC_address and hop limit limit_value

  • %ASA-7-333004: EAP-SQ response invalid - context:0x%08x.

  • %ASA-7-333005: EAP-SQ response contains invalid TLV(s) - context:EAP-context

  • %ASA-7-333006: EAP-SQ response with missing TLV(s) - context:EAP-context

  • %ASA-7-333007: EAP-SQ response TLV has invalid length - context:EAP-context

  • %ASA-7-333008: EAP-SQ response has invalid nonce TLV - context:EAP-context

  • %ASA-7-335007: NAC Default ACL not configured - host-address

  • %ASA-7-342001: The REST API Agent was successfully started.

  • %ASA-7-342005: REST API image has been successfully installed.

  • %ASA-7-342007: REST API image has been successfully uninstalled.

  • %ASA-7-419003: Cleared TCP urgent flag

  • %ASA-7-421004: Failed to inject {TCP|UDP}IP_addressportIP_addressport

  • %ASA-7-444307: %SMART_LIC-7-DAILY_JOB_TIMER_RESET: Daily job timer reset.

  • %ASA-7-609001: Built local-host zone_name:ip_address

  • %ASA-7-609002: Teardown local-host zone_name:ip_address duration time

  • %ASA-7-701001: alloc_user() out of Tcp_user objects

  • %ASA-7-701002: alloc_proxy() out of Tcp_proxy objects

  • %ASA-7-702307: IPSEC: An directiontunnel_typespi local_IPremote_IP

  • %ASA-7-703001: H.225 message received from interface_nameIP_addressportinterface_nameIP_addressportnumber

  • %ASA-7-703002: Received H.225 Release Complete with newConnectionNeeded for interface_nameIP_addressinterface_nameIP_addressport

  • %ASA-7-703008: Allowing early-message: msg_str before SETUP from src_int_name:src_ip/src_port to dest_int_name:dest_ip/dest_port

  • %ASA-7-709001: FO replication failed: cmd=commandcode

  • %ASA-7-709002: FO unreplicable: cmd=command

  • %ASA-7-710001: TCPsource_addresssource_portinterface_namedest_addressservice

  • %ASA-7-710002: {TCP|UDP} access permitted from source_address/source_port to interface_name:dest_address/service

  • %ASA-7-710004: TCPSrc_ipSrc_portIn_nameDest_ipDest_portCurr_connConn_lmt

  • %ASA-7-710005: {TCP|UDP|SCTP}source_addresssource_portinterface_namedest_addressservice

  • %ASA-7-710006: protocolsource_addressinterface_namedest_address

  • %ASA-7-710007: NAT-T keepalive received from inside: ip-Addrportoutsideip-Addrport

  • %ASA-7-711001: debug_trace_msg

  • %ASA-7-711003: Unknown/Invalid interface identifier(vpifnum) detected.

  • %ASA-7-711006: CPU profiling has started for n-samplesreason-string

  • %ASA-7-713024: Group = groupname, Username = username, IP = peerIP Group group IP ip Received local Proxy Host data in ID Payload: Address IP_address, Protocol protocol, Port port

  • %ASA-7-713025: Group = groupname, Username = username, IP = peerIP Received remote Proxy Host data in ID Payload: Address IP_address, Protocol protocol, Port port

  • %ASA-7-713028: Group = groupname, Username = username, IP = peerIP Received local Proxy Range data in ID Payload: Addresses IP_address - IP_address, Protocol protocol, Port port

  • %ASA-7-713029: Group = groupname, Username = username, IP = peerIP Received remote Proxy Range data in ID Payload: Addresses IP_address - IP_address, Protocol protocol, Port port

  • %ASA-7-713034: Group = groupname, Username = username, IP = peerIP Received local IP Proxy Subnet data in ID Payload: Address IP_address, Mask netmask, Protocol protocol, Port port

  • %ASA-7-713035: Group = groupname, Username = username, IP = peerIP Group group IP ip Received remote IP Proxy Subnet data in ID Payload: Address IP_address, Mask netmask, Protocol protocol, Port port

  • %ASA-7-713039: Group = groupname, Username = username, IP = peerIP Send failure: Bytes (number ), Peer: IP_address

  • %ASA-7-713040: Group = groupname, Username = username, IP = peerIP Could not find connection entry and can not encrypt: msgid message_number

  • %ASA-7-713052: Group = groupname, Username = username, IP = peerIP User (user ) authenticated.

