ScreenOS 5.3.0 Messages--Text Only P/N 093-1673-000, Rev. B Addresses Notification (00054) Address for { ip address } in zone has been { added | deleted | modified } Address group has been { added | deleted | modified } Address group has { added | deleted } member Address for ip address in zone { add | delete | modify } Alarm (00054) SCAN-MGR: Cannot get { AltServer info | Version number | Path_GateLockCE info } from server.ini file. Admin Alert (00027) ScreenOS .. Serial# : Asset recovery performed ScreenOS .. Serial # : Asset recovery has been aborted System configuration has been erased Critical (00027) Multiple login failures occurred for user from IP address : Multiple login failures occurred for user Warning (00002) Admin AUTH: Local instance of an external admin user’s privilege has been changed from to Warning (00515) Vsys admin user has logged { on | out } via { Telnet from : | SSH from : } Vsys admin user has logged { on | out } via the console Admin user has logged { on | out } via { Telnet from : | SSH from : } Admin user has logged { on | out } via the console Management session via { serial console | Telnet from : | SSH from : } for [ vsys ] admin has timed out Login attempt to system by admin via { the console | Telnet from : | SSH from : } has failed Admin user has been forced to log out of the serial console session. Admin user has been forced to log out of the SSH session on host : Admin user has been forced to log out of the Telnet session on host : Admin user has been forced to log out of the Web session on host : Remotely authenticated Admin demoted from ROOT privilege to RW privilege. Remotely authenticated Admin demoted from privilege to privilege. Warning (00518) Admin user has been rejected via the server at Warning (00519) Admin user has been accepted via the server at Notification (00002) Root admin access restriction through console only has been { enabled | disabled } by admin Single use password restriction for read-write administrators has been { disabled | enabled } by admin Root admin password restriction of minimum characters has been { enabled | disabled } by admin Maximum failed login attempts from before administrative session disconnects has been modified from to by admin Admin user “” logged in for Web ({ http | https }) management (port ) from :. Admin user “” login attempt for Web ({ http | https }) management (port ) from : failed. Admin user “” login attempt for Web ({ http | https }) management (port ) from : failed due to an incorrect client ID. Admin user “” logged out for Web ({ http | https }) management (port ) from :. Notification (00003) The console timeout value changed from to minutes The console page size changed from to The serial console has been { enabled | disabled } by admin The console debug buffer has been {enabled | disabled } Information (00002) Admin name for account has been modified to Admin password for account has been modified Admin account created for Admin account deleted for Admin account modified for Management restriction for subnet has been { added | removed } Management restriction was removed from all IPs and subnets System IP has been changed from to { SSH | Telnet | HTTP } port has been changed from to Web admin authentication idle timeout value has been changed from to minutes ADSL Notification (00555) ADSL Line UP Fast and Interleave Channels. ADSL Line Waiting for Activating. ADSL Line Activating. ADSL Line Down. ADSL Line UP Fast Channel. ADSL Line UP Interleaved Channel. ADSL Line UP Fast Channel, change Utopia address to match it. ADSL Line UP Interleaved Channel, change Utopia address to match it. ADSL Line in an unknown state. ADSL line signal lost detected. Adsl line suicide request received. ADSL line closed. ADSL line opened ( time ). ADSL line failed ( incompatible line conditions). ADSL line failed ( protocol error). ADSL line failed ( Error Message received from ATU-C). ADSL line failed ( spurious ATU detected). ADSL line failed ( forced silence). ADSL line failed ( unselectable operation mode). ADSL line open failed (unknown error code). ADSL line open rejected. Antivirus Critical (00554) SCAN-MGR: Check AV pattern file failed with error code: SCAN-MGR: Cannot write AV pattern file to flash. SCAN-MGR: Cannot retrieve AV pattern file from :. HTTP status code: Error (00554) SCAN-MGR: Cannot get { AltServer info | Version number | Path_GateLockCE info } from server.ini file. SCAN-MGR: Per server.ini file, the AV pattern file size