Firepower Threat Defense API Reference v3(FTD v6.4)
FTD API v3
- Overview
- Error Codes
- Resources
- Model Index
- AAASetting
- ASPathList
- AccessPolicy
- ActiveDirectoryRealm
- ActiveUserSessions
- AnyConnectClientProfile
- AnyConnectPackageFile
- ApiVersions
- Application
- ArchivedBackup
- AuditEntityChange
- AuditEvent
- BGP
- BackupImmediate
- BackupScheduled
- BreakHAStatus
- CertFileUploadStatus
- Certificate
- addExternalCACertificate
- addExternalCertificate
- addInternalCACertificate
- addInternalCertificate
- deleteExternalCACertificate
- deleteExternalCertificate
- deleteInternalCACertificate
- deleteInternalCertificate
- editExternalCACertificate
- editExternalCertificate
- editInternalCACertificate
- editInternalCertificate
- getExternalCACertificate
- getExternalCACertificateList
- getExternalCertificate
- getExternalCertificateList
- getInternalCACertificate
- getInternalCACertificateList
- getInternalCertificate
- getInternalCertificateList
- CliDeploymentError
- CloudCommunicationSettings
- CloudConfig
- CloudManagement
- CloudServicesInfo
- Command
- CommandAutoComplete
- ConfigIssue
- ConnectTest
- Continent
- Country
- CustomLoggingList
- DHCPServerContainer
- DNS
- DataInterfaceManagementAccess
- Deployment
- DeploymentData
- DeviceHostname
- DeviceLogSettings
- DiskUsage
- Download
- ExpandedCommunityList
- ExportConfigJobHistory
- ExtendedAccessList
- FeatureInformation
- FilePolicy
- FlexConfigObject
- FlexConfigPolicy
- GeoLocation
- GeolocationUpdateImmediate
- GeolocationUpdateSchedule
- HAAction
- HAConfiguration
- HAFailoverConfiguration
- HAStatus
- HTTPAccessList
- HardwareBypass
- HitCount
- IPV4PrefixList
- IPV6PrefixList
- IdentityPolicy
- IdentityServicesEngine
- IkevOnePolicy
- IkevOneProposal
- IkevTwoPolicy
- IkevTwoProposal
- InitialProvision
- Interface
- InterfaceInfo
- IntrusionPolicy
- IntrusionSettings
- Job
- deleteJobHistoryBackup
- deleteJobHistoryCloudManagement
- deleteJobHistoryDeployment
- deleteJobHistoryEntities
- deleteJobHistoryEntity
- deleteJobHistoryGeolocation
- deleteJobHistoryHaConfigSync
- deleteJobHistorySruUpdate
- deleteJobHistoryVDBUpdate
- deleteLicenseJobHistory
- getJobHistoryBackup
- getJobHistoryBackupList
- getJobHistoryCloudManagement
- getJobHistoryCloudManagementList
- getJobHistoryDeployment
- getJobHistoryDeploymentList
- getJobHistoryEntity
- getJobHistoryEntityList
- getJobHistoryGeolocation
- getJobHistoryGeolocationList
- getJobHistoryHaConfigSync
- getJobHistoryHaConfigSyncList
- getJobHistorySruUpdate
- getJobHistorySruUpdateList
- getJobHistoryVDBUpdate
- getJobHistoryVDBUpdateList
- getLicenseJobHistory
- getLicenseJobHistoryList
- JoinHAStatus
- LocalIdentitySource
- ManagementIP
- NAT
- NTP
- NTPStatus
- NetworkFeedCategory
- NetworkObject
- OSPF
- OSPFInterfaceSettings
- PendingChanges
- PolicyList
- PortObject
- addICMPv4PortObject
- addICMPv6PortObject
- addPortObjectGroup
- addProtocolObject
- addTCPPortObject
- addUDPPortObject
- deleteICMPv4PortObject
- deleteICMPv6PortObject
- deletePortObjectGroup
- deleteProtocolObject
- deleteTCPPortObject
- deleteUDPPortObject
- editICMPv4PortObject
- editICMPv6PortObject
- editPortObjectGroup
- editProtocolObject
- editTCPPortObject
- editUDPPortObject
- getICMPv4PortObject
- getICMPv4PortObjectList
- getICMPv6PortObject
- getICMPv6PortObjectList
- getPortObjectGroup
- getPortObjectGroupList
- getProtocolObject
- getProtocolObjectList
- getTCPPortObject
- getTCPPortObjectList
- getUDPPortObject
- getUDPPortObjectList
- PostUpgradeFlags
- PullUpgradeImmediate
- PullUpgradeJob
- RaVpn
- RaVpnConnectionProfile
- RaVpnGroupPolicy
- RadiusIdentitySource
- RadiusIdentitySourceGroup
- RestoreImmediate
- RolePermission
- RouteMap
- SRUUpdateImmediate
- SRUUpdateSchedule
- SSHAccessList
- SSLCipher
- SSLPolicy
- SToSConnectionProfile
- ScheduleExportConfig
- ScheduleTroubleshoot
- Secret
- SecurityIntelligence
- editSecurityIntelligenceNetworkPolicy
- editSecurityIntelligencePolicy
- editSecurityIntelligenceURLPolicy
- getSecurityIntelligenceNetworkPolicy
- getSecurityIntelligenceNetworkPolicyList
- getSecurityIntelligencePolicy
- getSecurityIntelligencePolicyList
- getSecurityIntelligenceURLPolicy
- getSecurityIntelligenceURLPolicyList
- SecurityIntelligenceUpdateFeedsImmediate
- SecurityIntelligenceUpdateFeedsSchedule
- SecurityZone
- SmartLicensing
- SpecialRealm
- StandardAccessList
- StandardCommunityList
- StaticRouteEntry
- StaticRouteEntryContainer
- SyslogServer
- SystemFeedObject
- SystemInformation
- Telemetry
- TestDirectory
- TestIdentityServicesEngineConnectivity
- TestIdentitySource
- TimeZones
- Token
- TrafficInterruptionReasons
- TrafficUser
- TrafficUserGroup
- TrendingReport
- TroubleshootJobHistory
- URLCategory
- URLFeedCategory
- URLObject
- URLReputation
- Upgrade
- UpgradeFile
- Upload
- UrlCategoryInfo
- User
- VDBUpdateImmediate
- VDBUpdateSchedule
- WebAnalyticsSetting
- WebUICertificate
- Models
- Model Index for FTD 6.4.0
- AAASetting
- AccessControlRuleDeployInfo
- AccessDefaultAction
- AccessEntryBase
- AccessPolicy
- AccessPolicyDeployInfo
- AccessRule
- AccessRuleInfo
- ActiveDirectoryRealm
- ActiveUserSessions
- AdministrativeDistance
- AFAggregateAddress
- AFAggregateAddressIPv4
- AFAggregateAddressIPv6
- AFBase
- AFBGPDistance
- AFInjectMap
- AFIPv4
- AFIPv4Network
- AFIPv6
- AFIPv6Network
- AFMaximumPaths
- AFNetworkBase
- AFTableMap
- AnyConnectClientProfile
- AnyConnectGroupPolicy
- AnyConnectPackageFile
- AnyConnectPackages
- AnyConnectProfile
- AnyConnectVpnConnection
- AnyConnectVpnConnectionUncompressedModel
- ApiVersions
- Application
- ApplicationCategory
- ApplicationFilter
- ApplicationFilterCondition
- ApplicationTag
- ArchivedBackup
- Area
- AreaNetwork
- AreaRange
- AreaType
- ASPathEntry
- ASPathList
- AuditDeploymentData
- AuditDeploymentEvent
- AuditDiscardPendingChangesEvent
- AuditEntityChange
- AuditEntityCreateEvent
- AuditEntityDeleteEvent
- AuditEntityUpdateEvent
- AuditEvent
- AuditFailedLoginEvent
- AuditHAActionData
- AuditHaActionEvent
- AuditJobExecutionData
- AuditJobExecutionEvent
- AuditLoginEvent
- AuditLogoutEvent
- AuditOutOfBandChangeEvent
- AuthenticationBase
- BackupFile
- BackupImmediate
- BackupScheduled
- BaseDiff
- BaseEntityDiff
- BGP
- BGPBestPath
- BGPGracefulRestart
- BGPTimers
- BreakHAStatus
- BridgeGroupInterface
- BridgeGroupInterfaceIdInfo
- BufferedLogging
- CertFileUploadStatus
- CertificateStatus
- CertificateUserNameSettings
- ChangePasswordStatus
- CliDeploymentError
- Clipboard
- CloudCommunicationSettings
- CloudConfig
- CloudManagement
- CloudServicesInfo
- CloudUnregisterImmediate
- CloudUnregisterJobHistory
- Command
- CommandAutoComplete
- CommunityEntryBase
- ConfigIssue
- ConfigIssueMessage
- ConnectivitySetting
- ConnectTest
- ConsoleLogFilter
- Continent
- Country
- CustomLoggingList
- CustomLoggingListLogLevel
- CustomLoggingListMessage
- DatabaseInfo
- DataDNSSettings
- DataInterfaceManagementAccess
- DataSSLCipherSetting
- DataSyslogServerLogging
- DefaultIdentityRule
- DefaultInformationOriginate
- DeployedConfigChecksum
- DeploymentData
- DeploymentInfo
- DeploymentSchedule
- DeploymentStatus
- DeploymentStatusMessage
- Device
- DeviceDNSSettings
- DeviceHostname
- DeviceLogFilterBase
- DeviceLogSettings
- DHCPServer
- DHCPServerContainer
- DirectoryConfiguration
- DirectoryUserDownloadImmediate
- DirectoryUserImportImmediate
- DiskUsage
- DistinguishedName
- DistinguishedNameGroup
- DistributeList
- DNSServer
- DNSServerGroup
- EasySetupBase
- EasySetupStatus
- EmbeddedAppFilter
- EmbeddedAppFilterBase
- EmbeddedURLFilter
- EntityCreate
- EntityDelete
- EntityDiffAnalyserResult
- EntityUpdate
- EpsReportItem
- ErrorResponse
- EventingCacheRefreshImmediate
- ExpandedCommunityEntry
- ExpandedCommunityList
- ExportConfigFile
- ExportConfigJobHistory
- ExtendedAccessEntry
- ExtendedAccessList
- ExternalCACertificate
- ExternalCACertificateGroup
- ExternalCertificate
- FeatureInformation
- FeatureInformation$Feature
- FileChunkContent
- FileChunksInfo
- FileEntity
- FileMalwareSyslogServerLogging
- FilePolicy
- FileUploadStatus
- FlexConfigObject
- FlexConfigPolicy
- FlexVariable
- FlowBit
- FlowBitRuleRelation
- FQDNId
- GeoLocation
- GeolocationUpdateImmediate
- GeolocationUpdateSchedule
- GeolocationVersion
- HaBreakCleanupImmediate
- HABreakStatus
- HaConfigSyncImmediate
- HAConfiguration
- HAFailoverConfiguration
- HAIPv4Address
- HAIPv6Address
- HAJoinStatus
- HardwareBypass
- HAStatus
- HitCount
- HTTPAccessList
- ICMPv4PortObject
- ICMPv6PortObject
- IdentityPolicy
- IdentityRule
- IdentityServicesEngine
- IdentitySourceBase
- IkePolicyBase$CliTokenIf
- IkevOnePolicy
- IkevOneProposal
- IkevTwoPolicy
- IkevTwoProposal
- IncomingRouteFilter
- InetAddressBase
- InitialProvision
- InterfaceInfo
- InterfaceInfoEntry
- InterfaceIPv4
- InterfaceIPv6
- InternalCACertificate
- InternalCertificate
- IntrusionPolicy
- IntrusionPolicyRuleUpdate
- IntrusionRule
- IntrusionRuleConfig
- IntrusionRuleInfo
- IntrusionRuleMetaData
- IntrusionRuleRelation
- IntrusionRuleUuidInfo
- IntrusionSettings
- IPPrefixEntry
- IPSRuleClassification
- IPSVariableNetworkGroup
- IPSVariablePortGroup
- IPv4Address
- IPV4PrefixList
- IPV4PrefixListFilter
- IPv6Address
- IPv6Prefix
- IPV6PrefixList
- IPV6PrefixListFilter
- ISEObject
- ISESession
- JobHistoryBackup
- JobHistoryCloudManagement
- JobHistoryDeployment
- JobHistoryDirectoryUserDownload
- JobHistoryDirectoryUserImport
- JobHistoryEntity
- JobHistoryEventingCacheRefresh
- JobHistoryGeolocation
- JobHistoryHaBreakCleanup
- JobHistoryHaConfigSync
- JobHistoryRestore
- JobHistorySecurityIntelligenceFeedDownload
- JobHistorySruUpdate
- JobHistoryUpgrade
- JobHistoryVDBUpdate
- JoinHAStatus
- LDAPRealm
- License
- LicenseJobHistory
- LicenseRegistrationJobHistory
- Links
- LinksReference
- LocalIdentitySource
- LogAdjacencyChanges
- LsaThrottleTimer
- ManagementIP
- ManualNatRule
- ManualNatRuleContainer
- ManualNatRuleContainerDeployInfo
- MD5Authentication
- ModelClassDependency
- Neighbor
- NeighborAdvanced
- NeighborAdvertiseMap
- NeighborBase
- NeighborDefaultOriginate
- NeighborDistributeList
- NeighborEBGPMultiHop
- NeighborFallOverBFD
- NeighborFilterList
- NeighborGeneral
- NeighborHAMode
- NeighborHops
- NeighborIPv4
- NeighborIPv6
- NeighborLocalAs
- NeighborMaximumPrefix
- NeighborRouteMap
- NeighborRoutes
- NeighborTimers
- NeighborTransportPathMTUDiscovery
- NeighborTTLSecurityHop
- NestedEntity
- NetworkFeed
- NetworkFeedCategory
- NetworkObject
- NetworkObjectGroup
- NGFWErrorMessage
- NsfGracefulRestart
- Nssa
- NTP
- NTPStatus
- OAuthTokenInfo
- OAuthTokenInfo$TokenInfoEntry
- ObjectNatRule
- ObjectNatRuleContainer
- ObjectRevisionDbCache
- ObjectUuidMapDbCache
- OpenSSLCipherInfo
- OSPF
- OSPFDeadIntervalMechanism
- OSPFHelloMultiplierMechanism
- OSPFInterfaceSettings
- OSPFLostNeighborDetectionMechanism
- OSPFProtocolConfiguration
- OutgoingRouteFilter
- Paging
- PasswordAuthentication
- PatOptions
- PercentUsageReportItem
- Permission
- PhysicalInterface
- PolicyList
- PolicyRuleIdInfo
- PolicyRuleIdMapDbCache
- PortObjectGroup
- PostUpgradeFlags
- PrefixFilter
- PrefixListFilter
- ProcessConfiguration
- ProductivityCondition
- ProtocolObject
- PullUpgradeImmediate
- PullUpgradeJob
- RadiusIdentitySource
- RadiusIdentitySourceGroup
- RaVpn
- RaVpnConnectionProfile
- RaVpnGroupPolicy
- RBACResource
- RBACResourceGroup
- RealmIdInfo
- RedistributeBGP
- RedistributeConnected
- RedistributeEIGRP
- RedistributeISIS
- RedistributeISISIPv6
- RedistributeOSPF
- RedistributeOSPFv3
- RedistributeProtocol
- RedistributeRIP
- RedistributeStatic
- ReferenceModel
- ReferenceUpdate
- ReportItem
- ReportItemAttribute
- ResourcePermission
- ResponseStatus
- RestoreImmediate
- RiskCondition
- RolePermission
- RouteMap
- RouteMapEntry
- RouteMetric
- ScheduleExportConfig
- ScheduleTroubleshoot
- SearchCondition
- SecondaryAuthenticationSettings
- Secret
- SecurityIntelligenceFeedsInfo
- SecurityIntelligenceNetworkPolicy
- SecurityIntelligencePolicy
- SecurityIntelligenceUpdateFeedsImmediate
- SecurityIntelligenceUpdateFeedsSchedule
- SecurityIntelligenceURLPolicy
- SecurityZone
- SerializationKey
- SerialNumber
- ServerHostAndPort
- SmartAgentConnection
- SmartAgentStatus
- SmartAgentSyncRequest
- SnortVersion
- SpecialRealm
- SpfThrottleTimer
- SRUIntrusionPolicy
- SRUUpdateImmediate
- SRUUpdateSchedule
- SRUVersion
- SSHAccessList
- SSLCipher
- SSLPolicy
- SSLPolicyDefaultAction
- SSLRule
- SSLUndecryptableActions
- StandardAccessEntry
- StandardAccessList
- StandardCommunityEntry
- StandardCommunityList
- StaticRouteEntry
- StaticRouteEntryContainer
- SToSConnectionProfile
- Stub
- SubInterface
- SummaryAddress
- SyslogServer
- SyslogServerLogFilter
- SystemFeedObject
- SystemInformation
- TCPPortObject
- Telemetry
- TelemetryJobHistory
- TelemetrySchedule
- TestDirectory
- TestIdentityServicesEngineConnectivity
- TestIdentitySource
- ThroughputReportItem
- Time
- Timers
- TimeZones
- TokenPayloadUnion
- TokenResponseUnion
- TokenStatus
- TrafficEntry
- TrafficGroupEntry
- TrafficInterruptionReasons
- TrafficUser
- TrafficUserBase
- TrafficUserEntry
- TrafficUserGroup
- TrendingReport
- TroubleshootFile
- TroubleshootJobHistory
- TSAgentSession
- TunnelPolicy
- TunnelPolicyDeployInfo
- TunnelRule
- TunnelZone
- TypeCondition
- UDPPortObject
- UpgradeFile
- UploadBackupStatus
- URLCategory
- UrlCategoryInfo
- URLCategoryMatcher
- URLFeed
- URLFeedCategory
- URLObject
- URLObjectGroup
- URLReputation
- User
- UserBase
- UserPreferences
- UserRole
- UserSession
- ValueAdd
- ValueDelete
- ValueUpdate
- VariableBase
- VDBUpdateImmediate
- VDBUpdateSchedule
- VDBVersion
- VirtualLink
- VlanTag
- VlanTagGroup
- VpnGatewaySettings
- VPNSession
- WebAnalyticsSetting
- WebUICertificate
Category | Code | Message | |||
---|---|---|---|---|---|
Validation | acRuleDestUdpProtocolNotAllowedWithUdpDestPort | You cannot add a destination UDP protocol object with destination UDP ports: {0} | |||
Validation | linaAAAServerTestConnectionInternalError | Internal error occured while testing aaa-server connection with data-plane. Please check backend logs. | |||
Validation | manualNatRouteLookupDestNetworkMismatch | The Perform Route Lookup option is available for identity NAT only. The original and translated destination networks must be identical to use the option. | |||
Validation | manualNatSrc64Ipv6HostCountTooHigh | The IPv6 host count {0} in the original source exceeds the maximum allowed {1} in an IPv6 to IPv4 manual NAT source translation | |||
Validation | contextCreationFailed | Could not create device registration context. Please try again later. | |||
Validation | invalidUserRoleName | The user role name was not provided in the request or the name is invalid. | |||
Validation | missingFilterProcessor | Query processing failed due to a missing filter processor for class : "{0}" | |||
Validation | invalidV6EndCompatible | IPv4-compatible IPv6 as end address is not supported. | |||
Validation | appFilterInvalidNumericValueHigh | The numeric input for {0} is too high. The maximum value {1}. | |||
Validation | ipv4OrIpv6Required | You must select either an Ipv4 or Ipv6 network. | |||
Validation | missingValidator | Validation failed due to a missing validator: "{0}" | |||
Validation | invalidInput | Validation failed. Invalid input: "{0}" | |||
Validation | invalidOspfInterfaceConflictingMechanism | Conflicting lost neighbor detection mechanism. Either hello-multiplier or dead-interval and hello-interval must be used but not both | |||
Validation | lockInvalidUnlock | Attempting to acquire an invalid lock: "{0}" | |||
Validation | SecurityIntelligenceExceededMaxNetworkListSize | The combined number of entries in the network whitelist and blacklist cannot exceed 255. | |||
Validation | ipsecExcessIkev1Policies | The maximum number of IKEv1 policies enabled has already been reached ({0}) | |||
Validation | invalidSmartCliRequiredDisabled | {0}: This is a required command. You cannot disable it | |||
Validation | objectNatSubnetNotAllowedInDynamicRuleTransNet | The dynamic auto NAT rule cannot have subnet objects for the translated address: {0} | |||
Validation | invalidOspfExceededLimit | Only two OSPF processes are allowed per device | |||
Validation | passwordTooLong | Password is too long. The password needs to be less than 129 characters long | |||