  • %ASA-7-713066: Group = groupname, Username = username, IP = peerIP IKE Remote Peer configured for SA: SA_name

  • %ASA-7-713094: Group = groupname, Username = username, IP = peerIP Cert validation failure: handle invalid for Main /Aggressive Mode Initiator /Responder !

  • %ASA-7-713099: Group = groupname, Username = username, IP = peerIP Tunnel Rejected: Received NONCE length number is out of range!

  • %ASA-7-713103: Group = groupname, Username = username, IP = peerIP Invalid (NULL) secret key detected while computing hash

  • %ASA-7-713104: Group = groupname, Username = username, IP = peerIP Attempt to get Phase 1 ID data failed while hash computation

  • %ASA-7-713113: Group = groupname, Username = username, IP = peerIP Deleting IKE SA with associated IPsec connection entries. IKE peer: IP_address, SA address: internal_SA_address, tunnel count: count

  • %ASA-7-713114: Group = groupname, Username = username, IP = peerIP Connection entry (conn entry internal address) points to IKE SA (SA_internal_address ) for peer IP_address, but cookies don't match

  • %ASA-7-713117: Group = groupname, Username = username, IP = peerIP Received Invalid SPI notify (SPI SPI_Value )!

  • %ASA-7-713121: IP = peerIP Keep-alive type for this connection: keepalive_type

  • %ASA-7-713143: IP = peerIP Processing firewall record. Vendor: vendor(id), Product: product(id), Caps: capability_value, Version Number: version_number, Version String: version_text

  • %ASA-7-713160: Group = groupname, Username = username, IP = peerIP Remote user (session Id - id ) has been granted access by the Firewall Server

  • %ASA-7-713164: The Firewall Server has requested a list of active user sessions

  • %ASA-7-713169: Group = groupname, Username = username, IP = peerIP IKE Received delete for rekeyed SA IKE peer: IP_address, SA address: internal_SA_address, tunnelCnt: tunnel_count

  • %ASA-7-713170: Group = groupname, Username = username, IP = peerIP Group group IP ip IKE Received delete for rekeyed centry IKE peer: IP_address, centry address: internal_address, msgid: id

  • %ASA-7-713171: Group = groupname, Username = username, IP = peerIP NAT-Traversal sending NAT-Original-Address payload

  • %ASA-7-713187: Group = groupname, Username = username, IP = peerIP Tunnel Rejected: IKE peer does not match remote peer as defined in L2L policy IKE peer address: IP_address, Remote peer address: IP_address

  • %ASA-7-713190: Group = groupname, Username = username, IP = peerIP Got bad refCnt ( ref_count_value ) assigning IP_address ( IP_address )

  • %ASA-7-713204: Group = groupname, Username = username, IP = peerIP Adding static route for client address: IP_address

  • %ASA-7-713221: Group = groupname, Username = username, IP = peerIP Static Crypto Map check, checking map = crypto_map_tag, seq = seq_number...

  • %ASA-7-713222: Group = groupname, Username = username, IP = peerIP Group group Username username IP ip Static Crypto Map check, map = crypto_map_tag, seq = seq_number, ACL does not match proxy IDs src:source_address dst:dest_address

  • %ASA-7-713223: Group = groupname, Username = username, IP = peerIP Static Crypto Map check, map = crypto_map_tag, seq = seq_number, no ACL configured

  • %ASA-7-713224: Group = groupname, Username = username, IP = peerIP Static Crypto Map Check by-passed: Crypto map entry incomplete!

  • %ASA-7-713225: Group = groupname, Username = username, IP = peerIP [IKEv1], Static Crypto Map check, map map_name, seq = sequence_number is a successful match

  • %ASA-7-713233: (VPN-unit) Remote network (remote network) validated for network extension mode.