is zero. SCAN-MGR: AV pattern file size is too large ( bytes). SCAN-MGR: Alternate AV pattern file server URL is too long: bytes. Max: bytes. SCAN-MGR: Cannot retrieve { server.ini | AV pattern } file from :. HTTP status code: . SCAN-MGR: Cannot write AV pattern file to { RAM | flash }. SCAN-MGR: Cannot check AV pattern file. VSAPI code: SCAN-MGR: Internal error occurred while retrieving { server.ini | AV pattern } file. SCAN-MGR: Internal error occurred when calling this function: . [ Layer: . | Limit: . | Returned: ] { Error: | Returned a NULL VSC handler | cpapiErrCode: }. SCAN-MGR: TmIntSetScanMethod failed. Scan Method: Err: . Error (00054) APPPRY: Suspicious client :->: used percent of AV resources, which exceeded the max of percent. Warning (00547) AV scan-mgr has been { attached to | detached from } policy ID AV: VIRUS FOUND: :->:, AV: Content from :->: was not scanned because max content size was exceeded. AV: Content from :->: was not scanned because max content size was exceeded. AV: Content from :->: was not scanned due to a scan engine error or constraint. AV object scan-mgr has been disabled. AV object scan-mgr timeout has been reset to its default value. Warning (00566) SMTP relay from () ->() fails with response code . APP session () ->() is aborted due to with code . Notification (00554) SCAN-MGR: URL for AV pattern update server has been set to , and the update interval to minutes. SCAN-MGR: URL for AV pattern update server has been unset, and the update interval returned to its default. SCAN-MGR: New AV pattern file has been updated. Version: ; size: bytes. SCAN-MGR: New AV pattern file has been updated. Version: ; size: bytes. SCAN-MGR: Attempted to load AV pattern file created after the AV subscription expired. (Exp: date:time2>) SCAN-MGR: Notification (00066) AV maximum content size has been set to KB. AV maximum number of concurrent messages has been set to . AV fail mode has been set to {drop | pass} unexamined traffic if content size exceeds max. AV fail mode has been set to unexamined traffic if any error occurs. AV per client allowed resource has been set to percent. AV HTTP turn http connection header close modification. AV HTTP turn http webmail scanning. AV HTTP set webmail pattern . AV HTTP unset webmail pattern . AV HTTP turn off http trickling setting. AV HTTP trickling setting to be trickling byte for every Mb if content length is larger than MB. AV has been {attached | detached} to policy ID AV {sets | removes} ext list with file extensions . AV {sets | removes} MIME list with MIME extensions . AV {sets | removes} a profile . AV profile {set | unset} protocol AV queue size is set to . Notification (00547) AV object scan-mgr has been enabled [ with timeout ]. Notification (00554) SCAN-MGR: Number of decompression layers has been set to . SCAN-MGR: Maximum content size has been set to KB. SCAN-MGR: Maximum number of concurrent messages has been set to . SCAN-MGR: Fail mode has been set to { drop | pass } unexamined traffic if { content size | number of concurrent messages } exceeds max. SCAN-MGR: AV pattern file has been set not to load upon bootup. SCAN-MGR: IP address for dump TFTP server has been set to . SCAN-MGR: URL for AV pattern update server has been set to , and the update interval to minutes. SCAN-MGR: URL for AV pattern update server has been unset, and the update interval returned to its default. SCAN-MGR: New AV pattern file has been updated. Version: ; size: bytes. SCAN-MGR: AV client has exceeded its resource allotment. Remaining available resources: . SCAN-MGR: Attempted to load AV pattern file created after the AV subscription expired. (Exp: ) SCAN-MGR: ARP Critical (00031) { arp req | arp reply } detected an IP conflict (IP , MAC ) on interface Critical (00079) { arp req | arp reply } detected a duplicate VSD group master (IP , MAC ) on interface Notification (00031) ARP detected IP conflict: IP address changed from interface to interface Notification (00051) Static ARP entry { added to | deleted from } interface with IP and MAC Notification (00053) ARP always on destination enabled Notification (00054) ARP always on destination disabled Attack Database Notification (00767) Attack database version has been [ authenticated and ] saved to flash. Cannot parse attack database [ header info ] Cannot switch to attack database version Cannot save attack database version Cannot download attack database from (error ) Deep Inspection update key has expired. Attack database