Validation | ipv6PoolMissingPrefixLength | Missing prefix length in IPV6 address pool | |||
Validation | DHCPServerNoInterfaceIpAddress | The interface must have an IP address because it is used as a DHCP Server | |||
Validation | manualNatSubnetNotAllowedInDynamicRuleTransSrc | The dynamic manual NAT rule cannot have subnet objects for the translated source: {0} | |||
Validation | geoUpdateError_11 | Unable to update the Geolocation database, please retry the update | |||
Validation | cannotChangeNameOfRAVPNUser | You cannot change the username of a RA VPN user | |||
Validation | dnsServersipv6management | You cannot use an IPv6 address for the DNS server because IPv6 is disabled on the management interface. | |||
Validation | cannotDeleteBaseLicense | The base license cannot be removed | |||
Validation | sysInfoNullFileOrProcess | Cannot create reader for null file or process | |||
Validation | nullBgpNeighborFilteringMaximumPrefixLimitRestartInterval | Restart Interval can not be null. | |||
Validation | managementOnlyCannotBeDisabled | You cannot disable the management-only option on the Management interface | |||
Validation | invalidBGPAddressFamilyMoreThanTwo | Cannot have more than two address families. | |||
Validation | contextActivationFailed | Could not activate context. Please try again. | |||
Validation | accessListEntriesNotUnique | Access List entries must be unique. | |||
Validation | aaaInvalidUseLocalConfig | {0} AAA setting using "{1}" type for the "{2}" field must set the "useLocal" field to {3} | |||
Validation | filterNotSupported | Filter property not supported | |||
Validation | vdbBootstrap | Adding VDB updates to database | |||
Validation | diskFileNameIsEmpty | Disk file name cannot be null or empty string | |||
Validation | manualNatDest64Ipv6HostObjNotAllowedInOrigDest | You cannot use an IPv6 host network object as the original destination in an IPv6 to IPv4 manual NAT destination translation rule: {0} | |||
Validation | invalidUsage | Validation failed, method "{0}" cannot be used to process "{1}" | |||
Validation | manualNatOrigSrcAndDestIpVersionMismatch | The original source and original destination addresses must have the same IP version | |||
Validation | staticRouteDupIdentifier | Static routes must be identifiable by a unique combination of interface, network, and gateway values | |||
Validation | duplicateUserInRule | {0} is in the rule more than once. | |||
Validation | bridgeGroupInterfaceHardwareNameNotEditable | The bridge group interface hardware name cannot be modified by editing the bridge group interface. Current bridge group interface hardware name in the DB is {0}, bridge group interface ID from request is {1} | |||
Validation | shouldNotContainHTML | HTML tags are not allowed | |||
Validation | cannotEditIPOfNeighborInterface | An interface cannot have the same IPv4 address as a neighbor in OSPF {0}. | |||
Validation | appFilterInvalidTypeName | Invalid application filter type name {0}. | |||
Validation | objectNat66OrigAddrPrefixShorterThanTransAddrPrefix | The IPv6 prefix of the original address subnet "{0}" must be greater than or equal to the IPv6 prefix of the translated address subnet "{1}" | |||
Validation | manualNatOrigDestIsNull | You must specify an original destination network | |||
Validation | invalidOspfInterfaceConflictingNetwork | OSPF area networks must all belong to Management interfaces or Data interfaces | |||
Validation | invalidBGPNeighborPasswordLength | Passwords used for BGP Neighbor authentication must be between 1 and 25 characters | |||
Validation | invalidUserIdentitySourceTypeInRule | The identity source for the users in the rule should be of type IdentityRealmBase or LocalIdentitySource | |||
Validation | ipsecPolicySamePriority | Priority cannot overlap with existing policy: {0} | |||
Validation | invalidFlexCliInterfaceValue | {0} value must be an existing PhysicalInterface, SubInterface, or a BridgeGroupInterface Object | |||
Validation | bypassPairShouldContainTwoInterfaces | The hardware bypass pair does not contain two interfaces that are allowed to be paired | |||
Validation | invalidHAFailoverPeerPollTimeUnit | Peer Poll time unit must be MILLISECONDS or SECONDS | |||
Validation | s2sIkev1NoEnabledPolicyWithAuth | Cannot enable site-to-site IKE-V1 without enabling any IKE-V1 policy with authentication type {0} | |||
Validation | nullPlatformLogSettings | Platform log settings cannot be null on this platform. | |||
Validation | DHCPServerIPPoolSize | DHCP server IP address range must not exceed 256 entries: {0} | |||
Validation | DHCPServerPrimaryWINSHost | DHCP server primary WINS server must be host type: {0} | |||
Validation | bridgeGroupInterfaceReferencedInStaticRoute | The following Interfaces are used in static route configuration: {0}. This feature is not compatible with a bridge group member interface. You must remove the interfaces from the configuration before you can add them to the bridge group. | |||
Validation | connectorMsgSendError | Connector failed to send the message. | |||
Validation | AnyConnExcessFiles | Can only have one AnyConnectPackageFile per platform | |||
Validation | sysInfoIOException | IO Exception thrown while trying to read System Information | |||
Validation | invalidOspfDuplicateDefaultArea | 0.0.0.0/0.0.0.0 is already used, only one area can be set as a default area | |||
Validation | invalidLicenseCount | This is an invalid number of license requests. Please specify the count as 1 | |||
Validation | identityRealmMultipleDirectoryConfig | Multiple directory configurations are not allowed for the realm. | |||
Validation | invalidHoldTime | Hold time must be 0 or greater than 2 seconds. | |||
Validation | invalidTemplateInstance | Instance does not match with the template it uses. Found mismatch in the properties "{0}" of SmartCLI instance with name "{1}". | |||
Validation | invalidDupInAclRouteFilter | Only one access list is allowed per interface | |||
Validation | vdbUpdateError_12 | Error running VDB update | |||
Validation | cannotRetrieveHAStatus | Failed to retrieve current device's HA configuration status | |||
Validation | sruUpdateError_8 | Rulepack download failed | |||
Validation | bgpInvalidBgpNeighborAdvertiseMapConfiguration | Cannot configure exist-map and non-exist map for the same advertise-route-map and exist-route-map. | |||
Validation | invalidLoggingListName | Severity level cannot be used as name. Name cannot be substring of severity level. | |||
Validation | unpersistedReferenceTarget | Un-persisted reference target is detected, reference source is {0}, reference target is {1} | |||
Validation | natPatOptionsNotSupported | The PAT pool option is not supported in NAT rules | |||
Validation | expiredCertificateUpload | The uploaded certificate has already expired. Please upload an unexpired certificate. | |||
Validation | PullUpgradeInitiationFailed | Pull upgrade job initiation failed | |||
Validation | manualNatDest46AnyIpv6NotValid | The network corresponding to the full range of IPv6 addresses, i.e. ::/0, cannot be used in the destination of an IPv6 to IPv4 manual NAT rule | |||
Validation | invalidIpAddress | Invalid IP address | |||
Validation | cryptoCompliantIkev2Policy | The IKE-V2 policies are using strong encryption which is not allowed by your licensing setting, please disable them or use DES only: {0} | |||
Validation | emptyCertificateString | Certificate String cannot be empty. | |||
Validation | emptyFlexVariableName | The variable name is missing in {0} | |||
Validation | PullSignValidationFailed | Image signature verification failed | |||
Validation | DNInvalidCN | CN is invalid, should be in format CN= |
|||
Validation | objectNat46Ipv6PrefixTooLong | The translated address IPv6 network prefix length must be less than or equal to 96 in an IPv4 to IPv6 auto NAT rule: {0}({1}) | |||
Validation | interfaceIsRequired | Either data interface or management interface should be selected. | |||
Validation | cannotConfigureMacAddress | You cannot configure MAC address on interface {0} when it is in passive mode. | |||
Validation | geoUpdateError_2 | No valid support contract found. Contact sales or support for more information | |||
Validation | vdbUpdateError_4 | Update file is corrupted | |||
Validation | invalidSmartCliIPValue | {0} value must be a valid IPv4 or IPv6 address | |||
Validation | invalidLoggingListInvalidRange | Message start ID cannot be greater than or equal to message end ID. | |||
Validation | invalidSystemUpgradeFile | The uploaded file is not valid. Upgrade files must have file type REL.tar. Do not perform upgrades with file type .sh upgrade files. | |||
Validation | invalidFlexCliNegateLineSyntax | Syntax error with Flex Config CLI negate line: {0} | |||
Validation | linaResponseTimedOut | Cannot establish connection with data-plane. Request/Response timed out. | |||
Validation | AnyConnACPrfOutsideIntfInBvi | The interface {0} added to AnyConnectProfile is invalid, it is member of BridgeGroup. | |||
Validation | aceSourceEmptyDestinationIsNot | The source network list cannot be empty when the destination network list has entries. | |||
Validation | invalidLicenseType | This is an invalid type. Please specify one of the following: BASE, MALWARE, THREAT, URLFILTERING | |||
Validation | objectNat64Ipv6HostCountTooHigh | The IPv6 host count {0} in the original address exceeds the maximum allowed {1} in an IPv6 to IPv4 auto NAT rule | |||
Validation | cannotHaveStaticRouteOnTheMemberOfBVI | Bridge Group Member Interface: {0} cannot have static route entry | |||
Validation | objectNatRouteLookupNetworksMismatch | The Perform Route Lookup option is available for identity NAT only. The original and translated addresses must be identical to use the option. | |||
Validation | unknownCertKeyType | Only '.der,.pem,.crt,.cer,.cert,.key' files are allowed for upload | |||
Validation | invalidOSPFAreaNetworkBrigeGroupInterface | Bridge group interface falls in the same network as Area network. OSPF can not be configured on BVI interface | |||
Validation | AnyConnCryptoCompliance | Current licensing status does not allow use of cryptography present in AnyConnect VPN | |||
Validation | appFilterInvalidTypeValue | Invalid application filter type value {0}. | |||
Validation | DHCPServerWithDefaultPassiveInterface | You cannot use a passive mode interface for the DHCP server default interface. | |||
Validation | incompatibleBackupFile | Backup file is incompatible with this Hardware and/or the SW version. | |||
Validation | s2sIkev2NoEnabledPolicy | Cannot enable site-to-site IKE-V2 without enabling any IKE-V2 policy | |||
Validation | sruUpdateError_15 | Internal error occurred while updating Rule Update. Please contact technical support | |||
Validation | bridgeGroupInterfaceReferencedInNatRule | The following Interfaces are used in NAT rules configuration: {0}. This feature is not compatible with a bridge group member interface. You must remove the interfaces from the configuration before you can add them to the bridge group. | |||
Validation | nextHopInvalidSettingCombination | Cannot provide Specific IP(s) when Next Hop uses peer address. | |||
Validation | diagIntfMgmtIntfIpv4 | You cannot configure the same IPv4 address for the management interface and the diagnostic physical interface. | |||
Validation | duplicateName | Validation failed due to a duplicate name: "{0}" | |||
Validation | invalidOspfAreaIdValue | Area ID must be an integer between 0 and 4294967295 or an IPv4 address | |||
Validation | staticRouteDefaultNetworkSameGateway | Static route duplicate gateway for default network: {0} | |||
Validation | invalidOspfNotEnabledOnInterface | OSPF is not enabled on the interface {0} for the configured networks | |||
Validation | upgradeFileNotFound | Upgrade file not found. | |||
Validation | minPrefixLessThanMaxPrefix | The minimum prefix length should be less than the maximum prefix length. | |||
Validation | ftdCertNotFound | FTD Certificate not found. | |||
Validation | deprecatedAppsDescription | Please remove deprecated applications from standalone and embedded application filters. | |||
Validation | invalidSmartCliNegateLineSyntax | Syntax error with Smart CLI negate line: {0} | |||
Validation | RaVpnSecAuthCommPwdNotValid | Common Password cannot be specified. | |||
Validation | cryptoCompliantS2SIkev2Proposal | The S2S VPN connection profile {0} is using IKE-V2 proposals with strong encryption which is not allowed by your licensing setting, please de-reference them and use DES only: {1} | |||
Validation | invalidObjectNameSpaceAllowed | The name "{0}" is invalid. The name can start with an alphanumeric character or an underscore. It can contain spaces and the special characters +, ., _, and -. However, the name cannot include a leading or trailing space. | |||
Validation | acRuleDestinationZonePassive | You cannot use a passive mode security zone as a destination zone in rule {0}. | |||
Validation | invalidOspfRedistOspfNone | OSPF redistribution is not possible without enabling another OSPF process | |||
Validation | invalidSyslogPort | Invalid port for Syslog Server. Either use the default ports, which are 514 for UDP or 1470 for TCP, or specify a port in the 1025-65535 range. | |||
Validation | createFTSIndexFailed | Failed to create indices for objects and rules. Full Text Search will not work. | |||
Validation | noRealmId | Realm ID is required | |||
Validation | DHCPServerPrimaryDNSHost | DHCP server primary DNS server must be host type: {0} | |||
Validation | s2sIkev2MaskedRemoteKeyNotAllowed | Masked value for IKE-V2 pre-shared remote key is not allowed with connection profile creation | |||
Validation | passwordConsecutive | Password contains consecutive characters | |||
Validation | AnyConnNoAddrPools | IPv4 or IPv6 address pool is required | |||
Validation | networkWithoutNetmask | The type Network requires a netmask. To specify a single host, either use the type Host, or use {0}/255.255.255.255. | |||
Validation | geoUpdateError_8 | Unspecified error when doing remote update. GeoDB download failed | |||
Validation | s2sNatExemptIntfCannotBeBviMember | Inside interface for NAT exempt cannot be a bridge-group member: {0} | |||
Validation | raCaCertUsedAsInternalCertificate | A CA certificate cannot be used as identity certificate for authentication between remote access clients and FTD. Please provide a valid identity certificate for successful remote access VPN establishment. | |||
Validation | invalidOspfNetwork | {0} is not a legal network | |||
Validation | operatorNotSupported | Filter operator not supported | |||
Validation | dnsServerGroupNameCannotBeDefault | DefaultDNS is a reserved name. Please enter a different name. | |||
Validation | appFilterApp | The application filter must have valid application parameter values. {0}. | |||
Validation | invalidSmartCliSecretValue | {0} entity value must be an existing Secret Object | |||
Validation | invalidOspfSummaryAddress | OSPF does not support summary address 0.0.0.0/0.0.0.0 | |||
Validation | atleastOneSyslogServerRequired | Atleast one Syslog Server Configuration is required to enable Syslog filter. | |||
Validation | objectNatRouteLookupAndIntfInTransNet | You cannot select the Perform Route Lookup option if you select interface for translated source | |||
Validation | invalidMinHoldTime | Minimum hold time must be 0 or greater than 2 seconds. | |||
Validation | onlyIPv6NetworkObjectsAllowed | Only IPV6 networks are allowed. | |||
Validation | invalidOspfInterfaceSecretNotFound | Secret {0} is not found | |||
Validation | sruDownloadSuccess | Rulepack successfully downloaded | |||
Validation | invalidSmartCliNetworkObjectValue | {0} entity value must be an existing Network Object | |||
Validation | vdbUpdateError_3 | The update server did not have a file applicable to this device. Try again later. If the problem persists, contact Technical Support. | |||
Validation | identityRealmDuplicateADPrimaryDomain | This AD Primary Domain is already used by realm {0} | |||
Validation | invalidConnectionTypeSync | You cannot perform a sync if you are not registered | |||
Validation | nameUseReservedKeyWord | You cannot use a reserved keyword as an object or group name: "{0}" | |||