  • %ASA-7-713234: (VPN-unit) Remote network (remote network) from network extension mode client mismatches AAA configuration (aaa network).

  • %ASA-7-713236: Group = groupname, Username = username, IP = peerIP IKE_DECODE tx/rx Message (msgid=msgid) with payloads:payload1 (payload1_len) + payload2 (payload2_len)...total length: tlen

  • %ASA-7-713263: Group = groupname, Username = username, IP = peerIP Received local IP Proxy Subnet data in ID Payload: Address IP_address, Mask /prefix_len, Protocol protocol, Port port

  • %ASA-7-713264: Group = groupname, Username = username, IP = peerIP Received local IP Proxy Subnet data in ID Payload: Address IP_address, Mask/prefix_len, Protocol protocol, Port port {“Received remote IP Proxy Subnet data in ID Payload: Address ip_address, Mask/mask, Protocol protocol_nane, Port port_number ”}

  • %ASA-7-713906: Descriptive_event_string.

  • %ASA-7-714001: description_of_event_or_packet

  • %ASA-7-714002: Group = groupname, Username = username, IP = IP_address IKE Initiator starting QM: msg id = message_number

  • %ASA-7-714003: IP = IP_address IKE Responder starting QM: msg id = message_number

  • %ASA-7-714004: Group = groupname, Username = username, IP = IP_address IKE Initiator sending 1st QM pkt: msg id = message_number

  • %ASA-7-714005: Group = groupname, Username = username, IP = IP_address IKE Responder sending 2nd QM pkt: msg id = message_number

  • %ASA-7-714006: Group = groupname, Username = username, IP = IP_address IKE Initiator sending 3rd QM pkt: msg id = message_number

  • %ASA-7-714007: IKE Initiator sending Initial Contact

  • %ASA-7-714011: Group = groupname, Username = username, IP = IP_address Description of received ID values

  • %ASA-7-715001: Descriptive statement

  • %ASA-7-715004: subroutine name Q Send failure: RetCode (return_code )

  • %ASA-7-715005: subroutine name Bad message code: Code (message_code )

  • %ASA-7-715006: Group = groupname, Username = username, IP = IP_address IKE got SPI from key engine: SPI = SPI_value

  • %ASA-7-715007: Group = groupname, Username = username, IP = IP_address IKE got a KEY_ADD msg for SA: SPI = SPI_value

  • %ASA-7-715008: Could not delete SA SA_address, refCnt = number, caller = calling_subroutine_address

  • %ASA-7-715009: Group = groupname, Username = username, IP = IP_address IKE Deleting SA: Remote Proxy IP_address, Local Proxy IP_address

  • %ASA-7-715013: Group = groupname, Username = username, IP = IP_address Tunnel negotiation in progress for destination IP_address, discarding data

  • %ASA-7-715018: Group = groupname, Username = username, IP = IP_address IP Range type id was loaded: Direction %s,  From: %a, Through: %a

  • %ASA-7-715019: Group = group, Username = username, IP = ip Group group Username username IP ip IKEGetUserAttributes: Attribute name = name

  • %ASA-7-715020: Group = group, Username = username, IP = ip construct_cfg_set: Attribute name = name

  • %ASA-7-715021: Group = group, Username = username, IP = ip Delay Quick Mode processing, Cert/Trans Exch/RM DSID in progress

  • %ASA-7-715022: Group = group, Username = username, IP = ip Resume Quick Mode processing, Cert/Trans Exch/RM DSID completed

  • %ASA-7-715027: Group = group, Username = username, IP = ip IPsec SA Proposal # chosen_proposal, Transform # chosen_transform acceptable Matches global IPsec SA entry # crypto_map_index

  • %ASA-7-715028: Group = group, Username = username, IP = ip IKE SA Proposal # 1, Transform # chosen_transform acceptable Matches global IKE entry # crypto_map_index

  • %ASA-7-715031: Obtained IP addr (%s) prior to initiating Mode Cfg (XAuth %s)

  • %ASA-7-715032: Sending subnet mask (%s) to remote client

  • %ASA-7-715033: Group = group, Username = username, IP = ip Processing CONNECTED notify (MsgId message_number )

  • %ASA-7-715034: IP = ip action IOS keep alive payload: proposal=time 1 /time 2 sec.