version was rejected because the authentication check failed. Attack was {created|deleted|changed to} . Attack was {added | deleted} to attack group . Attack group was {created | deleted } . Attack group was changed to . Attack group was {added | removed} {to | from} attack group . Attacks Emergency (00005) SYN flood! From : to :, proto TCP (zone , int ). Occurred times. Emergency (00006) Teardrop attack! From : to :, proto { TCP | UDP | } (zone , int ). Occurred times. Emergency (00007) Ping of Death! From to , proto 1 (zone , int ). Occurred times. Alert (00004) WinNuke attack! From : to :139, proto TCP (zone , int ). Occurred times. Alert (00008) IP spoofing! From : to :, proto { TCP | UDP | } (zone , int ). Occurred times. Alert (00009) Source Route IP option! From : to :, proto { TCP | UDP | } (zone , int ). Occurred times. Alert (00010) Land attack! From : to :, proto TCP (zone , int ). Occurred times. Alert (00011) ICMP flood! From to , proto 1 (zone , int ). Occurred times. Alert (00012) UDP flood! From : to :, proto UDP (zone , int ). Occurred times. Alert (00016) Port scan! From : to :, proto { TCP | UDP | } (zone , int ). Occurred times. Alert (00017) Address sweep! From to , proto 1 (zone , int ). Occurred times. Critical (00032) Malicious URL! From : to :, proto TCP (zone , int ). Occurred times. Critical (00033) Src IP session limit! From : to :, proto { TCP | UDP | } (zone , int ). Occurred times. Critical (00412) SYN fragment! From : to :, proto TCP (zone , int ). Occurred times. Critical (00413) No TCP flag! From : to :, proto { TCP | UDP | } (zone , int ). Occurred times. Critical (00414) Unknown protocol! From : to :, proto (zone , int ). Occurred times. Critical (00415) Bad IP option! From : to :, proto { TCP | UDP | } (zone , int ). Occurred times. Critical (00430) Dst IP session limit! From : to :, proto { TCP | UDP | } (zone , int ). Occurred times. Critical (00431) ZIP file blocked! From : to :, proto { TCP | UDP | } (zone , int ). Occurred times. Critical (00432) Java applet blocked! From : to :, proto { TCP | UDP | } (zone , int ). Occurred times. Critical (00433) EXE file blocked! From : to :, proto { TCP | UDP | } (zone , int ). Occurred times. Critical (00434) ActiveX control blocked! From : to :, proto { TCP | UDP | } (zone , int ). Occurred times. Critical (00435) ICMP fragment! From to , proto 1 (zone , int ). Occurred times. Critical (00436) Large ICMP packet! From to , proto 1 (zone , int ). Occurred times. Critical (00437) SYN and FIN bits! From : to :, proto TCP (zone , int ). Occurred times. Critical (00438) FIN but no ACK bit! From : to :, proto TCP (zone , int ). Occurred times. Critical (00439) SYN-ACK-ACK Proxy DoS! From : to :, proto TCP (zone , int ). Occurred times. Critical (00440) Fragmented traffic! From : to :, proto { TCP | UDP | } (zone , int ). Occurred times. Critical, Error, Warning, Notification, Information (00601) attack! From : to :, proto { TCP | UDP }, through policy . Occurred times. Notification (00002) has been { enabled | disabled } on zone has been set to for zone Malicious URL has been { added | deleted | modified } for zone { Bypass-others-IPSec | Bypass non-IP traffic } option has been { enabled | disabled } Logging of { dropped | IKE | SNMP | ICMP } traffic to self has been { enabled | disabled } Logging of dropped traffic to self (excluding multicast) has been { enabled | disabled } on Notification (00767) Attack was { created | deleted } Attack was changed to Attack [ group ] was { added to | removed from } Attack group was { created | deleted } Attack group was changed to Auth Warning (00518) Authentication for user was denied, (long username) Authentication for user was denied, (long password) User at has been rejected via the {RADIUS | SecurID | LDAP | Local } server at User at {RADIUS | SecurID | LDAP | Local } authentication attempt has timed out User at has been challenged via the {RADIUS | SecurID | LDAP | Local } server at (Rejected since challenge is not supported for Web) User at has been challenged via the {RADIUS | SecurID | LDAP | Local } server at (Rejected since challenge is not supported for FTP) WebAuth user at has been rejected/timed out via the {RADIUS | SecurID | LDAP | Local } server at Local authentication for WebAuth user was denied Error in authentication for WebAuth user Local authentication for user was denied Warning (00519) WebAuth user at has been accepted via the {RADIUS | SecurID | LDAP | Local } server at User at has