Validation | invalidSmartCliInterfaceValue | {0} entity value must be an existing PhysicalInterface, SubInterface, or a BridgeGroupInterface Object | |||
Validation | timezoneMalformed | Cannot find the time zone | |||
Validation | cannotChangeUserRoleOfUser | You cannot update the user role of a user. | |||
Validation | invalidFlexCliIncorrectSectionUsage | Incorrect section usage found | |||
Validation | invalidOspfMissingArea | Referenced Area ID {0} is not configured | |||
Validation | invalidHAFailoverPeerHoldTime | Peer hold time must be between 800 and 999 milliseconds, or 1 and 15 seconds. | |||
Validation | communityEntriesNotUnique | Community entries must be unique. | |||
Validation | manualNatTransSrcAndDestIpVersionMismatch | The translated source and translated destination addresses must have the same IP version | |||
Validation | RaVpnConnProfAuthentictaionServerNotSpecified | Authentication Identity source not specified. | |||
Validation | invalidHAFailoverInterfacePollTimeUnit | Interface poll time unit must be MILLISECONDS or SECONDS | |||
Validation | missingIdentityRuleWithAuth | Because there are no identity rules that require authentication, no users or groups defined in the directory can be matched. Configure at least one identity rule that requires authentication before configuring user-based access control rules. | |||
Validation | webCertMissingInternalCert | The Web Server Certificate must be assigned an Internal Certificate. | |||
Validation | invalidSmartCliEnumValue | {0} value must be one of the allowed enum values {1} | |||
Validation | acPolicyInvalidDefaultActionWithIps | Invalid default action {0}; only Allow is allowed with intrusion inspection | |||
Validation | AnyConnACPrfOutsideIntfHasNoName | The interface {0} added to AnyConnectProfile should have a logical name. | |||
Validation | sruMaximumRuleUpdate | Failed to update Intrusion Rule, only {0} may be updated in single transaction. | |||
Validation | objectNatDupRuleWithSameOrigNetwork | There is another auto NAT rule with the same original network. Only one auto NAT rule is allowed per each original network | |||
Validation | invalidOspfVirtualLinkMD5NotEnabled | The selected authentication type is message digest. You must also configure the message digest key | |||
Validation | useOfUnspecifiedIPAddressOnly | {0} is known as an Unspecified Address. This address cannot be assigned to an interface. | |||
Validation | cannotBlankIntfNameUsedInDIMA | Cannot blank out the name of interface when its used in management access rule. | |||
Validation | haIdenticalAddresses | {0} has identical primary and secondary {1} addresses. | |||
Validation | invalidOspfInterfaceMD5NotEnabled | Message digest has been chosen as the authentication type but message-digest-key is not configured | |||
Validation | invalidFlexCliTemplateNull | Template cannot be null | |||
Validation | evalAlreadyUsed | This device has already used evaluation mode. If you would like Smart Licensing capabilities, please register | |||
Validation | invalidTarget | Validation failed due to an invalid relationship target: "{0}" | |||
Validation | invalidAuthAction | Invalid authentication action in identity rule. You can select No Auth or Active Auth only. | |||
Validation | invalidDupOutRouteFilter | Duplicate configuration found for outgoing route filter | |||
Validation | diskFileNameInvalid | Disk file name cannot be null or empty or longer than 60 characters. It can start with an alphanumeric character or an underscore and contain the special characters +, ., _ and - | |||
Validation | invalidFlexCliTemplateIndexRef | Index reference is not supported | |||
Validation | sequenceNumberNotUnique | Sequence number needs to be unique across all entries. | |||
Validation | duplicateVlanId | VLAN ID {0} is already used in {1} | |||
Validation | InvalidBgpNeighborMigrationLocalAsRemoteAsNumber | Cannot have local-as number same as remote-as number. | |||
Validation | acRuleNetworkObjectSubtypesNotSupported | Access list contains network-object of un-supported sub-types. | |||
Validation | invalidLocalUserInRule | The local user selected in the rule is not valid. | |||
Validation | natDestIntfNotNamed | The interface used for NAT rule destination interface must have a name | |||
Validation | invalidVersion | Validation failed due to an invalid version: "{0}" | |||
Validation | invalidSmartCliBranchRequired | Incomplete configuration, at least one command must be enabled for the chosen value {0} | |||
Validation | scheduleInvalidTrigger | Unable to schedule job {0}. Invalid start trigger. | |||
Validation | cannotUseIntfInRavpn | You cannot use an interface that is currently being used in an AnyConnect VPN connection | |||
Validation | cannotUseIntfWithPassiveMode | You cannot use an passive mode interface to configure data interface. | |||
Validation | acRuleNullRuleAction | You must specify an access rule action | |||
Validation | manualNatDest46Ipv6PrefixTooShort | The translated destination IPv6 network prefix length must be greater than or equal to 64 in an IPv4 to IPv6 manual NAT destination translation: {0} | |||
Validation | haBreakMustClearIntf | An {0} executed on a device not in active state must clear interfaces | |||
Validation | invalidSmartCliDuplicateConfiguration | You have already configured the command with the same values | |||
Validation | s2sNetworksMixedToStrict | Local networks contain both IPv4 and IPv6 but remote networks contain only {0} addresses | |||
Validation | bgpGracefulStalePathTimeWithoutGracefulRestart | Graceful restart should be enabled before setting stale path time | |||
Validation | invalidOspfAreaTypeConfiguration | Multiple area types defined for the same area | |||
Validation | scheduleExist | Unable to schedule job {0}. A schedule is pending. | |||
Validation | staticRouteNetworkMatchesInterfacePrefix | There is already a route for {0}/{1} because of the implicit route for the interface {2}, {3}/{4}. Do not define routes for networks configured on an interface. | |||
Validation | invalidSmartCliInterfaceNameRequired | Interface associated with {0} object of {1} (Smart CLI) should have a non-empty NAME. | |||
Validation | SecurityIntelligenceURLPolicyMoreThanOne | Cannot have more than one Security Intelligence URL Policy. | |||
Validation | AnyConnProxyServerPortTooLong | Proxy Server Host and Port should be within 100 characters | |||
Validation | acRuleNullEventLogAction | You must specify an event logging action for the access rule | |||
Validation | invalidASPathName | ASPath name must be a numeric value between 1 and 500 | |||
Validation | registrationFailure | The device is not registered. | |||
Validation | manualNatTransDestIsNull | You must specify a translated destination network | |||
Validation | AnyConnEmptyPackages | No any-connect package file is included, please upload and select at least one | |||
Validation | invalidOspfv2IP | {0} must be an IPv4 address | |||
Validation | invalidTimeoutSpecified | Timeout value has to be in the range {0} and {1} | |||
Validation | manualNatDest64Ipv4AnyIsNotAllowedWithNat46WellKnownPrefix | The translated destination cannot be IPv4 "any" with the well known NAT46 prefix "64:ff9b::" in the original destination | |||
Validation | ipWithoutPrefix | The IPv6 address requires a prefix. | |||
Validation | manualNatOrigSrcHasIpv6AndIpv4Addresses | The original source network should not contain both IPv4 and IPv6 addresses | |||
Validation | manualNatDuplicateRule | Another manual NAT rule is found to have identical address and port translation | |||
Validation | haActionDuringDeployment | HA action cannot be performed during an ongoing deployment process. | |||
Validation | contextUpdateFailed | Could not update device registration context. Please try again. | |||
Validation | scheduleInvalidType | Unable to schedule job. Invalid type. | |||
Validation | invalidOspfInterfaceNeighborsDefined | Operation cannot be performed. An OSPF neighbor is defined for the interface {0} in the object {1} | |||
Validation | acRuleOverlapCountryContinentDestNetworks | The destination networks should not contain both country {0} and continent {1} | |||
Validation | invalidPort | Invalid port. Valid ports are from 1 to 65535. | |||
Validation | interfaceCannotHaveIpv6AddressOfBgpNeighbor | An interface cannot have the same IPv6 address as a neighbor in BGP. | |||
Validation | aceSourceDestinationNoMatchingIPV | IP version of source and destination network objects do not match. | |||
Validation | dnsDuplicate | DNS server {0} is specified more than once. Please remove duplicate servers. | |||
Validation | invalidOspfOutRouteFilterIdNotFound | No process found for the given protocol and identifier | |||
Validation | invalidFlexCliPortValue | {0} value must be an existing TCPPortObject or UDPPortObject | |||
Validation | objectNatTransNetIsNullAndIntfInTransNetIsFalse | You must specify an address or interface for the translated address | |||
Validation | invalidFlexCliDuplicateVariable | A variable with name {0} already exists in the configuration | |||
Validation | appFilterInvalidTagName | Invalid application filter tag name {0}. | |||
Validation | invalidNetworkSubtypeForDataInterface | The management access rule for the data interfaces contains a network object of an unsupported type. | |||
Validation | unsupportedSSPInterfaceDuplex | Unsupported SSP Interface Duplex on NGFW | |||
Validation | appFilterInvalidTagValue | Invalid application filter tag value {0}. | |||
Validation | invalidSmartCliLineNotRepeatable | This command cannot be repeated but it appears more than once in the configuration. Please remove the repeated commands | |||
Validation | cannotNotFindValue | Validation of depending objects could not be done successfully. The system failed to resolve the references of this entity for the depending objects. | |||
Validation | invalidRavpnLicense | RA-VPN license is not enabled | |||
Validation | invalidOspfNsfIetfOnly | NSF IETF requires Opaque LSA, IETF helper enabled and LLS capability, Cisco helper negated | |||
Validation | onlyIPv4NetworksAllowed | Only IPV4 networks are allowed - {0} | |||
Validation | invalidOspfInterfaceSecretRequirements | Secret {0} does not meet the password requirements for {1} | |||
Validation | connectorResetError | Connector reset failed due to an internal error. | |||
Validation | invalidOutRouteFilterId | Process identifier is required for the chosen protocol | |||
Validation | sruUpdateError_17 | Error downloading rule update, file is corrupt (Incorrectly Signed). Please contact technical support. | |||
Validation | unsupportedNetworkType | {0} {1} | |||
Validation | invalidFlexCliCharLimitExceeded | A cli command exceeded character limit | |||
Validation | AnyConnIntfAddrOverLap | Interface {0} cannot be in the address pool range {1} | |||
Validation | invalidOspfAreaDupPrefixFilter | Only one prefix list can be configured in either direction | |||
Validation | bgpDuplicateNetworksNotAllowed | Duplicate networks are not allowed | |||
Validation | appFilterDupCondition | The application filter contains identical conditions. | |||
Validation | DHCPServerOverlapOutsideInterface | A DHCP server is already configured for {0}. You cannot use DHCP to obtain the IP address on an interface running DHCP server. Please select a different interface. | |||
Validation | geoDbBootstrap | Adding Geolocation updates to database | |||
Validation | invalidConnectionType | The Connection Type entered for Smart Licensing is invalid, please give either "Eval" for Evaluation Mode or "Register" with a token to register to the cloud | |||
Validation | iseNetworkFilterInvalid | You cannot use an FQDN or RANGE network object or an IPV6 Address in the Identity Services Engine configuration. | |||
Validation | evalNotUsed | Evaluation mode cannot be stopped as it is not currently in use | |||
Validation | invalidOspfDuplicateNetwork | {0} has already been configured | |||
Validation | managementInterfaceCannotBeParent | You cannot create a subinterface on the Management interface {0} | |||
Validation | primaryAndSecondaryIseConflict | Primary and Secondary ISE Server address cannot be the same | |||
Validation | invalidFlexCliTemplateEmpty | Template cannot be empty | |||
Validation | ipsecNoEnabledIkev1PoliciesWithPreshareAuth | Cannot disable or delete IKEv1 policy with pre-shared key authentication, need at least one policy active while a site-to-site connection profile using IKEv1 exists | |||
Validation | haBreakFromNegotiation | The units in this HA pair are in negotiation. You cannot execute {0} until negotiation is finished. | |||
Validation | invalidFlexCliNoBlocks | A group of blocks can be empty but not null | |||
Validation | AnyConnServerCertNeedsIssuerCommonName | The Server certificate {0} requires issuer common name | |||
Validation | invalidFlexCliLineSyntax | Syntax error with Flex Config CLI line: {0} | |||
Validation | identityRealmNullDirectoryConfig | No directory configuration defined for the realm. | |||
Validation | AnyConnPrefillUsernameFromCertificateNotEnabled | Please enable PrefillUsernameFromCertificate to update DisablePrefilledUsernameEdit. | |||
Validation | invalidIPAddressRange | DHCP server IP address range is invalid | |||
Validation | objectNat46PrivateIpv4IsNotAllowedWithNat46WellKnownPrefix | The private IPv4 address "{1}" in original address "{0}" is not allowed with the well known NAT64 prefix "64:ff9b::" in the translated address | |||
Validation | acRuleDupUrlCat | More than one URL matcher is specified for URL category {0} | |||
Validation | aceLogIntervalNull | The log interval cannot be set to null when the logging option is enabled. | |||
Validation | haFullDeploymentNeeded | Before attempting {0}, all pending changes need to be deployed. | |||
Validation | sameIPGateway | IP address and Gateway cannot be same | |||
Validation | SecurityIntelligenceNetworkPolicyMoreThanOne | Cannot have more than one Security Intelligence Network Policy. | |||
Validation | backupDoesNotExist | Backup does not exist. | |||
Validation | invalidStateName | Invalid State name | |||
Validation | invalidSpecialRealmId | Invalid Special Realm creation operation | |||
Validation | authTokenContainSpecialChar | The registration key is invalid. | |||
Validation | s2sNoIkev1RemoteAnyNetwork | For IKEv1 connections, specific local networks with a remote network spanning the entire IP address space is not allowed | |||
Validation | objectNatDestIntfIpv6DisabledWithIpv6InTransNetwork | Destination interface "{0}" is not IPv6 enabled. You cannot use IPv6 addresses in the translated network | |||
Validation | invalidSmartCliLineSyntax | Syntax error with Smart CLI line: {0} | |||
Validation | sruUpdateError_5 | The system could not download the update file. Please try again later. | |||
Validation | invalidRetryInterval | Retry interval has to be in the range {0} and {1} | |||
Validation | InvalidBgpNeighborMigrationLocalAsBgpAsNumber | Cannot have local-as number same as BGP AS number. | |||
Validation | mgmtIPandGatewayNotSameSubnet | The gateway {1} is not in the same subnet defined by the management address, {0}/{2}. The management and gateway addresses must be in the same subnet. | |||
Validation | monitoredInterfaceCannotBeShutdown | Cannot disable HA monitored interface on this platform. Please remove interface monitoring, perform deploy and then disable the interface. | |||
Validation | DHCPServerSecondaryDNSOnly | DHCP server secondary DNS server cannot be specified unless a primary DNS server is also specified | |||
Validation | multicastAddressNotAllowed | The IP address cannot be a multicast address. | |||
Validation | invalidIpv4Address | Invalid IPv4 address | |||
Validation | licensingJobInProgress | License registration is in progress. Please try after some time | |||
Validation | interfaceInDHCPServerContainer | The interface {0} is already configured as DHCP auto configuration. You must remove it before adding the interface to a bridge group | |||
Validation | AnyConnIdleTimeoutInvalid | AnyConnect idle timeout must be 1-35791394 minutes | |||
Validation | vdbUpdateError_5 | The system could not download the update file. Please try again later. | |||
