The following article provides an overview on all operational events that are processed by the Barracuda NG Firewall.
Event-ID | Description | Relevance | Severity | Notification | Persistent |
---|---|---|---|---|---|
10 | Disk Space Low | On at least one partition between 70 and 90 % of available disk space are in use. Disk usage is graphically depicted in the Control > System tab. Low disk space is characterized by a yellow status bar. | Warning | 1 | yes |
11 | Disk Space Critical | On at least one partition more than 90 % of available disk space are in use. Disk usage is graphically depicted in the Control > System tab. Critical disk space is characterized by a red status bar. | Error | 1 | yes |
20 | Memory Low | At least 70 or up to 90 % of available memory are in use. Memory usage is graphically depicted in the Control > System tab. Low memory availability is characterized by a yellow status bar. | Warning | 1 | yes |
21 | Memory Critical | More than 90 % of available memory are in use. Memory usage is graphically depicted in the Control > System tab. Critical memory availability is characterized by a red status bar. | Error | 1 | yes |
30 | High System Load | The "Warning" Load Warnings have been exceeded. Thresholds may be configured in Config > Box > Infrastructure Services > Control > CPU-LOAD Monitoring section. | Warning | 1 | yes |
31 | Excessive System Load | The "Critical" Load Warnings have been exceeded. Thresholds may be configured in Config > Box > Infrastructure Services > Control > CPU-LOAD Monitoring section. | Error | 1 | yes |
34 | Critical System Condition | The Watchdog repair binary could not be executed flawlessly (see: Watchdog; parameter Run S.M.A.R.T). | Error | 1 | yes |
48 | Device Mismatch | See description. | Error | 1 | no |
49 | Device Activation Failed | A network interface could not be activated. | Error | 1 | no |
50 | Device Down | A network interface has been disabled. | Error | 1 | yes |
51 | IP Address Added | The control daemon has added a server IP to the network configuration (for example after manual configuration changes, enabling a server, …). | Information | 1 | no |
52 | IP Address Removed | The control daemon has removed a hitherto existing server IP address from the network configuration (for example after manual configuration changes, blocking or disabling a server, …). | Information | 1 | no |
54 | IP Property Change Failed | Not available. | Error | 1 | no |
55 | Assigned IP Address Changed | An IP address, which has been assigned to the system by an DHCP server has changed. | Information | 1 | no |
56 | Duplicate DHCP IP | A DHCP server assigned IP address living on the system has additionally been detected in the network. | Warning | 1 | no |
57 | Dyn DNS Update Succeeded | Update of a configured DynDNS account (for example DHCP network or ISDN network configuration) has succeeded/failed. | Information | 1 | no |
58 | Dyn DNS Update Failed | Warning | 1 | no | |
60 | Route Added | A route has been added to the active network configuration, for example because an xDLS connection has been activated or a gateway has become available. | Information | 1 | no |
61 | Route Deleted | A route has been deleted from the system, for example because a gateway has become unavailable. | Information | 1 | no |
62 | Route Changed | The state or a parameter of a route has changed. | Information | 1 | no |
63 | Route Enabled | A route has been activated, because for example a server IP has been added to the configuration. | Information | 1 | no |
64 | Route Disabled | A route has been disabled, because for example a server IP has been deleted from the configuration. | Information | 1 | no |
65 | Route Reactivated | See also Event-ID 66 Route Deactivated. A gateway route has been reactivated because the initial state has been restored. | Information | 1 | no |
66 | Route Deactivated | A gateway route has been deactivated because a former gateway IP has become a local IP on a Barracuda NG Firewall system. This event might occur on secondary HA boxes, when the server IP of the primary box (former gateway IP for the secondary box) changes to the secondary box after HA takeover. | Information | 1 | no |
70 | Flash RAM auto detection | The Storage Architecture option available in the Box Configuration file might have been misconfigured. | Error | 1 | no |
90 | Module Error | See description. | Error | 1 | no |
100 | Missing Configuration File | A server or service configuration file cannot be retrieved, that means it might have been deleted. | Error | 1 | no |
110 | Missing Sysctrl | Not available. | Error | 1 | yes |
120 | Missing Executable | A binary needed at start-up could not be found (for example for setting parameters, …). | Error | 1 | yes |
131 | Resource Missing | A resource needed for full system functionality is missing, for example a configured network interface is not available. | Error | 1 | no |