been accepted via the {RADIUS | SecurID | LDAP | Local} server at Local authentication for WebAuth user was successful Local authentication for user was successful Warning (00520) Trying primary server Trying backup1 server Trying backup2 server Backup1 , backup2 , and primary servers failed Backup2 , primary , and backup1 servers failed Primary , backup1 , and backup2 servers failed Notification (00015) WebAuth is set to Auth server server name has been unset Host name for Infranet Controller changed from to . Infranet Enforcer has connected to Infranet Controller (ip ). Auth server RADIUS secret has been unset Timeout for Infranet Controller changed from to seconds. Auth server RADIUS secret has been unset Auth server timeout has been unset to default Password for Infranet Controller changed. Infranet Enforcer did not receive a keepalive from the Infranet Controller(ip_addr) in the past seconds. Cleaning up internal state. Auth server RADIUS port has been unset to default Source interface for Infranet Controller changed from to . Infranet Enforcer could not connect to the Infranet Controller because no IP address is set for the Controller. Auth server type has been set to {RADIUS | SecurID | LDAP} Certificate Authority index for Infranet Controller changed. Infranet Enforcer could not connect to the Infranet Controller because a socket is already connected. Certificate subject for Infranet Controller changed from to . Infranet Enforcer could not connect to the Infranet Controller because no password is set for the Controller. Infranet Controller was deleted. Infranet Enforcer could not connect to the Infranet Controller because no certificate is set for the Controller. Auth server server name has been set to Infranet Controller was created. Infranet Enforcer could not connect to the Infranet Controller because a socket could not be created. Auth server RADIUS secret has been changed Port number for Infranet Controller changed from to . Infranet Enforcer could not connect to the Infranet Controller because the interface could not be bound to the socket. Auth server SecurID server name has been set to IP address for Infranet Controller changed from to . Infranet Enforcer could not connect to the Infranet Controller because the socket could not be bound. Auth server SecurID auth port has been set to Contact interval for Infranet settings changed from to seconds. Contact interval for Infranet settings changed from to seconds. Infranet Enforcer could not connect to the Infranet Controller because the socket could not be bound to SSL protocol. Timeout action for Infranet settings changed from to . Infranet Enforcer could not connect to the Infranet Controller because the Controller could not be reached on the network. Auth server SecurID use duress has been { enabled | disabled } Auth server SecurID timeout has been set to Auth server SecurID client retries has been set to Auth server SecurID backup1 server name has been set to Auth server authentication timeout has been set to Auth server LDAP parameters have been set to server name: , port: , dn:, cn: Auth server RADIUS port has been set to Auth server has been { created | modified } Auth server type has been unset to default RADIUS Auth server backup1 name has been unset Auth server backup2 name has been unset Auth server account type has been set to Auth server RADIUS retry timeout has been set to default of Auth server has been deleted Auth server LDAP dn has been set to Auth server LDAP cn has been set to Auth server LDAP port number has been set to Auth server backup1 server name has been set to Auth server backup2 server name has been set to Auth server id has been set to Default firewall authentication server has been changed to Admin user attempted to verify the encrypted password . Verification was successful. Admin user attempted to verify the encrypted password . Verification failed. Auth server username separator character has been set to , number of occurrences of separator character is Number of RADIUS retries for auth server has been set to Auth server fail-over revert interval has been set to seconds. Notification (00525) User at must enter “Next Code” for SecurID User at must enter “New PIN” for SecurID User at must make a “New PIN” choice for SecurID User at has selected a system-generated PIN for authentication with SecurID The new PIN for user at has been { accepted | rejected } by SecurID . Notification (00544) Access for firewall user at (accepted at