ZyXEL Communications ZyWall USG 2000 User Manual page 845

Unified security gateway
Hide thumbs Also See for ZyWall USG 2000:
Table of Contents

Advertisement

Table 278 IPSec Logs (continued)
LOG MESSAGE
Get outbound transform
fail
Inbound transform
operation fail
Outbound transform
operation fail
Packet too big with
Fragment Off
SPI:0x%x SEQ:0x%x
Execute transform step
fail, ret=%d
SPI:0x%x SEQ:0x%x No
rule found, Dropping
packet
SPI:0x%x SEQ:0x%x
Packet Anti-Replay
detected
VPN connection %s was
disabled.
VPN connection %s was
enabled.
Due to active
connection allowed
exceeded, %s was
deleted.
Table 279 Firewall Logs
LOG MESSAGE
priority:%lu, from %s
to %s, service %s, %s
%s:%d: in %s():
Firewall has been %s.
Firewall rule %d has
been moved to %d.
Firewall rule %d has
been deleted.
Firewall rules have
been flushed.
Firewall rule %d was
%s.
ZyWALL USG 2000 User's Guide
DESCRIPTION
When outgoing packet need to be transformed, the engine
cannot obtain the transform context.
After encryption or hardware accelerated processing, the
hardware accelerator dropped a packet (resource shortage,
corrupt packet, invalid MAC, and so on).
After encryption or hardware accelerated processing, the
hardware accelerator dropped a packet (e.g., resource
overflow, corrupt packet, and so on).
An outgoing packet needed to be transformed, but the
fragment flag was off and the packet was too big.
The variables represent the SPI, sequence number and the
error number. When trying to perform transforming, the
engine returned an error.
The variables represent the SPI and the sequence number.
The packet did not match the tunnel policy and was dropped.
The variables represent the SPI and the sequence number.
The device received a packet again (that it had already
received).
%s is the VPN connection name. An administrator disabled the
VPN connection.
%s is the VPN connection name. An administrator enabled the
VPN connection.
%s is the VPN connection name. The number of active
connections exceeded the maximum allowed.
DESCRIPTION
1st variable is the global index of rule, 2nd is the from zone,
3rd is the to zone, 4th is the service name, 5th is ACCEPT/
DROP/REJECT.
Firewall is dead, trace to %s is which file, %d is which line,
%s is which function
%s is enabled/disabled
1st %d is the old global index of rule, 2nd %d is the new
global index of rule
%d is the global index of rule
Firewall rules were flushed
%d is the global index of rule, %s is appended/inserted/
modified
Appendix A Log Descriptions
845

Advertisement

Table of Contents
loading

This manual is also suitable for:

Zywall usg 1000

Table of Contents