Appendix A Log Descriptions

Table 263 IPSec Logs (continued)

LOG MESSAGE

DESCRIPTION

Get outbound transform

When outgoing packet need to be transformed, the engine

fail

cannot obtain the transform context.

Inbound transform

After encryption or hardware accelerated processing, the

operation fail

hardware accelerator dropped a packet (resource shortage,

 

corrupt packet, invalid MAC, and so on).

 

 

Outbound transform

After encryption or hardware accelerated processing, the

operation fail

hardware accelerator dropped a packet (e.g., resource

 

overflow, corrupt packet, and so on).

 

 

Packet too big with

An outgoing packet needed to be transformed, but the

Fragment Off

fragment flag was off and the packet was too big.

SPI:0x%x SEQ:0x%x

The variables represent the SPI, sequence number and the

Execute transform step

error number. When trying to perform transforming, the

fail, ret=%d

engine returned an error.

SPI:0x%x SEQ:0x%x No

The variables represent the SPI and the sequence number.

rule found, Dropping

The packet did not match the tunnel policy and was dropped.

packet

 

SPI:0x%x SEQ:0x%x

The variables represent the SPI and the sequence number.

Packet Anti-Replay

The device received a packet again (that it had already

detected

received).

VPN connection %s was

%s is the VPN connection name. An administrator disabled the

disabled.

VPN connection.

VPN connection %s was

%s is the VPN connection name. An administrator enabled the

enabled.

VPN connection.

Due to active

%s is the VPN connection name. The number of active

connection allowed

connections exceeded the maximum allowed.

exceeded, %s was

 

deleted.

 

Table 264 Firewall Logs

LOG MESSAGE

DESCRIPTION

priority:%lu, from %s

1st variable is the global index of rule, 2nd is the from zone,

to %s, service %s, %s

3rd is the to zone, 4th is the service name, 5th is ACCEPT/

 

 

DROP/REJECT.

 

 

%s:%d: in %s():

Firewall is dead, trace to %s is which file, %d is which line,

 

%s is which function

 

 

Firewall has been %s.

%s is enabled/disabled

Firewall rule %d has

1st %d is the old global index of rule, 2nd %d is the new

been moved to %d.

global index of rule

Firewall rule %d has

%d is the global index of rule

been deleted.

 

Firewall rules have

Firewall rules were flushed

been flushed.

 

Firewall rule %d was

%d is the global index of rule, %s is appended/inserted/

%s.

modified

812

 

ZyWALL USG 50 User’s Guide