Validation | bridgeGroupInterfaceMemberIsMgmtOnly | Management interface {0} cannot be Bridge Group member interface | |||
Validation | identityRealmDuplicateAD | There is already an AD configured with the Hostname {0} and Port {1} | |||
Validation | invalidSmartCliAccessListValue | {0} entity value must be an existing Standard or Extended Access List Object | |||
Validation | s2sAnyNetworkOneProfile | Only one Site-to-Site VPN profile can exist if local and remote networks are both unset in a profile | |||
Validation | invalidSmartCliNumericValue | {0} value is not a valid integer | |||
Validation | invalidLineConfiguration | Line is not correctly configured. Please check the qualifiedPath and selfId values. | |||
Validation | manualNatPortNotAllowedWithDnsEnabled | You cannot enable DNS reply with port translation in a manual NAT rule | |||
Validation | newInstanceWithMetadata | Validation failed, attempting to create an object with pre-populated metadata | |||
Validation | invalidMalwareLicense | Malware license is not enabled | |||
Validation | invalidPerAccessListLoggingValues | When the logging option is set to per access list, the log level and log interval may not be null. | |||
Validation | staticRouteInconsistentGatewayProtocol | Static route inconsistent protocol version for gateway: IPv4 vs IPv6 {0} | |||
Validation | invalidFTSFilterValue | The search filter contains an unsupported character. Supported characters are [a-z A-Z 0-9 * . , _ -]. | |||
Validation | ipsecExcessIkev2Policies | The maximum number of IKEv2 policies enabled has already been reached ({0}) | |||
Validation | s2sOverlapNetworks | Site-to-Site profile {0} has overlapping local and remote network address space with profile {1} | |||
Validation | geoUpdateError_6 | The latest GeoDB update is already installed | |||
Validation | invalidQualifierText | "{0}" is not a valid qualifier. Quailifier text can optionally begin with a forward slash followed by one or more alphabets, numbers, or underscore. | |||
Validation | linaUnableToResolveHostname | Unable to resolve the hostname {0} to an IP Address | |||
Validation | DHCPServerAutoConfigName | This interface is being used for DHCP auto configuration. You cannot remove the interface name until you change the DHCP server auto configuration settings. | |||
Validation | InvalidCountryContinentSelection | Validation failed. You cannot include country "{0}" because continent "{1}" is already included. | |||
Validation | acRuleCannotHaveMultipleModes | You cannot use security zone of different modes in a rule. | |||
Validation | invalidOspfLsaTimers | Incorrect LSA timer configuration, expected initial-delay <= min-delay <= max-delay | |||
Validation | bridgeGroupInterfaceIsOutsideInterfaceInAnyConnectProfile | The interface {0} selected as outside interface in AnyConnectProfile {1} | |||
Validation | manualNatDest66HostInOrigDestNotAllowedWithSubnetInTransDest | The IPv6 host object "{1}" in the original destination is not allowed with an IPv6 subnet object "{0}" in the translated destination | |||
Validation | invalidOspfNeighborIPAddress | Specified neighbor IP address belongs to one of the interfaces on the device | |||
Validation | SecurityIntelligencePolicyEventLogOffWithSyslogOn | You cannot enable syslog with event log disabled | |||
Validation | vdbUpdateError_11 | Version mismatch, unable to proceed | |||
Validation | invalidHAInterface | The {0} must be a physical interface | |||
Validation | invalidActiveAuthPort | Invalid port for Active Auth. Port must be either 855 or in the 1025-65535 range | |||
Validation | missingRealmInAuthRule | No realm found in an identity Rule that uses the Auth action. | |||
Validation | notInRange | The value has to be between {0} and {1} | |||
Validation | mismatchedVersion | Another user or the system updated this object while you were editing it. Please refresh the browser page and redo your changes. | |||
Validation | invalidOspfInterfaceNoConfiguration | Configuration is not specified for the selected interface | |||
Validation | manualNatRouteLookupAndIntfInOrigDest | You cannot select the Perform Route Lookup option if you select interface for original destination | |||
Validation | acRuleSyslogOnWithEventLogOff | You cannot enable syslog with event logging disabled | |||
Validation | invalidBgpNeighborInterface | BGP Neighbor cannot have the same IP address as that of a device interface | |||
Validation | invalidOspfAreaIdLeadingZero | Numeric Area ID should be an unsigned integer without leading zeros | |||
Validation | invalidBgpNetworkManagementInterfaceConfigured | BGP is not supported on management-only interface | |||
Validation | errorWhenRunningCLI | Cannot retrieve hardware bypass information | |||
Validation | invalidTopLevelDomainName | The top-level domain must start with an alphabetic character. | |||
Validation | InvalidSSPFactoryServiceClass | Error while getting service class for a give model type {0} | |||
Validation | multicastMacAddress | Invalid MAC address. MAC address must not have the multicast bit set (The second hexadecimal digit from the left cannot be an odd number.) | |||
Validation | invalidBaseLicense | Base license is not enabled | |||
Validation | natSrcModePassive | Source interface {0} is in passive mode. You cannot use a passive mode interface in NAT rules : {1} | |||
Validation | SSLSettingProtocolVersionsNotOrdered | You cannot skip a protocol version between start and end range. Missing protocol versions are {0}. | |||
Validation | removeExistingIPFromHAInterface | Interface {0} is configured with IP addresses. You must remove the IP address configuration to use this interface for the failover or stateful failover interface. | |||
Validation | invalidSmartCliActionDependency | Operation cannot be performed due to a dependency in the object {0} | |||
Validation | bridgeGroupInterfaceReferencedInS2SVPN | The following Interfaces are used in S2S VPN configuration: {0}. This feature is not compatible with a bridge group member interface. You must remove the interfaces from the configuration before you can add them to the bridge group. | |||
Validation | staticRouteWrongInterfaceNew | There is already a static route defined for {0} on interface {1}. You must use the same interface for all static routes to this destination. | |||
Validation | invalidObjectForSupportedNetworkObjectAnnotation | Invalid object type for SupportedNetworkObject annotation. | |||
Validation | ipPoolStartEndIpNotInSameSubnet | Start and end IP address are not in the same sub-net with given sub-net prefix | |||
Validation | RaVpnAddressPoolOverlapVal | IP Address Pool {0} with range {1} has overlapping addresses with Address Pool {2} with range {3}. | |||
Validation | SyslogServerInterfaceInBridgeGroup | The interface {0} is already a member of the bridge group interface {1} and hence cannot be configured as a Syslog server | |||
Validation | invalidDupInRouteFilter | Duplicate configuration found for incoming route filter | |||
Validation | DHCPServerClient | You cannot configure DHCP server on a interface that obtains its IP address using a DHCP client | |||
Validation | invalidSmartCliStringValuePattern | {0} value does not match the pattern it uses | |||
Validation | staticRouteInterfaceModePassive | The selected interface {0} used in static route cannot be in passive mode. | |||
Validation | genericException | Error: {0} | |||
Validation | appFilterMissingUuid | The application filter should have a UUID {0}. | |||
Validation | manualNatTransSrcHasIpv6AndIpv4Addresses | The translated source network should not contain both IPv4 and IPv6 addresses | |||
Validation | invalidSmartCliBranchUsage | Branch commands are not in accordance with branching usage | |||
Validation | invalidOspfInterfaceManagementOnly | You cannot enable OSPF on management-only interfaces | |||
Validation | cannotContainDHCPIpv4Address | The interface is configured in passive mode. It cannot contain a DHCP IPV4 address. | |||
Validation | manualNatSrcIntfIsNullWithIntfInOrigDest | Source interface cannot be any if you select interface in original destination | |||
Validation | invalidNumericObjectName | The name "{0}" is invalid. The name must be an unsigned numeric value | |||
Validation | sruImportError | Failed to import Rule Update package | |||
Validation | sruUpdateError_9 | The latest Rulepack update is already installed | |||
Validation | addressDoesNotMatchNetmask | The IP Address {0} does not match with netmask {1}. To specify a network use {2}/{3}. To specify a host use {4}/255.255.255.255. | |||
Validation | bridgeGroupInterfaceMemberIpv6UnsupportedOptions | Bridge Group member interface {0} cannot turn on IPV6 options: ipv6-enabled, auto-config, suppress-RA or enable DHCP for IPv6 address and non-address configuration | |||
Validation | sruUpdateError_12 | Unable to copy installed files | |||
Validation | invalidURL | Must be a valid URL | |||
Validation | acPolicyInvalidIdentityWIthNoSSL | You cannot configure identity policy without enabling SSL policy | |||
Validation | interfaceHasSubInterfaces | You cannot configure {0} with an interface that has subinterfaces. Please edit the interface and remove subinterfaces, or select a different interface. | |||
Validation | smartAgentInitializationError | Unable to initialize Smart Agent, which communicates with the Smart Licensing server. Please reboot the system and try enabling/disabling licenses again. If the problem persists, please contact Cisco Technical Support. | |||
Validation | bgpHaNotConfigured | High availability has not been configured. | |||
Validation | s2sIkev2MaskedLocalKeyNotAllowed | Masked value for IKE-V2 pre-shared local key is not allowed with connection profile creation | |||
Validation | cannotHaveNullCertForPolicyWithRules | Cannot have a null certificate for Identity Policy which has one or more rules | |||
Validation | failedToDiscardPendingChanges | You cannot discard pending changes. The system must complete an initial successful deployment before you can have the option to discard pending changes. | |||
Validation | fileNotFound | File not Found | |||
Validation | RaVpnMaxNumberAddressPoolVal | A maximum of 6 Address Pools are allowed. | |||
Validation | invalidOspfInterfaceConflictingInterval | Hello interval({0}) must be set to a value less than Dead interval({1}) | |||
Validation | nameCannotBeNull | The interface is configured in passive mode. You must provide a name. | |||
Validation | invalidUserTypeInRule | The users in the rule should be of type TrafficUserEntry or TrafficGroupEntry | |||
Validation | invalidNetworkSubtypeForIdentityRuleDestination | The identity rule destination criteria contains a network object of an unsupported type. | |||
Validation | lockTimeout | Unable to acquire the read-lock due to timeout | |||
Validation | cannotCreateHardwareBypassPairs | Cannot create hardware bypass Pair. | |||
Validation | objectNatDestIntfIsNullWithIntfInTransNetwork | Destination interface cannot be "any" if you select Interface for translated network | |||
Validation | SslRulesWithDeletedCategories | Some of the SSL decryption rules refer to deleted URL Categories. Number of SSL decryption rules affected: {0}. | |||
Validation | noSpaceAllowOnName | The logical name cannot contain any spaces | |||
Validation | s2sInvalidNetworks | Profile cannot have strictly {0} local networks and {1} remote networks | |||
Validation | invalidFlexCliBlockNotFound | Referenced block {0} is not found | |||
Validation | invalidThreatLicense | Threat license is not enabled | |||
Validation | PullDiskSpaceNotAvailable | Disk space is not available | |||
Validation | invalidServerSecretKey | The server secret key is invalid. It can contain the special characters: $, &, -, _, ., +, @ but should not contain spaces. | |||
Validation | identitySourceIDIsNullOrEmpty | The identity source ID cannot be null or empty | |||
Validation | ipsecCombinedModeNullIntegrity | Combined mode encryption must be used with solely null integrity type because combined modes internally set integrity type | |||
Validation | manualNatSrc46DynamicNotAllowed | Dynamic NAT is not allowed in a manual NAT rule for IPv4 to IPv6 source address translation | |||
Validation | invalidOrMissingUserRole | No user role could be obtained from identity source response for external user. | |||
Validation | fqdnIdAssignmentFailure | Unable to assign the FQDN ID to the FQDN network object. | |||
Validation | invalidLicenseForObject | Missing license for object: {0} requires the {1} license | |||
Validation | cannotRestoreInHAMode | You cannot restore a backup while the device is part of a high availability group. Please break HA and then perform the restore operation. | |||
Validation | staticRouteDupNetworkValue | Static route duplicate network value: {0} | |||
Validation | entityNotFoundWithUuid | Failed to find DB entity of type {0} with UUID {1} | |||
Validation | invalidCountryCode | Invalid Country code | |||
Validation | cannotEditDeleteSpecialRealm | Cannot edit the Special Realm | |||
Validation | standbyIPWithoutActiveIPAddress | Standby IP Address cannot be specified without an active IP Address. | |||
Validation | interfaceReferencedInOspfNeighbor | Interface cannot be updated when referenced in OSPF neighbor. You must remove the neighbor before updating the interface. | |||
Validation | invalidLinkLocalIPAddress | The IP address "{0}" is not a link-local address | |||
Validation | s2sMoreThanOneDynamicPeer | Only one Site-to-site profile can have a dynamic peer. | |||
Validation | ipv6OverlappingSubnet | This IPv6 address exists in the subnet of the {0} interface. | |||
Validation | invalidDHCPClientInternalRouting | You must specify a static address for the management IP when you route management traffic through the data interfaces. Using DHCP client to obtain an address is not allowed. | |||
Validation | AnyconnInvalidClientPackage | AnyConnect client file uploaded is invalid {0} | |||
Validation | interfaceWithDHCPAddress | HA cannot be enabled when interface {0} has a DHCP address. | |||
Validation | invalidSmartCliCommunityListValue | {0} entity value must be an existing Standard or Expanded Community List Object | |||
Validation | RaVpnSecAuthNotValidOnCertOnly | Secondary Authentication not valid on selected Authentication method. | |||
Validation | cannotStopEval | Evaluation mode is not in use. You cannot stop evaluation mode | |||
Validation | currentAndNewPasswordCannotBeTheSame | Current and new password cannot be the same | |||
Validation | invalidOspfRedistOspfIdentifier | Identifier value {0} does not match any OSPF processes in use | |||
Validation | s2sOutsideIntfIsNullOrEmpty | Site-to-Site VPN outside-interfaces cannot be null or empty | |||
Validation | invalidV6StartCompatible | IPv4-compatible IPv6 as start address is not supported. | |||
Validation | AnyConnDnsExcess | There can only be a maximum of two servers for {0} | |||
Validation | DHCPServerIPPoolRange | The interface DHCP server address pool {0} is not on the same subnet as the interface IP address, {1}. The pool must be on the same subnet and it cannot contain the interface IP address. If you are changing the interface IP address, you must first delete the DHCP server. | |||
Validation | InvalidBgpNeighborDupRouteMapFilter | Only one route map can be configured in either direction | |||
Validation | vdbUpdateError_14 | VDB successfully updated but skipping deployment as this is a STANDBY device. | |||
Validation | invalidOspfDuplicateProcess | An OSPF process already exists with the given Process ID | |||
Validation | manualNatSrc46PrivateIpv4IsNotAllowedWithNat46WellKnownPrefix | The private IPv4 address "{1}" in original source "{0}" is not allowed with the well known NAT64 prefix "64:ff9b::" in the translated source | |||
Validation | geoUpdateError_5 | The system could not download the update file. Please try again later. | |||
Validation | invalidDefaultLoggingValues | When the logging option is set to default, the log level and log interval must be null. | |||
Validation | invalidAction | Invalid Action {0} | |||
Validation | incompatibleTypes | ICMP Code and Type are not compatible. | |||
Validation | ipsecPolicyNeedGroup | Policy must have at least one DH group | |||
