The following article provides an overview on all operational events that are processed by the Barracuda NG Firewall.
|10||Disk Space Low|
On at least one partition between 70 and 90 % of available disk space are in use. Disk usage is graphically depicted in the CONTROL > Resources tab. Low disk space is characterized by a yellow status bar.
|11||Disk Space Critical|
On at least one partition more than 90 % of available disk space are in use. Disk usage is graphically depicted in the CONTROL > Resources tab. Critical disk space is characterized by a red status bar.
At least 70 or up to 90 % of available memory are in use. Memory usage is graphically depicted in the CONTROL > Resources tab. Low memory availability is characterized by a yellow status bar.
More than 90 % of available memory are in use. Memory usage is graphically depicted in the CONTROL > Resources tab. Critical memory availability is characterized by a red status bar.
|30||High System Load|
The "Warning" Load Warnings have been exceeded. Thresholds may be configured in CONFIGURATION > Configuration Tree > Box > Infrastructure Services > Control > CPU-LOAD Monitoring section.
|31||Excessive System Load|
The "Critical" Load Warnings have been exceeded. Thresholds may be configured in CONFIGURATION > Configuration Tree > Box > Infrastructure Services > Control > CPU-LOAD Monitoring section.
|34||Critical System Condition|
The Watchdog repair binary could not be executed flawlessly (see: Watchdog; parameter Run S.M.A.R.T).
|49||Device Activation Failed||A network interface could not be activated.||Error||1||no|
|50||Device Down||A network interface has been disabled.||Error||1||yes|
|51||IP Address Added|
The control daemon has added a server IP to the network configuration (for example after manual configuration changes, enabling a server, …).
IP Address Removed
|The control daemon has removed a hitherto existing server IP address from the network configuration (for example after manual configuration changes, blocking or disabling a server, …).||Information||1||no|
|54||IP Property Change Failed||Not available.||Error||1||no|
Assigned IP Address Changed
An IP address, which has been assigned to the system by an DHCP server has changed.
|56||Duplicate DHCP IP|
An DHCP server assigned IP address living on the system has additionally been detected in the network.
|57||Dyn DNS Update Succeeded|
Update of a configured DynDNS account (for example DHCP network or ISDN network configuration) has succeeded/failed.
|58||Dyn DNS Update Failed||Warning||1||no|
A route has been added to the active network configuration, for example because an xDLS connection has been activated or a gateway has become available.
A route has been deleted from the system, for example because a gateway has become unavailable.
The state or a parameter of a route has changed.
A route has been activated, because for example a server IP has been added to the configuration.
A route has been disabled, because for example a server IP has been deleted from the configuration.
See also Event-ID 66 Route Deactivated. A gateway route has been reactivated because the initial state has been restored.
A gateway route has been deactivated because a former gateway IP has become a local IP on a Barracuda NG Firewall system. This event might occur on secondary HA boxes, when the server IP of the primary box (former gateway IP for the secondary box) changes to the secondary box after HA takeover.
Flash RAM auto detection
The Storage Architecture option available in the Box Configuration file might have been misconfigured.
Missing Configuration File
A server or service configuration file cannot be retrieved, that means it might have been deleted.
A binary needed at start-up could not be found (for example for setting parameters, …).
A resource needed for full system functionality is missing, for example a configured network interface is not available.
|135||Resource Limit Pending|
Less than 50 % of maximum command value remain (see: - Successive Command Maximum).
|136||Resource Limit Exceeded|
The number of concurrent connections allowed to connect to a service or a configured maximum limit has reached a critical value or has been exceeded (for example, see: - Parallel Connection Limit, Spooling Limit). The maximum command counter has been reached or has been exceeded (- Successive Command Maximum).
|150||Corrupted Data File|
The utility dstats has identified a corrupt data file (see: - Statistics).
|400||Time Discontinuity Detected|
The statistics daemon has detected a time shift, that means a deviation from former time settings (for example date/time settings have been changed manually, hardware clock settings are wrong after reboot).
The license that is installed on the system is invalid, for example the Hardware ID of the system does not match with the ID the license has been issued for or the validity period has been exceeded.
|501||No License Found||See description.|
|505||License Limit Exceeded|
The license limit of IPs protected by the firewall has been exceeded.
The Watchdog repair binary could not be executed flawlessly (see: Watchdog).
|600||HA Partner Unreachable|
Connectivity between a Barracuda NG Firewall and its high availability partner is disrupted.
|610||Reporter SSH Host Key Mismatch||The Management Reporter SSH host key does not match.||Error||1||yes|
Connectivity between CC and one of its administered boxes is disrupted. This event is only generated on the CC.
Box Reachable Again
Connectivity between CC and one of its administered boxes has been restored. This event is only generated on the CC.
Process Core Found
The core-search utility has found a core dump of a Barracuda NG Firewall process and has moved it to /var/phion/crash.
|700||SIM Card Handling||See description.||Error||1||yes|
|701||SIM Card Handling||See description.||Warning||1||yes|
|702||3G Network Registration||This event occurs if the Barracuda M10 modem dialed in successfully into a GSM network.||Warniing||1||yes|
|703||3G Network Registration||See description.||Error||1||yes|
|704||Signal Strength||See description.||Warning||1||yes|
|710||SMS Handling||See description.||Error||1||yes|
|711||SMS Handling||See description.||Warning||1||yes|
|721||SMS Handling||See description.||Information||1||yes|
|2000||Start Server||A server has been started either by the system or manually.||Information||4||no|
|2001||Start Service||A service has been started either by the system or manually.||Information||4||no|
|2002||Start Box Service||A box-service has been started either by the system or manually.||Information||4||no|
|2010||Stop Server||A server has been stopped either by the system or manually.||Information||4||no|
|2011||Stop Service||A service has been stopped either by the system or manually.||Information||4||no|
|2012||Stop Box Service||A box-service has been stopped either by the system or manually.||Information||4||no|
A server has been restarted either by the system or manually.