135 | Resource Limit Pending | Less than 50 % of maximum command value remain (see: - Successive Command Maximum). | Warning | 1 | yes |
136 | Resource Limit Exceeded |
| Warning | 1 | yes |
150 | Corrupted Data File | The utility dstats has identified a corrupt data file (see: - Statistics). | Error | 1 | no |
400 | Time Discontinuity Detected | The statistics daemon has detected a time shift, that means a deviation from former time settings (for example date/time settings have been changed manually, hardware clock settings are wrong after reboot). | Warning | 1 | no |
500 | Invalid License | The license that is installed on the system is invalid, for example the Hardware ID of the system does not match with the ID the license has been issued for or the validity period has been exceeded. | Error | 1 | yes |
501 | No License Found | See description. | Error | 1 | yes |
505 | License Limit Exceeded | The license limit of IPs protected by the firewall has been exceeded | Error | 1 | no |
510 | Invalid Argument | The Watchdog repair binary could not be executed flawlessly (see: Watchdog). | Error | 1 | no |
600 | HA Partner Unreachable | Connectivity between a Barracuda NG Firewall and its high availability partner is disrupted. | Error | 1 | yes |
610 | Reporter SSH Host Key Mismatch | The Management Reporter SSH host key does not match. | Error | 1 | yes |
620 | Box Unreachable | Connectivity between CC and one of its administered boxes is disrupted. This event is only generated on the CC. | Warning | 1 | yes |
622 | Box Reachable Again | Connectivity between CC and one of its administered boxes has been restored. This event is only generated on the CC. | Information | 1 | no |
666 | Process Core Found | The core-search utility has found a core dump of a Barracuda NG Firewall process and has moved it to /var/phion/crash. | Warning | 1 | no |
700 | SIM Card Handling | See description. | Error | 1 | yes |
701 | SIM Card Handling | See description. | Warning | 1 | yes |
702 | 3G Network Registration | This event occurs if the Barracuda M10 modem dialed in successfully into a GSM network. | Warniing | 1 | yes |
703 | 3G Network Registration | See description. | Error | 1 | yes |
704 | Signal Strength | See description. | Warning | 1 | yes |
710 | SMS Handling | See description. | Error | 1 | yes |
711 | SMS Handling | See description. | Warning | 1 | yes |
721 | SMS Handling | See description. | Information | 1 | yes |
2000 | Start Server | A server has been started either by the system or manually. | Information | 1 | no |
2001 | Start Service | A service has been started either by the system or manually. | Information | 1 | no |
2002 | Start Box Service | A box-service has been started either by the system or manually. | Information | 1 | no |
2010 | Stop Server | A server has been stopped either by the system or manually. | Information | 1 | no |
2011 | Stop Service | A service has been stopped either by the system or manually. | Information | 1 | no |
2012 | Stop Box Service | A box-service has been stopped either by the system or manually. | Information | 1 | no |
2020 | Restart Server | A server has been restarted either by the system or manually. | Information | 1 | no |
2021 | Restart Service | A service has been restarted either by the system or manually. | Information | 1 | no |
2022 | Restart Box Service | A box-service has been restarted either by the system or manually. | Information | 1 | no |
2030 | Block Server | A server has been blocked manually. | Warning | 1 | no |
2031 | Block Service | A service has been blocked manually. | Warning | 1 | no |
2032 | Block Box Service | A box-service has been blocked manually. | Warning | 1 | no |
2040 | Deactivate Server | See description. | Warning | 1 | no |
2041 | Deactivate Service | See description. | Warning | 1 | no |
2042 | Deactivate Box Service | See description. | Warning | 1 | no |
2044 | No Valid License for Service | See description. | Warning | 1 | yes |
2045 | Entering GRACE Mode | A system with a formerly valid license has changed into grace mode, either because the host-key the license has been issued for does not match with the system’s host key or because the CC-administered box could not validate its license with the CC. | Warning | 1 | no |
2046 | Entering DEMO Mode | The system has been installed without importing a valid license or a valid box license has been removed from it. | Error | 1 | no |
2047 | GRACE Mode Expired | Grace mode has expired. | Error | 1 | no |
2050 | Reactivate Server | See description. | Warning | 1 | no |
2051 | Reactivate Service | See description. | Warning | 1 | no |
2052 | Reactivate Box Service | See description. | Warning | 1 | no |
2054 | Subprocess Kill Requested | A sub-process has been killed manually. | Information | 1 | no |
2056 | Connection Kill Requested | See description. | Information | 1 | no |
2058 | Session Kill Requested | See description. | Information | 1 | no |