Validation | adiCliTestTimedout | The connection test timed out. | |||
Validation | passwordTooShort | Password is too short. The password needs to be at least 8 characters long | |||
Validation | smartCliUpgradeFailed | SmartCLI upgrade failed due to a system error, please contact the support. | |||
Validation | blacklistedFlexConfigPolicy | There are FlexConfig objects in the FlexConfig policy that include blacklisted commands. You must either remove the blacklisted commands from the objects, or remove the objects from the policy, before you can add new Smart CLI objects. | |||
Validation | interfaceWithPassiveMode | You cannot use an interface in passive mode for HA configuration. | |||
Validation | InvalidPeerHoldTime | You cannot enter a hold time value that is less than 3 times the peer poll time | |||
Validation | s2sOverlapChosenNetworks | Site-to-site profile has {0} network objects that have overlapping address space: {1}, {2} | |||
Validation | invalidFileName | The filename is invalid | |||
Validation | acPolicySyslogOnWithEventLogOff | You cannot specify a syslog server because connection logging is disabled. | |||
Validation | ipsecPolicyNeedEncryption | Policy must have at least one encryption method | |||
Validation | invalidPublicKey | Public key is not valid | |||
Validation | invalidSpeedDuplexPair | You cannot select 1000 or 10000 Mbps when Duplex is "Half" | |||
Validation | subIntfReuseDupVlanId | VLAN ID {0} is already deployed on sub-interface {1} which is being deleted or modified. Please deploy current changes before re-using this VLAN ID. | |||
Validation | acRuleDestTcpProtocolNotAllowedWithTcpDestPort | You cannot add a destination TCP protocol object with destination TCP ports: {0} | |||
Validation | acRuleProtocolNotAllowedInSrcPorts | A protocol object is not allowed in the source ports field: {0} | |||
Validation | upgradeFileNotFoundOnDisk | Upgrade file not found on disk. | |||
Validation | unknownHostName | Could not determine device hostname. | |||
Validation | uncommitedChanges | You must deploy all uncommited changes before starting a system upgrade. | |||
Validation | fqdnIdNotAvailable | All FQDN IDs have been assigned. | |||
Validation | noBaseLicense | Cannot add a license when the base license is not present | |||
Validation | invalidAuthenticationPort | Authentication port has to be in the range {0} and {1} | |||
Validation | AnyConnOutsideCannotBePassive | The interface {0} added to AnyConnectProfile is invalid, the outside interface cannot be in passive mode | |||
Validation | RangeInvalidEnd | Invalid End Address | |||
Validation | manualNatStaticTransSrcNotNullAndIntfInTransSrcIsTrue | You cannot select both a translated address and interface for the translated address in static NAT | |||
Validation | invalidSmartCliStandardAccessListValue | {0} entity value must be an existing Standard Access List Object | |||
Validation | invalidConnectionTypeUpdate | This is an invalid type for updating. Please specify the type as Registration if trying to go from Eval mode to Registered mode | |||
Validation | SecurityIntelligenceExceededMaxURLListSize | The combined number of entries in the URL whitelist and blacklist cannot exceed 32767. | |||
Validation | ipsecNoEnabledIkev2Policies | Cannot disable or delete IKEv2 policy, need at least one policy active while a site-to-site connection profile using IKEv2 exists | |||
Validation | objectNatOrigNetworkIsNull | You must specify an original address in an auto NAT rule | |||
Validation | invalidFlexCliUnsupportedVariableType | {0} is not a supported variable type | |||
Validation | s2sCryptoRestrictedIkev1Proposals | S2S VPN uses IKE-V1 proposal(s) with strong encryption, which is not allowed by your licensing setting. Please use DES only | |||
Validation | s2sIkev2ProposalsEmpty | IKE-V2 proposals cannot be null or empty | |||
Validation | staticRouteNoNetworks | Static route should have at least one network | |||
Validation | manualNatSrc64AnyIpv6NotValid | The network corresponding to the full range of IPv6 addresses, i.e. ::/0, cannot be used in the source of an IPv6 to IPv4 manual NAT rule | |||
Validation | invalidVariableName | The name "{0}" is invalid. The name can start with an alphanumeric character or an underscore. It can contain the special characters +, _ and - | |||
Validation | PullUpgradeFailed | Pull Upgrade job failed | |||
Validation | s2sIkev1ProposalsTooMany | Too many IKE-V1 proposals. Number of assigned IKE-V1 proposals cannot exceed {0} | |||
Validation | ruleUrlCatStateDeleted | {0} rule must not contain an URL Category whose state is DELETED. | |||
Validation | PullValidationStarted | Upgrade installer file download is complete. Now validating the downloaded file. | |||
Validation | mismatchedOrdinal | Ordinal should remain same on update | |||
Validation | invalidSmartCliNumericMinValue | {0} value cannot be less than {1} | |||
Validation | s2sOutsideIntfCannotBeBviMember | Outside interface cannot be a bridge-group member: {0} | |||
Validation | AccessRulesWithDeprecatedCategories | Some of the access rules refer to deprecated URL Categories. Number of access rules affected: {0} | |||
Validation | acRuleDestTcpPortWithOtherSrcPort | When you specify destination TCP ports, the source ports should either be empty or contain at least one TCP port | |||
Validation | nestedReferenceCircle | A circular reference is found between nested entity {0} and {1} | |||
Validation | invalidUmbrellaDnsServerGroup | You cannot change the name or DNS server IP addresses in the system-defined CiscoUmbrellaDNSServerGroup object. | |||
Validation | InvalidBgpNeighborDupAccessListFilter | Only one access list can be configured in either direction | |||
Validation | s2sIkev2InvalidRemoteKey | Invalid IKE-V2 pre-shared remote key. It must contain 1 to 128 ASCII printable characters, no whitespace, no single or double quotation marks,no question marks and cannot be a single digit | |||
Validation | aaaUpdatingName | Updating the name for a rule is not supported | |||
Validation | acRuleLogEndNotAllowedWithDeny | You cannot log at the end of connection only if the access rule action is Block. | |||
Validation | SSLPolicyNoDecryptCAForResign | You must identify an internal CA certificate to use for decrypt re-sign rules in the SSL decryption policy | |||
Validation | cryptoCompliantS2SIkev1Proposal | The S2S VPN connection profile {0} is using IKE-V1 proposals with strong encryption which is not allowed by your licensing setting, please de-reference them and use DES only: {1} | |||
Validation | bridgeGroupInterfaceReferencedInSyslogServer | The following Interfaces are used in Syslog configuration: {0}. This feature is not compatible with a bridge group member interface. You must remove the interfaces from the configuration before you can add them to the bridge group. | |||
Validation | invalidV6EndMapped | IPv4-mapped IPv6 as end address is not supported. | |||
Validation | AnyConnInsideCannotBePassive | The interface {0} added to AnyConnectProfile is invalid, the inside interface cannot be in passive mode | |||
Validation | ConfigErrors | There are some configuration errors. Please fix them, deploy the configuration, and proceed with the upgrade. Check the pending changes for items that might need attention. | |||
Validation | webCertAlreadyExists | A Web Server Certificate already exists. | |||
Validation | invalidInterfaceForRouteMapEntry | A route map cannot include passive interfaces or bridge group member interfaces or an interface which is part of the high availability configuration. | |||
Validation | invalidOspfInterfaceEnabled | Selected Interface is enabled. | |||
Validation | manualNatDnsNotAllowedWithDest | You cannot enable DNS reply translation when doing destination address translation | |||
Validation | sruUpdateError_11 | Not enough disk space on root/Volume | |||
Validation | useHostForSingleAddress | Use Host to specify a single address. | |||
Validation | invalidLowercaseObjectName | The name "{0}" is invalid. The name can start with an alphanumeric lowercase character or an underscore. It can contain the special characters +, ., _ and - | |||
Validation | manualNatSrc66HostInTransSrcNotAllowedWithSubnetInOrigSrc | The IPv6 host object "{1}" in the translated source is not allowed with an IPv6 subnet object "{0}" in the original source | |||
Validation | parentInterfaceIsPassive | You cannot create a subinterface on the Passive interface {0} | |||
Validation | adiCliTestUnknownFailure | The connection test failed with an unknown error. | |||
Validation | invalidKey | Invalid key. | |||
Validation | appFilterInvalidCatValue | Invalid application filter category value {0}. | |||
Validation | vpnConnProfileNameIsIpAddress | VPN connection profile name must not be an IP-V4 or IP-V6 address value | |||
Validation | linkLocalIPAddressNotAllowed | The IP address {0} cannot be a link-local address | |||
Validation | manualNatStaticRuleEmpty | No network or port translation is specified with static NAT rule | |||
Validation | cannotConfigureIPv6Address | The interface is configured in passive mode. You cannot configure an IP v6 address on passive interface. | |||
Validation | invalidNetworkSubtypeForPolicy | Policy contains network-object of un-supported sub-types. | |||
Validation | appFilterDupProductivity | Duplicated business relevance selected: {0} | |||
Validation | nullAuthToken | The registration key is mandatory. | |||
Validation | RaVpnConnProfOnlyRadiusSupported | Only RADIUS Identity source is supported. | |||
Validation | deleteDepStatusObj | Cannot delete on-going Deployment Status object: {0} | |||
Validation | aaaUsernameCannotContainSpaces | Username cannot contain spaces | |||
Validation | aaaUpdatingProtocolType | Updating the protocol type for a rule is not supported | |||
Validation | passwordNoNumber | Password does not contain a number | |||
Validation | staticRouteWrongNetworkType | Wrong network type for static route: {0} | |||
Validation | InvalidOutsideInterface | Invalid outside interface selected. Default outside interface cannot be changed. | |||
Validation | loopbackAddressNotAllowed | The IP address cannot be a loopback address. | |||
Validation | DeviceSetupAlreadyDone | The initial device setup is complete. You can now manage the device and change the configuration. | |||
Validation | AnyConnACPkgInvalid | AnyConnect client package {0} is invalid for the given platform | |||
Validation | invalidOspfNeighborInterfaceNonBroadcast | Interface {0} network type must be point-to-point non-broadcast | |||
Validation | acRuleUrlCatRepBothNull | URL category and reputation are both any or null in one of the URL matchers | |||
Validation | aaaInvalidUsernameLength | Username is too long. The username must be less than 128 characters long | |||
Validation | invalidUuid | Validation failed due to an invalid UUID: "{0}" | |||
Validation | AnyConnDuplicateFileObj | Cannot create another AnyConnectPackageFile object for platform {0} | |||
Validation | invalidHAFailoverInterfacePollTime | Interface poll time must be between 500 and 999 milliseconds, or 1 and 15 seconds. | |||
Validation | ipv6SubnetOverlap | The prefix of IP address {0} overlaps with the prefix of the reserved range {1}, please use a higher prefix value or change the address. | |||
Validation | duplicateSyslogServerIPAddress | Two Syslog Servers cannot have same IPAddress. Duplicate IPAddress: {0} | |||
Validation | contextStatusFailed | Could not retrieve device registration context status. Please try again later. | |||
Validation | natDynamicRuleNotSupportNoProxyArp | Dynamic NAT does not support the Do Not Proxy ARP option | |||
Validation | subInterfaceNotAllowed | The interface is configured in passive mode. You cannot create subinterfaces on a passive interface. | |||
Validation | geoUpdateError_9 | GeoDB installation failure | |||
Validation | manualNatOrigDestHasIpv6AndIpv4Addresses | The original destination network should not contain both IPv4 and IPv6 addresses | |||
Validation | vdbUpdateError_9 | VDB Installation Failure | |||
Validation | invalidInterface | Management interface {0} is not allowed in security zones | |||
Validation | ipv6OptionsCannotBeTrue | The interface {0} is configured in passive mode. You cannot turn on IPV6 options: ipv6-enabled, auto-config, suppress-RA or enable DHCP for IPv6 address and non-address configuration. | |||
Validation | manualNatSrc46AnyIpv6NotValid | The network corresponding to the full range of IPv6 addresses, i.e. ::/0, cannot be used in the source of an IPv4 to IPv6 manual NAT rule | |||
Validation | ipsecNoEnabledIkev1Policies | Cannot disable or delete IKEv1 policy, need at least one policy active while a site-to-site connection profile using IKEv1 exists | |||
Validation | acRuleUnnamedInterfaceInDestZone | Destination security zone {0} contains an un-named interface that cannot be used in an access rule | |||
Validation | passwordCannotBeNull | Password field cannot be null | |||
Validation | AnyConnProxyExceptListTooLong | All addresses and ports in the proxy exception list combined can be no more than 255 characters | |||
Validation | notCryptoCompliant | Current license settings do not allow use of strong cryptography for VPN | |||
Validation | manualNatTransSrcIsNullAndIntfInTransSrcIsFalse | You must specify an address or interface for the translated address | |||
Validation | newInstanceWithInitializedId | Validation failed, attempting to create a new object with initialized ID | |||
Validation | acPolicyInvalidIdentityPolicyWithDisabledRealm | You cannot configure the identity policy with a disabled realm. | |||
Validation | AnyConnIOErrorXMLFile | {0} error while reading file. | |||
Validation | emptyKeyString | Key String cannot be empty. | |||
Validation | acRuleFilePolicyInvalidAction | The selected access rule action is invalid. You must select the Allow action for a rule that uses a file or intrusion policy | |||
Validation | internalCertValidationError | There was an error validating the Internal Certificate. | |||
Validation | s2sNoIkev1LocalAnyNetwork | For IKEv1 connections, a local network spanning the entire IP address space with specific remote networks is not allowed | |||
Validation | RaVpnGroupPolicyDeleteDefaultGP | Default Group Policy (DfltGrpPolicy) cannot be deleted. | |||
Validation | DNGroupDupDN | Group contains duplicate distinguished name objects | |||
Validation | invalidFlexCliLineBlacklist | Blacklisted cli error: {0} | |||
Validation | updateEasysetupStatusWithoutEula | The End User License Agreement has not been accepted, unable to update easy setup status | |||
Validation | certKeyTypeEmpty | You must specify whether this file is a certificate or key. Please set the fileType to cert or key. | |||
Validation | SSLSettingInvalidDHGroup | Invalid Diffie Hellman Group assigned. Valid values are GROUP_2, GROUP_5, GROUP_14 and GROUP_24. | |||
Validation | manualNatSrc46Ipv6HostObjNotAllowedInTransSrc | You cannot use an IPv6 host network object as the translated source in an IPv4 to IPv6 manual NAT source translation rule: {0} | |||
Validation | InvalidBgpNeighborMigrationRemoteAsBgpAsNumber | Cannot have remote-as number same as BGP AS number. | |||
Validation | initialDeploymentNotPerformed | You must deploy changes at least once before you can upgrade the system software. | |||
Validation | vdbUpdateError_2 | No valid support contract found. Contact sales or support for more information | |||
Validation | natOrigMappedPortsAreNotBothTcpOrBothUdp | The original and translated ports should be either both TCP ports or both UDP ports | |||
Validation | invalidOspfVirtualLinkRouterId | Multiple peer router id values specified for the same virtual link | |||
Validation | duplicateZone | Selected interface is already assigned to security zone {0} | |||
Validation | variablesetmodify | Cannot add a new or delete an existing variable. | |||
Validation | ipAddressRangeIsBlocked | The IP address {0} is part of an internally reserved range, (from={1} to={2}), please choose an address outside this range. | |||
Validation | deleteUmbrellaDnsServerGroup | You cannot delete the system-defined CiscoUmbrellaDNSServerGroup object. | |||
Validation | invalidSmartCliStringValueChar | {0} value cannot contain spaces or reserved characters | |||