  • %ASA-7-715035: IP = ip Starting IOS keepalive monitor: seconds sec.

  • %ASA-7-715036: Group = group, Username = username, IP = ip Sending keep-alive of type notify_type (seq number number )

  • %ASA-7-715037: Group = group, Username = username, IP = ip Unknown IOS Vendor ID version: major.minor.variance

  • %ASA-7-715038: Group = group, Username = username, IP = ip action Spoofing_information Vendor ID payload (version: major.minor.variance, capabilities: value )

  • %ASA-7-715039: Group = group, Username = username, IP = ip Unexpected cleanup of tunnel table entry during SA delete.

  • %ASA-7-715040: Deleting active auth handle during SA deletion: handle = internal_authentication_handle

  • %ASA-7-715041: Group = group, Username = username, IP = ip Received keep-alive of type keepalive_type, not the negotiated type

  • %ASA-7-715042: Group = group, Username = username, IP = ip IKE received response of type failure_type to a request from the IP_address utility

  • %ASA-7-715044: IP = ip Ignoring Keepalive payload from vendor not support KeepAlive capability

  • %ASA-7-715045: ERROR: malformed Keepalive payload

  • %ASA-7-715046: Group = groupname, Username = username, IP = IP_address Group = groupname, Username = username, IP = IP_address, constructing payload_description payload

  • %ASA-7-715047: Group = groupname, Username = username, IP = IP_address processing payload_description payload

  • %ASA-7-715048: Group = groupname, Username = username, IP = IP_address Send VID_type VID

  • %ASA-7-715049: Group = groupname, Username = username, IP = IP_address Received VID_type VID

  • %ASA-7-715050: Group = groupname, Username = username, IP = IP_address Claims to be IOS but failed authentication

  • %ASA-7-715051: IP = IP_address Received unexpected TLV type TLV_type while processing FWTYPE ModeCfg Reply

  • %ASA-7-715052: Group = groupname, Username = username, IP = IP_address Old P1 SA is being deleted but new SA is DEAD, cannot transition centries

  • %ASA-7-715053: Group = groupname, Username = username, IP = IP_address MODE_CFG: Received request for attribute_info !

  • %ASA-7-715054: MODE_CFG: Received attribute_name reply: value

  • %ASA-7-715055: Group = groupname, Username = username, IP = IP_address Send attribute_name

  • %ASA-7-715056: Group = groupname, Username = username, IP = IP_address Client is configured for TCP_transparency

  • %ASA-7-715057: Group = groupname, Username = username, IP = IP_address Auto-detected a NAT device with NAT-Traversal. Ignoring IPsec-over-UDP configuration.

  • %ASA-7-715058: Group = groupname, Username = username, IP = IP_address NAT-Discovery payloads missing. Aborting NAT-Traversal.

  • %ASA-7-715059: Group = groupname, Username = username, IP = IP_address Proposing/Selecting only UDP-Encapsulated-Tunnel and UDP-Encapsulated-Transport modes defined by NAT-Traversal

  • %ASA-7-715060: Group = groupname, Username = username, IP = IP_address Dropped received IKE fragment. Reason: reason

  • %ASA-7-715061: Group = groupname, Username = username, IP = IP_address Rcv'd fragment from a new fragmentation set. Deleting any old fragments.

  • %ASA-7-715062: Group = groupname, Username = username, IP = IP_address Error assembling fragments! Fragment numbers are non-continuous.

  • %ASA-7-715063: Group = groupname, Username = username, IP = IP_address Successfully assembled an encrypted pkt from rcv'd fragments!

  • %ASA-7-715064 -- IKE Peer included IKE fragmentation capability flags: Main Mode: true/false Aggressive Mode: true/false

  • %ASA-7-715065: Group = groupname, Username = username, IP = IP_address IKE state_machine subtype FSM error history (struct data_structure_address ) state, event : state /event pairs

  • %ASA-7-715066: Group = groupname, Username = username, IP = IP_address Can't load an IPsec SA! The corresponding IKE SA contains an invalid logical ID.