2060 | Emergency Server Start | A server has started because the HA partner is not available. | Warning | 1 | no |
2061 | Emergency Server Stop | A server has stopped because the HA partner server is in state active. | Warning | 1 | no |
2070 | Daemon Startup Failed | A daemon’s startup/shutdown has failed/succeeded. The daemon responsible for the event will be included in the event message. Eventing notifications may be configured per daemon (for example NTPd - see: ). They will only be generated for controlled startup/shutdown sequences and not for manual process terminations. | Warning | 1 | no |
2071 | Daemon Startup Succeeded | Information | 1 | no | |
2072 | Daemon Shutdown Failed | Information | 1 | no | |
2073 | Daemon Shutdown Succeeded | Information | 1 | no | |
2080 | Time Synchronization Failed | NTP sync with the configured NTP server has failed. NTP synchronization settings are defined in Config > Box > Settings > TIME/NTP tab. | Warning | 1 | no |
2081 | Time Synchronization | NTP sync with the configured NTP server has succeeded. NTP synchronization settings are defined in Config > Box > Settings > TIME/NTP tab. | Information | 1 | no |
2082 | Time Synchronization Denied | NTP sync with the configured NTP server has been denied. NTP synchronization settings are defined in Config > Box > Settings > TIME/NTP tab. | Error | 1 | no |
2102 | Network Restart Requested | A network restart has been triggered manually using Barracuda NG Admin. | Information | 1 | no |
2103 | Activate New Network | A new network configuration has been activated manually using Barracuda NG Admin. | Information | 1 | no |
2104 | NGFW Subsystem Start | The NGFW Subsystem (network and NGFW OS processes) has been started. | Information | 1 | no |
2105 | NGFW Subsystem Stop | The NGFW Subsystem (network and NGFW OS processes) has been stopped. | Information | 1 | no |
2120 | Mail DSN Message Sent | A DSN (Delivery Status Notification) message has been generated and sent by the mail gateway (for example due to undeliverable mail). Further DSN generation conditions are configurable in the Limits configuration section of the mail gateway (see: ). | Information | 1 | no |
2210 | Network Subsystem Restart | The network subsystem (routes, IP addresses, network interface drivers) has been restarted. | Information | 1 | no |
2212 | Unclean Network Subsystem | An error has occurred during network subsystem activation. | Warning | 1 | no |
2220 | Network Subsystem Shutdown | The network subsystem (routes, IP addresses, network interface drivers) has been shut down. | Information | 1 | no |
2222 | Unclean Network Subsystem | An error has occurred during network subsystem shutdown. | Information | 1 | no |
2230 | Network Subsystem Check | The network subsystem configuration has been checked for consistency. | Information | 1 | no |
2232 | Network Subsystem Check | The network subsystem configuration has been checked for consistency. | Information | 1 | no |
2234 | Network Subsystem Check Failed | An error has been discovered during network subsystem configuration check. | Warning | 1 | no |
2240 | Link Activation Failed | Activation of a dynamic link (for example xDSL, UMTS, DHCP) has failed. The reason for activation failure is provided in the event message. | Error | 1 | no |
2242 | Sublink Activation Failed | See description. | Error | 1 | no |
2250 | PCMCIA Bus Reset | Resetting the PCMCIA bus to recover from potential modem lockup by power cycling it. | Error | 1 | no |
2380 | Flawed Configuration Data | The rule file containing the domain settings of the mail gateway service is either missing or a corrupt rule file has been loaded. This event is only reported when parameter Bad Rulefile Loaded (see: ) is set to yes. | Error | 1 | no |
2500 | FW Forwarding Loop Suppressed | These events are triggered when the firewall engine delivers a local targeted session from the local firewall to the forwarding firewall (because of a non existing local listening socket) and in the forwarding firewall a rule matches that does not perform DNAT. | Information | 1 | yes |
2502 | FW Local Redirection Suppressed | Information | 1 | yes | |
2511 | FW Worker Limit Exceeded | See description. | Error | 1 | yes |
3000 | VPN Server Tunnel Terminated | The VPN peer IP address and/or gateway is unavailable or the VPN tunnel has been terminated manually. | Information | 1 | no |
3001 | VPN Alternative Tunnel Activated | A VPN alternative tunnel will be activated, when the active partner of the tunnel changes his Bind-IP address (for example provider failure). | Warning | 1 | no |
3002 | VPN Server Tunnel Activated | A VPN Site-to-Site tunnel has been activated. | Information | 1 | no |
3003 | activation of on- demand tunnel | A on-demand VPN Site-to-Site tunnel has been activated. | Notice | 1 | no |
3004 | deactivation of on-demand tunnel | A on-demand VPN Site-to-Site tunnel has been activated. | Notice | 1 | no |