Validation | adiCliTestCannotReachMQ | The connection test failed because ADI is not reachable. | |||
Validation | passwordDictWord | Password contains a dictionary word | |||
Validation | onlyStandardOrExtendedAccessList | The list should contain either all Standard Access List objects or all Extended Access List objects | |||
Validation | invalidNetworkSubtypeForSecIntelligencePolicyWhiteList | The Security Intelligence whitelist contains a network object of an unsupported type. | |||
Validation | appFilterInvalidCatName | Invalid application filter category name {0}. | |||
Validation | objectNat46Ipv6HostObjNotAllowedInTransAddr | You cannot use an IPv6 host network object as the translated address in an IPv4 to IPv6 auto NAT rule: {0} | |||
Validation | manualNatDest64PrivateIpv4IsNotAllowedWithNat46WellKnownPrefix | The private IPv4 address "{1}" in translated destination "{0}" is not allowed with the well known NAT64 prefix "64:ff9b::" in the original destination | |||
Validation | s2sOutsideIntfIsPassive | You cannot use a passive mode interface for the outside interface of a site-to-site VPN connection. | |||
Validation | acRuleMixedIpv4v6AddressInDestNetworks | Destination networks contain both IPv4 and IPv6 addresses | |||
Validation | manualNatOrigDestNotNullAndIntfInOrigDestIsTrue | You cannot select both an address and interface for the original destination | |||
Validation | policyRuleIdNotEditable | The policy rule ID cannot be modified by editing the rule. Current rule-ID in the DB is {0}, rule-ID from request is {1} | |||
Validation | AnyConnNoCAServerCert | CA Server certificate is required | |||
Validation | invalidOspfAreaTypeVLConfiguration | Virtual link cannot be configured on areas of type NSSA or Stub | |||
Validation | RangeInvalidStart | Invalid Start Address | |||
Validation | invalidSpeedCapability | The interface does not support this speed | |||
Validation | cryptoCompliantSSLCipher | The Data SSL Cipher Setting is using SSL ciphers with strong encryption which is not allowed by your licensing setting, please de-reference them. | |||
Validation | manualNatDest46Ipv6HostCountTooHigh | The IPv6 host count {0} in the translated destination exceeds the maximum allowed {1} in an IPv4 to IPv6 manual NAT destination translation | |||
Validation | invalidLoggingListProvideStartId | Please provide message start ID. | |||
Validation | geoUpdateError_1 | Unable to connect to update server | |||
Validation | manualNatDest64Ipv6RangeObjNotAllowedInOrigDest | You cannot use an IPv6 range network object as the original destination in an IPv6 to IPv4 manual NAT destination translation rule: {0} | |||
Validation | invalidHoldTimeKeepAliveTime | The keep alive time and hold time values must either both be zero, or both non-zero. You cannot have zero for one and non-zero for the other. | |||
Validation | contextDeletionSucceed | Device has been unregistered. | |||
Validation | deployPackageNotFound | You must first deploy the configuration before you can restore a backup | |||
Validation | invalidSyslogProtocol | Invalid protocol for Syslog Server. Protocol must be either TCP/UDP. | |||
Validation | attemptToChangeNoneditSubInterfaceId | Validation failed, attempt to change a non-editable subinterface ID | |||
Validation | invalidQualifiedPath | "{0}" is not a valid qualified path. A quailified path must resemble a file path beginning with a forward slash and can have alphabets, numbers, underscore, or forward slash. | |||
Validation | invalidSmartCliNumericMaxValue | {0} value cannot be greater than {1} | |||
Validation | natNotSupportedNetworkObjects | You cannot use FQDN or IP-Range network objects in the NAT rule. | |||
Validation | cannotEditIPOfBridgeGroupInterfaceMember | Interface {0} is a member of BridgeGroup Interface {1}. You cannot edit ip address for Interface {0} | |||
Validation | acRuleSrcTcpPortWithOtherDestPort | When you specify source TCP ports, the destination ports should either be empty or contain at least one TCP port | |||
Validation | invalidOspfInterfaceBviSelected | You cannot enable OSPF on a bridge group or bridge group member interface. | |||
Validation | s2sOutsideIntfNotNamed | Site-to-Site VPN outside-interface does not have logical name: {0} | |||
Validation | RaVpnConnectionProfileExists | There is one or more RAVPN Connection Profile(s) still on the device. Please remove all of them before removing RAVPN configuration. | |||
Validation | modeMisMatch | The mode for interface {0} does not match the mode of the security zone {1}. | |||
Validation | s2sPfsNoGroup1 | Diffie-Hellman group 1 can no longer be used for Perfect Forward Secrecy | |||
Validation | invalidTemplate | The template "{0}" is invalid. The name can start with an alphanumeric character or an underscore. It can contain the special characters +, ., _, -, '{{', and '}}' | |||
Validation | manualNatDest64Ipv6PrefixTooLong | The original destination IPv6 network prefix length must be less than or equal to 96 in an IPv6 to IPv4 manual NAT destination translation rule: {0}({1}) | |||
Validation | AnyConnRealmEncryptionTypeNotSupported | Realm server encryption type not supported by AnyConnect. | |||
Validation | RaVpnConnProfUserNameSettingsNotSupported | Username Settings are not supported for this Authentication Type of AAA only | |||
Validation | acRuleUnnamedInterfaceInSourceZone | Source security zone {0} contains an un-named interface that cannot be used in an access rule | |||
Validation | invalidLineInstance | Instance does not match with the template it uses. Found mismatch in the properties "{0}" of Line having selfQualifier "{1}". | |||
Validation | invalidHAFailoverPeerPollTime | Peer poll time must be between 200 and 999 milliseconds, or 1 and 15 seconds. | |||
Validation | routeMetricIsOutOfRange | The Route Metric must be between 1 and 255 | |||
Validation | diagIntfMgmtIntfIpv6 | You cannot configure the same IPv6 address for the management interface and the diagnostic physical interface. | |||
Validation | ipsecGroup1Removed | Diffie-Hellman group 1 can no longer be used in IKE v1 or v2 policies | |||
Validation | DHCPServerAutoConfigInterface | DHCP server auto config requires a default interface | |||
Validation | invalidServerSecretKeyLength | The server secret key exceeds the length limit, which is 64 characters. | |||
Validation | AnyConnAuthMethodMustBeAAAAndClientCertificate | Auth method must be {0} for Prefill username from certificate on user login window | |||
Validation | sruUpdateError_4 | Error downloading rule update, file is corrupt (MD5 does not match). Please contact technical support | |||
Validation | numberofinterfacesDoNotMatch | The number of interfaces in Lina do not match with the number in SSP | |||
Validation | moreThanOneISE | You cannot create more than one ISE configuration | |||
Validation | CryptoRestrictedSSLCipher | Data SSL Cipher Settings uses SSL Ciphers with strong encryption, which is not allowed by your licensing setting. | |||
Validation | geoUpdateError_7 | Peer certificate cannot be authenticated with known CA certificates | |||
Validation | SSLPolicyNoKeysForKnownKey | You must identify at least one internal certificate to configure decrypt known-key rules in the SSL decryption policy | |||
Validation | sruUpdateError_10 | 3D version mismatch, unable to proceed with installation | |||
Validation | invalidBgpNetworkBridgeGroupInterface | A Bridge group interface was configured for the same network. BGP cannot be configured on BVI interfaces. | |||
Validation | invalidSmartCliPrefixListValue | {0} entity value must be an existing IPv4 or IPv6 Prefix List Object | |||
Validation | acPolicyDefaultActionIsNull | The access policy default action setting is null | |||
Validation | containsInvalidChar | the field cannot contain the following character ';' | |||
Validation | manualNatSrc64Ipv6PrefixTooShort | The original source IPv6 network prefix length must be greater than or equal to 64 in an IPv6 to IPv4 manual NAT source translation: {0} | |||
Validation | encProtocolCannotBeNullWithCert | A certificate has been provided but no encryption protocol has not been provided | |||
Validation | invalidV6Mapped | IPv4-mapped IPv6 addresses are not supported. | |||
Validation | natDestinationModePassive | Destination interface {0} is in passive mode. You cannot a use passive mode interface in NAT rules : {1} | |||
Validation | invalidSmartCliBooleanValue | {0} value must be set to either true or false | |||
Validation | anyIPWithoutPrefix | The IP address requires a prefix. | |||
Validation | invalidFlexCliUnsupportedAsciiText | Non-printable ASCII text detected. If you are using copy/paste, some hidden ASCII characters might be included. Please try a different source editor, or type in the required text | |||
Validation | acRuleInvalidRiskReputation | You must specify a valid reputation | |||
Validation | dadIsOutOfRange | DAD (Duplication Address Detection) attempts must be between 0 and 600 | |||
Validation | removedInterfaceCannotBeEnabled | Interface {0} is no longer present and cannot be enabled | |||
Validation | s2sPfsGroupNotValidIkev1 | Only PFS groups 2 or 5 can be used with IKEv1 enabled | |||
Validation | nestedNetworkGroupMaxNestingLevel | This network group has more than 10 levels of nested objects, which is the maximum allowed nesting level. | |||
Validation | AnyConnAddressPoolTooBig | {0} address pool is too large, {1} contains more than 16384 addresses | |||
Validation | bridgeGroupInterfaceMemberEmptyName | Bridge Group interface member {0} cannot have empty name | |||
Validation | ipsecPolicyNeedIntegrity | Policy must have at least one integrity checking method | |||
Validation | AnyConnDnsInvalid | {0} is not a valid IP and not a valid DNS server | |||
Validation | interfaceNameEmptyForMonitoring | You can monitor an interface only if the interface has a name. | |||
Validation | cannotCreateOrEditLDAPRealm | Cannot create or edit LDAP Realm | |||
Validation | objectNatStaticTransNetNotNullAndIntfInTransNetIsTrue | You cannot select both a translated address and interface for the translated address in static NAT | |||
Validation | invalidGatewayForInternalRouting | You cannot specify a gateway when you are routing management traffic through the data interfaces. | |||
Validation | AnyConnOverlapNetworks | Address pool {0} has address space overlap with the selected inside networks | |||
Validation | cannotCreateBaseLicense | The base license cannot be created | |||
Validation | sruUpdateError_7 | Peer certificate cannot be authenticated with known CA certificates | |||
Validation | bgpGracefulRestartTimeWithoutGracefulRestart | Graceful restart should be enabled before setting restart time | |||
Validation | portNotExpected | The protocol type selected does not require a port. | |||
Validation | fileMalwareSyslogServerRequired | File malware syslog server is required. | |||
Validation | broadcastAddressNotAllowed | You cannot assign a broadcast address as the IP address of an interface. | |||
Validation | invalidLoggingListInvalidOPtions | Please provide either message ID or class. | |||
Validation | attemptToChangeNoneditHardwareName | Validation failed, attempt to change a non-editable name | |||
Validation | invalidAAARadiusMaxFailedAttempts | Max Failed Attempts must be in the range 1 to 5 | |||
Validation | invalidSmartCliStringValuePatternAnnotation | {0} value does not match the pattern it uses | |||
Validation | invalidRAVPNUsernameLength | Invalid username length. Username length should be between {0} to {1} characters | |||
Validation | emptySSHAAASettingServerSecretKey | AAASetting for SSH access cannot reference a {0} that has a {1} with an empty server secret key; "{2}" contains an empty server secret key | |||
Validation | nullValue | Value cannot be null. | |||
Validation | ipsecCryptoRestricted | Usable cryptography types are currently restricted by the licensing status of the device | |||
Validation | haMandatoryDeploymentNeeded | Before attempting {0}, you must complete a successful deployment job. | |||
Validation | dnsServersMaximumLimit | A maximum of two IPv4 and two IPv6 DNS servers is allowed. | |||
Validation | addressDoesNotMatchPrefixLength | The IP Address {0} does not match with the prefix length {1}. To specify a network use {2}/{3}. To specify a host use {4}. | |||
Validation | failedToExportConfig | You cannot export the configuration at this time. The system must complete an initial successful deployment before you can export the configuration. | |||
Validation | invalidSmartCliASPathValue | {0} entity value must be an existing ASPath Object | |||
Validation | invalidObjectName | The name "{0}" is invalid. The name can start with an alphanumeric character or an underscore. It can contain the special characters +, ., _ and - | |||
Validation | DHCPServerAutoConfigServer | You cannot define a DHCP server on the same interface used for the auto config default interface: {0} | |||
Validation | invalidFlexCliTemplate | Template could not be resolved. {0} | |||
Validation | manualNatRouteLookupAndIntfInTransSrc | You cannot select the Perform Route Lookup option if you select interface for translated source | |||
Validation | RACPrfInsideIntfHasNoName | The interface {0} added to RaVpn should have a logical name. | |||
Validation | s2sDupRemotePeerIpAddr | Duplicate remote-peer IP-address is found, remote-peer IP address must be unique across all S2S VPN connection profiles | |||
Validation | sequenceNumberInAscending | IP prefix entries should be arranged in the ascending order of sequence number of an entry. | |||
Validation | AccessRulesWithDeletedCategories | Some of the access rules refer to deleted URL Categories. Number of access rules affected: {0}. | |||
Validation | invalidAuthType | Invalid authentication type in identity rule. Only Basic, NTLM, Negotiate and Response page methods are supported. | |||
Validation | SecurityIntelligencePolicyMoreThanOne | Cannot have more than one Security Intelligence Policy. | |||
Validation | vdbUpdateError_13 | Unable to update VDB database, please retry the update | |||
Validation | insufficientDiskSpace | Insufficient disk space. | |||
Validation | SSLRuleNullEventLogAction | You must specify an event logging action for the SSL rule | |||
Validation | ipsecDupIkev2Prf | Cannot have duplicate pseudorandom functions | |||
Validation | dupliacteTemplateIdentifier | A template with same identifier already exists. {0} | |||
Validation | interfaceInHA | This physical interface is being used in a high availability (HA) configuration. You cannot update its properties or refer to it from other policies or objects. | |||
Validation | invalidSmartCliEnumValuesNull | Allowed enum values cannot be null or empty | |||
Validation | bridgeGroupInterfaceUsedUnsupportedOptions | {0} contains unsupported options. | |||
Validation | invalidFlexCliMissingVariable | Referenced variable {0} is not configured | |||
Validation | sruUpdateError_13 | Unable to install package | |||
Validation | acRuleMixedIpv4v6AddressInSrcNetworks | Source networks contain both IPv4 and IPv6 addresses | |||
Validation | haDeploymentCouldNotAutoRecover | Could not auto-recover, check logs for details. Please retry {0} deployment. | |||
Validation | natOrigMappedPortsAreNotBothSpecified | The original and translated ports should be either both specified or both empty | |||
Validation | bgpInvalidHoldTime | Hold time should be greater than keep alive time | |||
Validation | invalidOspfInterfaceNetworkType | Network type must be point-to-point non-broadcast when OSPF neighbors are defined on this interface | |||
Validation | connectorGenerateTokenError | Connector token was not generated. | |||
Validation | bridgeGroupInterfaceInvalidCreation | Cannot create more than one Bridge Group Interface. Please delete the existing one before creating a new Bridge Group Interface. | |||
Validation | regexPatternNotUnique | Regular expression pattern should be unique across all entries. | |||
Validation | upgradeIncorrectTypeInvocation | Upgrade could not be performed because of a system error, please contact the support. | |||
Validation | userPreferenceNotFound | Cannot find User Preferences. | |||