  • %ASA-7-715067: QM IsRekeyed: existing sa from different peer, rejecting new sa

  • %ASA-7-715068: Group = groupname, Username = username, IP = IP_address QM IsRekeyed: duplicate sa found by address, deleting old sa

  • %ASA-7-715069: Group = groupname, Username = username, IP = IP_address Invalid ESP SPI size of SPI_size

  • %ASA-7-715070: Group = groupname, Username = username, IP = IP_address Invalid IPComp SPI size of SPI_size

  • %ASA-7-715071: Group = groupname, Username = username, IP = IP_address AH proposal not supported

  • %ASA-7-715072: Group = groupname, Username = username, IP = IP_address Received proposal with unknown protocol ID protocol_ID

  • %ASA-7-715074: Group = groupname, Username = username, IP = IP_address Could not retrieve authentication attributes for peer IP_address

  • %ASA-7-715075: Group = group_name, Username = username, IP = IP_address Group = group_name, IP = IP_address Received keep-alive of type message_type (seq number number )

  • %ASA-7-715076: Group = group_name, Username = username, IP = IP_address Computing hash for ISAKMP

  • %ASA-7-715077: Pitcher: msg string, spi spi

  • %ASA-7-715078: Group = group_name, Username = username, IP = IP_address Received %s LAM attribute

  • %ASA-7-715079: Group = group_name, Username = username, IP = IP_address INTERNAL_ADDRESS: Received request for %s

  • %ASA-7-715080: Group = group_name, Username = username, IP = IP_address VPN: Starting P2 rekey timer: 28800 seconds.

  • %ASA-7-716008: WebVPN ACL: actionstring

  • %ASA-7-716010: Group groupuserip

  • %ASA-7-716011: Group groupuseripdomain

  • %ASA-7-716012: Group groupuseripdirectory

  • %ASA-7-716013: Group groupuseripfilename

  • %ASA-7-716014: Group groupuseripfilename

  • %ASA-7-716015: Group groupuseripfilename

  • %ASA-7-716016: Group groupuseripold_filenamenew_filename

  • %ASA-7-716017: Group groupuseripfilename

  • %ASA-7-716018: Group groupuseripfilename

  • %ASA-7-716019: Group groupuseripdirectory

  • %ASA-7-716020: Group groupuseripdirectory

  • %ASA-7-716021: File access DENIED, filename

  • %ASA-7-716024: Group nameuseripdescription

  • %ASA-7-716025: Group nameuseripdomaindescription

  • %ASA-7-716026: Group nameuseripdirectorydescription

  • %ASA-7-716027: Group nameuseripfilenamedescription

  • %ASA-7-716028: Group nameuseripfilenamedescription

  • %ASA-7-716029: Group nameuseripfilenamedescription

  • %ASA-7-716030: Group nameuseripfilenamedescription

  • %ASA-7-716031: Group nameuseripfilenamedescription

  • %ASA-7-716032: Group nameuseripfolderdescription

  • %ASA-7-716033: Group nameuseripfolderdescription

  • %ASA-7-716034: Group nameuseripfilename

  • %ASA-7-716035: Group nameuseripfilename

  • %ASA-7-716036: Group nameuseripuserserver

  • %ASA-7-716037: Group nameuseripuserserver

  • %ASA-7-716603: Received size-recvsrc-ip

  • %ASA-7-717024: Checking CRL from trustpoint: trustpoint name for purpose

  • %ASA-7-717025: Validating certificate chain containing number of certs

  • %ASA-7-717029: Identified client certificate within certificate chain. serial_number

  • %ASA-7-717030: Found a suitable trustpoint trustpoint name

  • %ASA-7-717034: No-check extension found in certificate. CRL check bypassed.