A service has been restarted either by the system or manually.
|2022||Restart Box Service|
A box-service has been restarted either by the system or manually.
A server has been blocked manually.
|2031||Block Service||A service has been blocked manually.||Information||4||no|
|2032||Block Box Service|
A box-service has been blocked manually.
|2040||Deactivate Server||See description.||Information||4||no|
Deactivate Box Service
No Valid License for Service
|2045||Entering GRACE Mode|
A system with a formerly valid license has changed into grace mode, either because the host-key the license has been issued for does not match with the system’s host key or because the CC-administered box could not validate its license with the CC.
|2046||Entering DEMO Mode||The system has been installed without importing a valid license or a valid box license has been removed from it.||Error||1||no|
|2047||GRACE Mode Expired||Grace mode has expired.||Error||1||no|
|2050||Reactivate Server||See description.||Information||4||no|
|2051||Reactivate Service||See description.||Information||4||no|
|2052||Reactivate Box Service||See description.||Information||4||no|
|2054||Subprocess Kill Requested||A sub-process has been killed manually.||Information||1||no|
|2056||Connection Kill Requested|
|2058||Session Kill Requested||See description.||Information||1||no|
|2060||Emergency Server Start|
A server has started because the HA partner is not available.
|2061||Emergency Server Stop|
A server has stopped because the HA partner server is in state active.
|2070||Daemon Startup Failed|
A daemon’s startup/shutdown has failed/succeeded. The daemon responsible for the event will be included in the event message. Eventing notifications may be configured per daemon (for example NTPd - see: ). They will only be generated for controlled startup/shutdown sequences and not for manual process terminations.
|2071||Daemon Startup Succeeded||Information||1||no|
|2072||Daemon Shutdown Failed||Information||1||no|
|2073||Daemon Shutdown Succeeded||Information||1||no|
Time Synchronization Failed
NTP sync with the configured NTP server has failed. NTP synchronization settings are defined in CONFIGURATION > Configuration Tree > Box > Administrative Settings > TIME Settings/NTP.
NTP sync with the configured NTP server has succeeded. NTP synchronization settings are defined in CONFIGURATION > Configuration Tree > Box > Administrative Settings > TIME Settings/NTP.
|2082||Time Synchronization Denied|
NTP sync with the configured NTP server has been denied. NTP synchronization settings are defined in CONFIGURATION > Configuration Tree > Box > Administrative Settings > TIME Settings/NTP.
A system reboot has been triggered manually at the physical console by pressing the keys CTRL-ALT-DEL simultaneously.
|2100||Reboot Requested||A system reboot has been triggered manually using Barracuda NG Admin.||Information||4||no|
|2101||System Halt Requested||A system shutdown has been triggered manually.||Information||4||no|
|2102||Network Restart Requested||A network restart has been triggered manually using Barracuda NG Admin.||Information||4||no|
Activate New Network
A new network configuration has been activated manually using Barracuda NG Admin.
NGFW Subsystem Start
|The NGFW Subsystem (network and NGFW OS processes) has been started.||Information||1||no|
|2105||NGFW Subsystem Stop|
The NGFW Subsystem (network and NGFW OS processes) has been stopped.
|2120||Mail DSN Message Sent|
A DSN (Delivery Status Notification) message has been generated and sent by the mail gateway (for example due to undeliverable mail). Further DSN generation conditions are configurable in the Limits configuration section of the mail gateway (see: ).
|2210||Network Subsystem Restart|
The network subsystem (routes, IP addresses, network interface drivers) has been restarted.
Unclean Network Subsystem
|An error has occurred during network subsystem activation.||Warning||1||no|
|2220||Network Subsystem Shutdown|
The network subsystem (routes, IP addresses, network interface drivers) has been shut down.
Unclean Network Subsystem
|An error has occurred during network subsystem shutdown.||Information||1||no|
Network Subsystem Check
|The network subsystem configuration has been checked for consistency.||Information||1||no|
|2232||Network Subsystem Check||The network subsystem configuration has been checked for consistency.||Information||1||no|
Network Subsystem Check Failed
An error has been discovered during network subsystem configuration check.
|2240||Link Activation Failed|
Activation of a dynamic link (for example xDSL, UMTS, DHCP) has failed. The reason for activation failure is provided in the event message.
|2242||Sublink Activation Failed||See description.||Error||1||no|
|2250||PCMCIA Bus Reset|
Resetting the PCMCIA bus to recover from potential modem lockup by power cycling it.
Flawed Configuration Data
The rule file containing the domain settings of the mail gateway service is either missing or a corrupt rule file has been loaded. This event is only reported when parameter Bad Rulefile Loaded (see: ) is set to yes.
FW Forwarding Loop Suppressed
These events are triggered when the firewall engine delivers a local targeted session from the local firewall to the forwarding firewall (because of a non existing local listening socket) and in the forwarding firewall a rule matches that does not perform DNAT.
FW Local Redirection Suppressed
FW Worker Limit Exceeded
VPN Server Tunnel Terminated
|The VPN peer IP address and/or gateway is unavailable or the VPN tunnel has been terminated manually.||Information||1||no|
VPN Alternative Tunnel Activated
A VPN alternative tunnel will be activated, when the active partner of the tunnel changes his Bind-IP address (for example provider failure).
VPN Server Tunnel Activated
A VPN Site-to-Site tunnel has been activated.
|3003||activation of on- demand tunnel||A on-demand VPN Site-to-Site tunnel has been activated.||Notice||1||no|
deactivation of on-demand tunnel
A on-demand VPN Site-to-Site tunnel has been activated.