Validation | invalidNodeId | Validation failed due to invalid node ID: {0} | |||
Validation | invalidSmartCliDependentEnabled | You cannot enable a dependent command when the parent command is disabled | |||
Validation | subinterfacesCannotContainAnotherSubinterface | A subInterface cannot contain another subInterface. | |||
Validation | conflictingFlexConfigPolicy | There are FlexConfig objects in the FlexConfig policy that include blacklisted commands. You must either remove the blacklisted commands from the objects, or remove the objects from the policy. | |||
Validation | diskFileNameIncorrectExt | Disk file name extension is not {0}: {1} | |||
Validation | invalidSmartCliIPV6PrefixListValue | {0} entity value must be an existing IPv6 Prefix List Object | |||
Validation | fileMalwareSeverityLevelRequired | File malware severity log level is required. | |||
Validation | DHCPServerNoInterfaceNetMask | The interface must have a netmask | |||
Validation | DHCPServerInterfaceModePassive | You cannot use a passive mode interface for the DHCP server default interface. | |||
Validation | createWithUuid | Validation failed, attempting to create a new object while specifying a UUID | |||
Validation | IntrusionRuleUpdateNotAllowed | You cannot change the state of a rule whose default state is Disabled | |||
Validation | acRuleSrcUdpPortWithOtherDestPort | When you specify source UDP ports, the destination ports should either be empty or contain at least one UDP port | |||
Validation | invalidFlexCliLineNull | A cli command cannot be null | |||
Validation | missingRealmInPassiveAuthIdentityRule | No realm found in an identity rule that uses the Passive Auth action. | |||
Validation | AnyConnProxyServerNull | Proxy Server Address/host cannot be null | |||
Validation | DHCPServerSecondaryWINSOnly | DHCP server secondary WINS server cannot be specified unless a primary WINS server is also specified | |||
Validation | aceDestinationEmptySourceIsNot | The destination network list cannot be empty when the source network list has entries. | |||
Validation | objectNat66HostInTransAddrNotAllowedWithSubnetInOrigAddr | The IPv6 host object "{1}" in the translated address is not allowed with an IPv6 subnet object "{0}" in the original address | |||
Validation | bgpInvalidASNumberUpdated | Cannot change as-number when editing BGP protocol | |||
Validation | deploymentInProgress | Could not initiate upgrade: deployment is in progress. Please wait for deployment to finish, then try again. | |||
Validation | blacklistedCli | Following cli's are blacklisted from the input: | |||
Validation | SSLRuleNullCertStatus | Certificate Status cannot be null | |||
Validation | invalidLoggingListRangeCollision | Message ID/range overlaps with existing range. | |||
Validation | AnyConnDnsMissing | At least one DNS has to be provided for AnyConnect VPN profile | |||
Validation | updateCertAndKey | You must update both certificate and private key. | |||
Validation | haDeploymentAutoRecovered | Successfully auto-recovered {0} deployment. | |||
Validation | invalidOspfInterfaceDuplicateConfiguration | Interface {0} has already been configured for the protocol {1} in the object {2} | |||
Validation | acPolicyInvalidDefaultActionWithNullIps | Invalid default action {0}, only Block or Trust is allowed without intrusion inspection | |||
Validation | duplicateOrdinal | Validation failed due to duplicate Ordinal | |||
Validation | showPostUpgradeDialogCannotBeTrue | The showPostUpgradeDialog value in PostUpgradeFlags cannot be set to true. | |||
Validation | s2sInsideIntfNotNamed | Site-to-Site VPN inside interface for NAT exempt does not have a logical name | |||
Validation | ipsecDupIkev2Integrity | Cannot have duplicate integrity methods | |||
Validation | passwordNoUplower | Password does not contain an upper and a lower case character | |||
Validation | invalidFlexCliNetworkValue | {0} value must be an existing NetworkObject or NetworkObjectGroup | |||
Validation | RaVpnPriSecUsernameSame | Primary and Secondary username fields cannot be the same. | |||
Validation | invalidFlexCliNumericValue | {0} value is not a valid integer | |||
Validation | containedEntityNotFoundInContainer | The contained entity to be updated is not found in the specified container | |||
Validation | invalidSmartCliObjectNameValue | {0} value must be same as the Smart CLI object name | |||
Validation | invalidV6StartMapped | IPv4-mapped IPv6 as start address is not supported. | |||
Validation | AnyConnNullRealmEncryptionType | Realm server encryption type cannot be null | |||
Validation | adiCliTestFailed | The connection test failed. | |||
Validation | bridgeGroupInterfaceReferencedInSmartCli | The following interfaces are referenced by Smart CLI: {0}. This feature is not compatible with a bridge group member interface. You must remove them before you can add the interfaces to a bridge group. | |||
Validation | unsupportedNGFWInterfaceDuplex | Unsupported NGFW Interface Duplex on SSP platform | |||
Validation | s2sCryptoRestrictedIkev2Proposals | S2S VPN uses IKE-V2 proposal(s) with strong encryption, which is not allowed by your licensing setting. Please use DES only | |||
Validation | DHCPIntfModeIsPassive | You cannot configure a DHCP server on a passive mode interface. | |||
Validation | AnyConnInvalidXMLFile | {0} is a Invalid XML file. | |||
Validation | invalidFlexCliStringValue | {0} value cannot be null or blank | |||
Validation | contextDeletionFailed | Unregistration process failed. Please try again later. | |||
Validation | BannerHasQuestionMarkChar | Banner display string cannot contain question mark character | |||
Validation | nullBgpNeighborRoutesAdvertisementInterval | Advertisement Interval can not be null. | |||
Validation | cannotHaveRealmOnTheMemberOfBVI | This interface is a member of a bridge group. You cannot use it in an identity realm configuration. | |||
Validation | AnyConnACPrfInsideIntfHasNoName | The interface {0} added to AnyConnectProfile should have a logical name. | |||
Validation | incompatibleStartEndAddress | Start and End Addresses must be the same IP type. | |||
Validation | bridgeGroupInterfaceReferencedInMgmtAccess | The following Interfaces are used in management access configuration: {0}. This feature is not compatible with a bridge group member interface. You must remove the interfaces from the configuration before you can add them to the bridge group. | |||
Validation | bridgeGroupInterfaceMemberHasIpv6Address | Bridge Group interface member {0} cannot contain IPV6 address | |||
Validation | objectNatNoInterfaceSelectedWithRouteLookup | Please specify both source and destination interfaces to enable route lookup | |||
Validation | realmIdChanged | The realm ID cannot be modified | |||
Validation | cannotBeMgmtInterface | The interface is configured in passive mode. You cannot configure it to be management interface. | |||
Validation | AnyConnOutsideIntfInDIMA | The selected outside interface is currently being used in a management access list and cannot be simultaneously used for AnyConnect VPN | |||
Validation | invalidAAARadiusGroupDeadtime | Dead Time must be between 0 and 1440 minutes | |||
Validation | invalidOspfDuplicateBackbone | A backbone area already exists in the configuration | |||
Validation | certificateKeyMismatch | Certificate and Private key do not match | |||
Validation | RaVpnGPSplitDomainsRequired | Split DNS Domains have to be specified. | |||
Validation | timeNotInRange | The time value has to be between {0} and {1} {2}. | |||
Validation | featureInfoIOException | IO Exception thrown while trying to read Feature Information | |||
Validation | vdbUpdateError_0 | VDB successfully updated | |||
Validation | ntpNotFound | Cannot find NTP settings. | |||
Validation | invalidSmartCliUnsupportedVariableType | {0} is not a supported variable type | |||
Validation | objectNat64Ipv6PrefixTooShort | The original address IPv6 network prefix length must be greater than or equal to 64 in an IPv6 to IPv4 auto NAT rule: {0} | |||
Validation | manualNatDest66TransDestPrefixShorterThanOrigDestPrefix | The IPv6 prefix of the translated destination subnet "{0}" must be greater than or equal to the IPv6 prefix of the original destination subnet "{1}" | |||
Validation | objectNat46DynamicNotAllowed | Dynamic NAT is not allowed in an auto NAT rule for IPv4 to IPv6 address translation | |||
Validation | AnyConnServerCertNeedsSubjectCommonName | The Server certificate {0} requires subject common name | |||
Validation | baseRealmDisabled | The realm used in the identity rule has been disabled. | |||
Validation | invalidSmartCliExpandedCommunityListValue | {0} entity value must be an existing Expanded Community List Object | |||
Validation | missingUuid | Validation failed due to an invalid UUID: null | |||
Validation | searchDomainNameTooLong | The domain search name in the DNS group is longer than 63 characters. The name must be shorter than 63 characters to use the group for data interfaces. | |||
Validation | vpnOnlyWithPlusOrApex | VPN-only license cannot be enabled with PLUS or APEX | |||
Validation | SSLRuleNullRuleAction | You must specify an SSL rule action | |||
Validation | invalidVariableSetInstance | Instance does not match with the template it uses. Found mismatch in the properties "{0}" of SmartCLIVariableSet having qualifiedPath "{1}". | |||
Validation | invalidPasswordCombination | You must enter both the new and old password | |||
Validation | manualNatNoDestNatWithSrcNat64 | Missing destination translation with IPv6 to IPv4 translation on source addresses | |||
Validation | staticRouteInconsistentNetworkProtocol | Static route inconsistent protocol version for network: IPv4 vs IPv6 {0} | |||
Validation | haLinkNotOnSameSubnet | The primary and secondary addresses of {0} must be on the same subnet. | |||
Validation | AnyConnExcessPackages | Can have only one AnyConnectPackages | |||
Validation | missingRealmInActiveAuthIdentityRule | No realm found in an identity rule that uses the Active Auth action. | |||
Validation | s2sNoRemotePeerIpAddr | Remote-peer IP-address can not be null in case of static peers. | |||
Validation | PullUpgradeSuccess | Pull is completed successfully | |||
Validation | manualNatSrc46Ipv4AnyIsNotAllowedWithNat46WellKnownPrefix | The original source cannot be IPv4 "any" with the well known NAT46 prefix "64:ff9b::" in the translated source | |||
Validation | mandateVlanOnNamedInterface | Interface cannot have a logical name if it has no VLAN assigned to it | |||
Validation | communityNumberNotInRange | Community number {0} should be between 1 and 4294967295 or in the format aa:nn where aa and nn are 2-byte numbers. A number from 1 to 65535 can be entered for each 2-byte number. | |||
Validation | duplicateInterfaceInList | There is already a management access list rule for this interface. Edit the existing rule. | |||
Validation | appFilterInvalidProductivityName | Invalid application filter business relevance name {0}. | |||
Validation | invalidDupOutAclRouteFilter | Only one access list is allowed per protocol process | |||
Validation | expiredCertificatePaste | The certificate has already expired. Please enter an unexpired certificate. | |||
Validation | invalidNetworkSubtypeForSecIntelligencePolicyBlackList | The Security Intelligence blacklist contains a network object of an unsupported type. | |||
Validation | SslRuleCannotHavePassiveZone | You cannot use a passive security zone in an SSL rule. | |||
Validation | IntrusionRuleNotFound | Unable to find the IntrusionRule | |||
Validation | couldNotInitializeUpgrade | Could not initiate upgrade. | |||
Validation | indexListSizeIncorrect | Error when getting the indices of the filtered container objects. | |||
Validation | identityRealmNullEncryptionCert | No encryption certificate defined for the realm | |||
Validation | sruUpdateError_1 | Connectivity problems. Unable to download the rule update. Please try again later. | |||
Validation | licenseAlreadyExists | This device already has a license of this type. You cannot have multiple licenses of the same type | |||
Validation | invalidObjectForNotHaInterfaceAnnotation | Invalid object type for NotHAInterface annotation. | |||
Validation | EmptySSLCipherSecurityLevel | You must specify one of the open SSL security level | |||
Validation | contextRetrieveFailed | Could not retrieve device registration context. Please try again later. | |||
Validation | AnyConnNotSupportedNestedNetworkGroup | You cannot use Nested network group {0} in the AnyConnectProfile {1} | |||
Validation | invalidSyncType | This is an invalid value for syncing. If you would like to sync, please set sync to be true | |||
Validation | geoUpdateError_10 | Error running GeoDB Update | |||
Validation | passwordNoSpecial | Password does not contain a special character | |||
Validation | invalidEmptyFqdn | The fully-qualified domain name is empty. Please specify a name. | |||
Validation | certTypeEmpty | Certificate Type is empty. You must specify a type. | |||
Validation | invalidOspfInerfaceIsPassive | Interface {0} cannot be passive | |||
Validation | invalidSmartCliNetworkValue | {0} entity value must be an existing NetworkObject or NetworkObjectGroup | |||
Validation | cliCommandNotSupported | This command is not supported or not recognized. Command abbreviations are not allowed. | |||
Validation | invalidInterfaceForPolicyList | A policy list cannot include passive interfaces or bridge group member interfaces or an interface which is part of the high availability configuration. | |||
Validation | DHCPServerInvalidName | DHCP server is already configured on this interface: {0} | |||
Validation | manualNatDest64DynamicNotAllowed | Dynamic NAT is not allowed in a manual NAT rule for IPv4 to IPv6 destination address translation | |||
Validation | bridgeGroupInterfaceMemberHasDHCPIpv4Address | Bridge Group interface member {0} cannot contain a DHCP IPV4 address | |||
Validation | AnyConnSplitTunnelNoInsideNet | Split tunnel functionality requires at least one inside network | |||
Validation | s2sIkev1ProposalsEmpty | IKE-V1 proposals cannot be null or empty | |||
Validation | sruUpdateUnknownError | Unknown error occurred while updating Rule Update | |||
Validation | standbyIPSameAsActiveIPAddress | Standby IP Address cannot be the same as an active IP Address. | |||
Validation | objectNatPortNotAllowedWithDynamicRule | Port translation is not allowed with dynamic auto NAT | |||
Validation | UnlockDeviceProvidedEulaIsNotCorrect | The provided End User License Agreement does not match with the End User License Agreement from the server. | |||
Validation | bridgeGroupInterfaceCannotHaveIpv6AddressOfBgpNeighbor | This IPv6 address is part of a neighbor that is being used in the BGP configuration. You cannot assign the same IPv6 address to a bridge group interface. | |||
Validation | acRuleMixedIpv4v6AddressInSrcDestNetworks | Source and destination networks contain a mix of IPv4 and IPv6 addresses | |||
Validation | natDynamicRuleNotSupportRouteLookup | Dynamic NAT does not support the Perform Route Lookup option | |||
Validation | scheduleDoesNotExist | Unable to modify a scheduled job. No pending schedule. | |||
Validation | duplicatesClasses | Duplicate classes: {0} are not allowed. | |||
Validation | invalidOspfRouterId | 0.0.0.0 is not a valid Router ID | |||
Validation | manualNatPortsNotAllTcpOrAllUdp | Manual NAT rule port references should be either all TCP ports or all UDP ports | |||
Validation | geoUpdateError_0 | GeoDB successfully installed | |||
Validation | RaVpnSpecialIdentityNotAllowed | Special-Identities-Realm not allowed as IdentitySource for RAVPN. | |||
Validation | ipsecEmptyIkev2Encryption | There must be at least one method of encryption | |||
Validation | invalidOspfInterfaceNotEnabled | Interface {0} must be enabled to configure OSPF | |||
Validation | activeAuthCertInvalidStartEndDate | The value or format of the start or end date of the uploaded certificate is invalid | |||
Validation | deprecatedApps | An application filter cannot contain deprecated applications. | |||
Validation | SSLRuleNeedVersion | Need at least one SSL/TLS version checkbox selected | |||
Validation | invalidOspfNsfMechanismRequired | You must specify the NSF mechanism to configure graceful restart | |||