  • %ASA-7-717036: Looking for a tunnel group match based on certificate maps for peer certificate with certificate_identifier

  • %ASA-7-717038: Tunnel group match found. Tunnel Group: tunnel_group_namecertificate_identifier

  • %ASA-7-717041: Local CA Server event: event info

  • %ASA-7-717045: Local CA Server CRL info: info

  • %ASA-7-718001: Internal interprocess communication queue send failure: code [error_code

  • %ASA-7-718017: Got timeout for unknown peer[IP_addressmessage_type

  • %ASA-7-718018: Send KEEPALIVE request failure to [IP_address

  • %ASA-7-718019: Sent KEEPALIVE request to [IP_address

  • %ASA-7-718020: Send KEEPALIVE response failure to [IP_address

  • %ASA-7-718021: Sent KEEPALIVE response to [IP_address

  • %ASA-7-718022: Received KEEPALIVE request from [IP_address

  • %ASA-7-718023: Received KEEPALIVE response from [IP_address

  • %ASA-7-718025: Sent CFG UPDATE to [IP_address

  • %ASA-7-718026: Received CFG UPDATE from [IP_address

  • %ASA-7-718029: Sent OOS indicator to [IP_address

  • %ASA-7-718034: Sent TOPOLOGY indicator to [IP_address

  • %ASA-7-718035: Received TOPOLOGY indicator from [IP_address

  • %ASA-7-718036: Process timeout for req-type[type_valueexchange_IDIP_address

  • %ASA-7-718041: Timeout [msgType=type

  • %ASA-7-718046: Create group policy [policy_name

  • %ASA-7-718047: Fail to create group policy [policy_name

  • %ASA-7-718049: Created secure tunnel to peer[IP_address

  • %ASA-7-718056: Deleted Master peer, IP IP_address

  • %ASA-7-718058: State machine return code: action_routinereturn_code

  • %ASA-7-718059: State machine function trace: state=state_nameevent_nameaction_routine

  • %ASA-7-718088: Possible VPN LB misconfiguration. Offending device MAC [MAC_address

  • %ASA-7-719005: FSM NAME has been created using protocol for session pointer from source_address.

  • %ASA-7-719006: Email Proxy session pointer has timed out for source_address because of network congestion.

  • %ASA-7-719007: Email Proxy session pointer cannot be found for source_address.

  • %ASA-7-719009: Email Proxy service is starting.

  • %ASA-7-719015: Parsed emailproxy session pointer from source_address username: mailuser = mail_user, vpnuser = VPN_user, mailserver = server

  • %ASA-7-719016: Parsed emailproxy session pointer from source_address password: mailpass = ******, vpnpass= ******

  • %ASA-7-720031: (VPN-unit) HA status callback: Invalid event received. event=event_ID.

  • %ASA-7-720034: (VPN-unit) Invalid type (type) for message handler.

  • %ASA-7-720041: (VPN-unit) Sending type message id to standby unit

  • %ASA-7-720042: (VPN-unit) Receiving type message id from active unit

  • %ASA-7-720048: (VPN-unit) FSM action trace begin: state=state, last event=event, func=function.

  • %ASA-7-720049: (VPN-unit) FSM action trace end: state=state, last event=event, return=return, func=function.

  • %ASA-7-720050: (VPN-unit) Failed to remove timer. ID = id.

  • %ASA-7-722029: Group groupuser-nameIP_addressconnectionsDPD_connscompression_resetsdecompression_resets

  • %ASA-7-722030: Group groupuser-nameIP_addressdata_bytesctrl_bytesdata_pktsctrl_pktsdrop_pkts

  • %ASA-7-722031: Group groupuser-nameIP_addressdata_bytesctrl_bytesdata_pktsctrl_pktsdrop_pkts

  • %ASA-7-723003: No memory for WebVPN Citrix ICA connection connection

  • %ASA-7-723004: WebVPN Citrix encountered bad flow control flow

  • %ASA-7-723005: No channel to set up WebVPN Citrix ICA connection.

  • %ASA-7-723006: WebVPN Citrix SOCKS errors.

  • %ASA-7-723007: WebVPN Citrix ICA connection connection

  • %ASA-7-723008: WebVPN Citrix ICA SOCKS Server server

  • %ASA-7-723009: Group group-nameuser-nameIP_addressconnection

  • %ASA-7-723010: Group group-nameuser-nameIP_addresschannel

  • %ASA-7-723011: Group group-nameuser-nameIP_addresssocksexp-msg-length

  • %ASA-7-723012: Group group-nameuser-nameIP_addresssocks

  • %ASA-7-723013: WebVPN Citrix encountered invalid connection connection

  • %ASA-7-723014: Group group-nameuser-nameIP_addressconnectionserverchannel

  • %ASA-7-725008: SSL client peer-typeinterfacesrc-ipsrc-portdst-ipdst-port

  • %ASA-7-725009: Device proposes the following n cipher(s) peer-type interface:src-ip/src-port to dst-ip/dst-port.

  • %ASA-7-725010: Device supports the following n

  • %ASA-7-725011: Cipher[order]: cipher_name

  • %ASA-7-725012: Device chooses cipher cipherpeer-typeinterfacesrc-ipsrc-portdst-ip

  • %ASA-7-725013: SSL peer-type interface:src-ip/src-port to dst-ip/dst-port chooses cipher cipher

  • %ASA-7-725014: SSL lib error. Function: function Reason: reason

  • %ASA-7-725017: No certificates received during the handshake with ssBdBds

  • %ASA-7-725021: Device preferring cipher-suiteinterfacesrc-ipsrc-portdst-ipdst-port

  • %ASA-7-725022: Device skipping cipher: cipherreasoninterfacesrc-ipsrc-portdst-ipdst-port

  • %ASA-7-730001: Group groupname, User username, IP ipaddr: VLAN MAPPING to VLAN vlanid

  • %ASA-7-730003: IP ipaddrvlanid

  • %ASA-7-730006: Group groupname, User username, IP ipaddr: is on NACApp AUTH VLAN vlanid.

  • %ASA-7-730007: Group groupnameusernameipaddrvlanvlanid

  • %ASA-7-730010: Group groupnameusername,ipaddrvlanid

  • %ASA-7-734003: DAP: User nameipaddrattr name/value

  • %ASA-7-737001: IPAA: Session=sessionmessage-type

  • %ASA-7-737035: IPAA: Session=session'message type'

  • %ASA-7-746012: user-identity: Add IP-User mapping ip addressdomain_nameuser_nameresultreason

  • %ASA-7-746013: user-identity: Delete IP-User mapping ip addressdomain_nameusernameresultreason

  • %ASA-7-747005: Clustering: State machine notify event event-name (event-id, ptr-in-hex, ptr-in-hex)

  • %ASA-7-747006: Clustering: State machine is at state state-name

  • %ASA-7-737200: VPNFIP: Pool=poolip-address

  • %ASA-7-737201: VPNFIP: Pool=poolip-addressrecycle

  • %ASA-7-737206: VPNFIP: Pool=poolmessage

  • %ASA-7-737400: POOLIP: Pool=poolip-address

  • %ASA-7-737401: POOLIP: Pool=poolip-addressrecycle

  • %ASA-7-737407: POOLIP: Pool=poolmessage

  • %ASA-7-750016: Local: localIP:port Remote:remoteIP:port Username:username Need to send a DPD message to peer

  • %ASA-7-751003: Need to send a DPD message to peer

  • %ASA-7-752002: Tunnel Manager Removed entry. Map Tag = mapTag . Map Sequence Number = mapSeq .

  • %ASA-7-752008: Duplicate entry already in Tunnel Manager

  • %ASA-7-776012: CTS SXP: timer name timer started for connection with peer peer IP.

  • %ASA-7-776013: CTS SXP: timer name timer stopped for connection with peer peer IP.

  • %ASA-7-776014: CTS SXP: SXP received binding forwarding request (action) binding binding IP - SGname(SGT).

  • %ASA-7-776015: CTS SXP: Binding binding IP - SGname(SGT) is forwarded to peer peer IP (instance connection instance num).

  • %ASA-7-776016: CTS SXP: Binding binding IP - SGName(SGT) from peer peer IP (instance binding's connection instance num) changed from old instance: old instance num, old sgt: old SGName(SGT).

  • %ASA-7-776017: CTS SXP: Binding binding IP - SGname(SGT) from peer peer IP (instance connection instance num) deleted in SXP database.

  • %ASA-7-776018: CTS SXP: Binding binding IP - SGname(SGT) from peer peer IP (instance connection instance num) added in SXP database.

  • %ASA-7-776019: CTS SXP: Binding binding IP - SGname(SGT) action taken. Update binding manager.

  • %ASA-7-776301: CTS Policy: Security-group tag sgtsgname

  • %ASA-7-776302: CTS Policy: Unknown security-group tag sgt

  • %ASA-7-776307: CTS Policy: Security-group name for security-group tag sgtold_sgnamenew_sgname

  • %ASA-7-776308: CTS Policy: Previously unknown security-group tag sgtsgname

  • %ASA-7-785001: Clustering: Ownership for existing flow from in_interface:src_ip_addr/src_port to out_interface:dest_ip_addr/dest_port moved from unit old-owner-unit-id at site old-site-id to unit new-owner-unit-id at site old-site-id due to reason

  • %ASA-7-815004: OGS: Packet protocol from source IP address/port to destination IP address/port matched number of source network objects source network objects and number of source network objects destination network objects total search entries total number of entries. Resultant key-set has number of entries entries

Variables Used in Syslog Messages

Syslog messages often include variables. The following table lists most variables that are used in this guide to describe syslog messages. Some variables that appear in only one syslog message are not listed.

Variable Fields in Syslog Messages

Variable

Description

acl_ID

An ACL name.

bytes

The number of bytes.

code

A decimal number returned by the syslog message to indicate the cause or source of the error, according to the syslog message generated.

command

A command name.

command_modifier

The command_modifier is one of the following strings:

  • cmd (this string means the command has no modifier)
  • clear
  • no
  • show

connections

The number of connections.

connection_type

The connection type:

  • SIGNALLING UDP
  • SIGNALLING TCP
  • SUBSCRIBE UDP
  • SUBSCRIBE TCP
  • Via UDP
  • Route
  • RTP
  • RTCP

dec

Decimal number.

dest_address

The destination address of a packet.

dest_port

The destination port number.

device

The memory storage device. For example, the floppy disk, internal flash memory, TFTP, the failover standby unit, or the console terminal.

econns

Number of embryonic connections.

elimit

Number of embryonic connections specified in the static or nat command.

filename

A filename of the type ASAimage, ASDM file, or configuration.

ftp-server

External FTP server name or IP address.

gateway_address

The network gateway IP address.

global_address

Global IP address, an address on a lower security level interface.

global_port

The global port number.

hex

Hexadecimal number.

inside_address

Inside (or local) IP address, an address on a higher security level interface.

inside_port

The inside port number.

interface_name

The name of the interface.

IP_address

IP address in the form n n n n , where n is an integer from 1 to 255.

MAC_address

The MAC address.

mapped_address

The translated IP address.

mapped_port

The translated port number.

message_class

Category of syslog message associated with a functional area of the ASA.

message_list

Name of a file you create containing a list of syslog message ID numbers, classes, or severity levels.

message_number

The syslog message ID.

nconns

Number of connections permitted for the static or xlate table.

netmask

The subnet mask.

number

A number. The exact form depends on the syslog message.

octal

Octal number.

outside_address

Outside (or foreign) IP address, an address of a syslog server typically on a lower security level interface in a network beyond the outside router.

outside_port

The outside port number.

port

The TCP or UDP port number.

privilege_level

The user privilege level.

protocol

The protocol of the packet, for example, ICMP, TCP, or UDP.

real_address

The real IP address, before NAT.

real_port

The real port number, before NAT.

reason

A text string describing the reason for the syslog message.

service

The service specified by the packet, for example, SNMP or Telnet.

severity_level

The severity level of a syslog message.

source_address

The source address of a packet.

source_port

The source port number.

string

Text string (for example, a username).

tcp_flags

Flags in the TCP header such as:

  • ACK
  • FIN
  • PSH
  • RST
  • SYN
  • URG

time

Duration, in the format hh mm ss

url

A URL.

user

A username.