Validation | emptyGroup | A group should contain at least one object. | |||
Validation | bridgeGroupInterfaceMemberHasIpv4Address | Bridge Group interface member {0} cannot contain IPV4 address | |||
Validation | ipsecNormalModeNullIntegrity | Normal encryption modes cannot be used with null integrity type, null integrity type is for combined modes | |||
Validation | invalidCliObjectName | The name "{0}" is invalid. The name can start with an alphanumeric character or an underscore. It can contain the special characters _ and - | |||
Validation | interfaceCannotHaveIpv4AddressOfBgpNeighbor | An interface cannot have the same IPv4 address as a neighbor in BGP. | |||
Validation | invalidBGPExceededLimit | Only one BGP protocol can be running in the system | |||
Validation | invalidOspfBackboneArea | A backbone area cannot be of type nssa or stub | |||
Validation | invalidNetworkSubtypeForManagementInterface | The management access rule for the management interface contains a network object of an unsupported type. | |||
Validation | aceLogLevelNull | The log level cannot be set to null when the logging option is enabled. | |||
Validation | mntCertNotFound | MNT Certificate not found. | |||
Validation | lockInvalidLock | Attempting to acquire an invalid lock: "{0}" | |||
Validation | adiCliTestSucceeded | The connection test succeeded. | |||
Validation | sruUpdateError_3 | The update server did not have a file applicable to this device. Try again later. If the problem persists, contact Technical Support. | |||
Validation | invalidToken | This is an invalid token. The length of the token must be 140 characters | |||
Validation | nullBgpNeighborFilteringMaximumPrefixLimitOption | Neighbor Maximum Prefix Option can not be null. | |||
Validation | invalidGateway | The Gateway entered is invalid | |||
Validation | invalidOspfRedistOspfSelfIdentifier | Identifier cannot be Process ID of the same OSPF process | |||
Validation | DHCPServerIPPoolNetwork | DHCP server IP address range {0} must not include the network address: {1} | |||
Validation | ipsecEmptyIkev2Integrity | There must be at least one method of integrity checking | |||
Validation | invalidAAARadiusIdentitySourceGroupSize | RADIUS identity sources in a RADIUS identity source group must not exceed 16 entries | |||
Validation | staticRouteWrongGatewayType | Wrong gateway type for static route: {0} | |||
Validation | failedToExportPendingChangesToFile | Unable to export pending changes to the file. | |||
Validation | networkAddressNotAllowed | You cannot assign a network address "{0}/{1}" as the IP address of an interface. | |||
Validation | manualNatSrcIntfIpv6DisabledWithIpv6InOrigDest | Source interface "{0}" is not IPv6 enabled. You cannot use IPv6 addresses in the original destination | |||
Validation | staticRouteInconsistentInterfaceProtocol | Static route inconsistent protocol version for interface: IPv4 vs IPv6 {0} | |||
Validation | invalidOspfAreaRange | 0.0.0.0/0.0.0.0 represents default and cannot be added as a range | |||
Validation | sysInfoFileNotFound | Unable to find file {0} | |||
Validation | PullUpgradeInitiated | Pull upgrade job initiated | |||
Validation | invalidBackupFile | Backup file is invalid. It does not have the manifest file. | |||
Validation | postUpgradefeaturelistChanged | The featureList in PostUpgradeFlags cannot be modified. | |||
Validation | deleteObjWithRel | Cannot delete object because it is being used by "{0}". You must remove the object from all parts of the configuration before you can delete it. | |||
Validation | nullObject | Input object is null | |||
Validation | staticRouteWrongInterfaceEdit | There are multiple static routes defined for {0}. All routes for this address must use the same interface. If you need to change the interface, you must first delete all other routes, change the interface on this route, and then recreate the other routes using the new interface. | |||
Validation | SSLPolicyAppMustHaveSSL | SSL rule cannot contain applications that do not use SSL | |||
Validation | invalidEigrpDuplicateProcess | EIGRP AS Number does not match with the identifier already configured. | |||
Validation | objectNat66OrigAddrIpv6PrefixTooShort | The original address IPv6 prefix must be greater than or equal to 64 in an IPv6 to IPv6 auto NAT rule: {0} | |||
Validation | invalidSmartCliIPV4PrefixListValue | {0} entity value must be an existing IPv4 Prefix List Object | |||
Validation | invalidCloudServiceEnableAction | To enable any cloud service the device must be enrolled with the cloud, either through Smart Licensing or Cisco Security Account. | |||
Validation | updateTimedOut | Update failed. Installation timed out. | |||
Validation | bridgeGroupInterfaceCannotHaveIpv4AddressOfBgpNeighbor | This IPv4 address is part of a neighbor that is being used in the BGP configuration. You cannot assign the same IPv4 address to a bridge group interface. | |||
Validation | haBreakFromConfig | The units in this HA pair are synchronizing configuration. You cannot execute {0} until synchronization is complete. | |||
Validation | invalidLoggingListParams | Please provide either log level or message ID. | |||
Validation | invalidDuplexType | Validaton Failed, This interface does not support {0} for duplex mode. | |||
Validation | invalidSmartCliRouteMapValue | {0} entity value must be an existing Route Map Object | |||
Validation | s2sIkev2ProposalsTooMany | Too many IKE-V2 proposals. Number of assigned IKE-V2 proposals cannot exceed {0} | |||
Validation | PullUnknownError | Some unknown error occured | |||
Validation | manualNatRouteLookupSrcNetworkMismatch | The Perform Route Lookup option is available for identity NAT only. The original and translated source networks must be identical to use the option. | |||
Validation | ipsecMixedCombinedNormalEncryption | Cannot mix combined mode (GCM) and normal mode encryption in an IKEv2 policy | |||
Validation | useOfUnspecifiedIPAddressWithPrefix | {0}/{1} is known as an Unspecified Address. This address cannot be assigned to an interface. | |||
Validation | invalidOspfDefaultInformationWithStub | You cannot configure the default-information originate command with OSPF stub areas. | |||
Validation | troubleshootFailed | Error generating troubleshooting file | |||
Validation | invalidFlexCliIPValue | {0} value must be a valid IPv4 or IPv6 address | |||
Validation | invalidOspfInterface | An interface with OSPF configuration must be enabled and cannot be in passive mode, or be a bridge group, or a member of a bridge group, or be part of the high availability configuration. | |||
Validation | s2sNetworksStrictToMixed | Local networks contain only {0} addresses but remote networks contain both IPv4 and IPv6 | |||
Validation | sruUpdateError_2 | No valid support contract. Unable to download the rule update | |||
Validation | cannotDeleteRealm | Cannot delete any realm | |||
Validation | AnyConnNoRealmServer | Realm server is required | |||
Validation | invalidLoggingListMessageId | Message ID should be in between {0} and {1}. | |||
Validation | invalidOspfNsfBoth | NSF Cisco and IETF requires all LLS capability, Cisco helper, Opaque LSA, and IETF helper be enabled | |||
Validation | bridgeGroupInterfaceIdNotAvailable | All bridge group interface IDs have been assigned between {0} and {1} | |||
Validation | expiredCertificateMgmtWebServer | The chosen certificate has already expired. Please apply an unexpired certificate. | |||
Validation | managementInterfaceCannotBeDisabled | You cannot disable the Management interface | |||
Validation | bgpAsDotNotationEnabled | You must disable AS dot notation if you do not use the X.Y number format. | |||
Validation | pxGridCertNotFound | pxGrid Certificate not found. | |||
Validation | s2sIntfForNatIsPassive | You cannot use a passive mode interface for the NAT exempt interface of a site-to-site VPN connection. | |||
Validation | invalidMtuVirtual | Invalid MTU for virtual device. You can set the MTU up to 9000 for virtual devices. | |||
Validation | valueNotInRange | {0} value must be between {1} and {2}. | |||
Validation | SSLSettingInvalidECDHGroup | Invalid Elliptical Curve Diffie Hellman Group assigned. Valid values are GROUP_19, GROUP_20 and GROUP_21. | |||
Validation | nextHopNullSpecificIPNotNull | Next Hop setting cannot be null when Specific IP is provided. | |||
Validation | AnyConnInvalidNetworkObjectType | Network object type is not valid for address pool | |||
Validation | DHCPServerIntInIPPool | Interface address {0} must not be in the IP address range: {1} | |||
Validation | AnyConnACPkgMissing | AnyConnect client package {0} is missing | |||
Validation | invalidV6Compatible | IPv4-compatible IPv6 addresses are not supported. | |||
Validation | unsupportedRedistribution | Unsupported redistribution protocol selected | |||
Validation | AnyConnInvalidAuthenticationIdentitySource | You must select an identity realm or radius group as the authentication identity source if you select Local as the fallback identity source. | |||
Validation | invalidRegexPattern | The regular expression pattern is not valid. The pattern must not contain any question marks, or spaces. | |||
Validation | natPortRangeNotSupported | Port range is not supported in auto NAT rules | |||
Validation | EmptySSLCipherProtocolVersionList | You must specify at least one SSL Protocol version | |||
Validation | invalidOspfDuplicateNeighborInterface | An OSPF neighbor is already defined on the interface {0}. Only one neighbor is allowed on point-to-point interfaces | |||
Validation | stringTooLong | The string {0} length exceeds the limit of {1} | |||
Validation | invalidPrefix | The Prefix entered is invalid | |||
Validation | emptyBypassList | The hardware bypass list is empty | |||
Validation | AnyConnACPrfOutsideIntfCannotBeMgmt | The interface {0} added to AnyConnectProfile is invalid, the outside interface cannot be for management only | |||
Validation | acRuleMoreThanOneEmbeddedAppFilter | An access rule should not have more than one embedded application filter | |||
Validation | handlerError | Internal error during feature toggle | |||
Validation | failedToExportHugePendingChangesToClipboard | Pending Changes size exceeds the limit for copying to clipboard. Please download pending changes as a file. | |||
Validation | provideAtLeaseOneField | You must define at least one option to create a valid certificate. | |||
Validation | invalidHostName | The fully-qualified domain name (FQDN) or IP address is not valid. | |||
Validation | interfaceNameRequired | Interface associated with a syslog server should have a non-empty NAME. | |||
Validation | AnyConnExcessProfile | Can have only one Any-Connect connection profile | |||
Validation | cannotConfigureIPAddress | The interface is configured in passive mode. You cannot configure an IP address on a passive interface. | |||
Validation | interfaceCannotHaveIpv6AddressOfBgpNetwork | This IPv6 address is part of a network that is being used in the BGP configuration. You cannot assign an IPv6 address from this network to a management-only interface or subinterface. | |||
Validation | cannotDiscardDuringDeploy | You cannot discard pending changes while a deployment is in progress. Please wait for the current deployment to finish. | |||
Validation | taskStatusNotAvailable | Status not available | |||
Validation | dnsServersCannotBeEmpty | You must specify at least one DNS server. | |||
Validation | invalidFTSFilter | You cannot combine a full-text search (filter=fts~) filter with any other filter parameter in a single request. | |||
Validation | SSPServerUnavailable | SSP Server Unavailable | |||
Validation | SSLSettingNoTLSVProtocolsAssigned | Along with DTLSV protocol family version at least one TLSV protocol family version should be assigned. | |||
Validation | haBreakFromSingle | The device does not have HA configured, {0} cannot be executed. | |||
Validation | methodException | Validation failed due to an exception: {0} | |||
Validation | invalidCertificate | Certificate is not valid | |||
Validation | AnyConnPoolIpvMismatch | Network object {0} IP version is not correct | |||
Validation | acPolicyInvalidIPS | The selected intrusion policy cannot be used in an access rule. | |||
Validation | invalidFqdn | The fully-qualified domain name is invalid. | |||
Validation | userServiceTypesIsNullOrEmpty | The user service types cannot be null or empty | |||
Validation | invalidFlexCliBooleanValue | {0} value must be set to either true or false | |||
Validation | invalidOspfAreaCost | Area cost is not applicable for backbone area | |||
Validation | invalidAgentStatus | Invalid Smart agent status | |||
Validation | vdbUpdateError_1 | Unable to connect to update server | |||
Validation | invalidNetworkSubTypeObjectsForPolicy | Unsupported type of network object: {0}. The object names are: {1}. | |||
Validation | invalidOspfDuplicateArea | Area ID must be unique per OSPF process | |||
Validation | invalidLocalUserType | The local user selected must be of type "trafficuserentry" | |||
Validation | invalidNetworkObjectType | Type has been set to an invalid value {0} | |||
Validation | minIpv6MtuIs1280 | To configure IPv6, the minimum MTU is 1280. | |||
Validation | invalidMacAddress | Invalid MAC address. The allowed format is H.H.H, where H is a 16-bit hexadecimal digit. | |||
Validation | CertStatusSelfSignedNullCheck | IsSelfSigned cannot be null | |||
Validation | invalidOspfVirtualLinkAuthKeyNotEnabled | The selected authentication type is password authentication. You must also configure the authentication key | |||
Validation | invalidFlexCliSecretValue | {0} value must be an existing Secret Object | |||
Validation | NoAssociatedIPSFound | Failed to find an IPS associated with the default policy {0}. | |||
Validation | AnyConnInsideIntfAddrOverLap | Cannot use an address pool with range {0} because it contains the address used on inside interface {1} | |||
Validation | appFilterMissingValue | The application filter should have a value {0}. | |||
Validation | appFilterInvalidNumericValueLow | The numeric input for {0} is too low. The minimum value {1}. | |||
Validation | natSourceIntfNotNamed | The interface used for NAT rule source interface must have a name | |||
Validation | invalidLine | Line is not valid. {0} | |||
Validation | manualNatDestIntfIsNullWithIntfInTransSrc | Destination interface cannot be any if you select interface for the translated source | |||
Validation | interfaceNameNull | Cannot associate an interface with no logical name. | |||
Validation | invalidOspfInterfaceNetworkMismatch | Interface {0} IP address does not belong to the specified network {1} of area {2} | |||
Validation | invalidFlexCliUnsupportedNumericValue | {0} value cannot have signs or leading zeros | |||
Validation | bridgeGroupInterfaceEnableIpv6AutoConfig | Bridge group interface do not support IPV6 option auto-config | |||
Validation | appFilterDupClassificationType | Duplicated classification type selected: {0} | |||
Validation | invalidURLfilterLicense | URL filtering license is not enabled | |||
Validation | cannotCreateIdRuleWithoutCert | Cannot create an identity rule if the Server Certificate for Active Authentication is not provided | |||
Validation | defaultActionNotPassiveOrNoAuth | The default action in the identity policy should be Passive or No Authentication | |||
Validation | invalidOspfRedistDuplicateConf | Multiple configurations found for the protocol {0} | |||
Validation | s2sIkev1InvalidKey | Invalid IKE-V1 pre-shared key. It must contain 1 to 128 ASCII printable characters, no whitespace, no single or double quotation marks, no question marks and cannot be a single digit | |||
Validation | appFilterInvalidRiskValue | Invalid application filter risk value {0}. | |||
Validation | invalidPrivateKey | Private key is not valid | |||
Validation | noConnection | This device is currently not registered or in evaluation mode for Smart Licensing | |||
Validation | invalidDomainName | The Domain name is invalid. It can contain only letters, digits and the characters '.' or '-'. It can consist of multiple sections, each separated by a '.' | |||
Validation | invalidTemplateIdentifier | Template identifier is not valid. {0} | |||
Validation | realmInterfaceNotNamed | Identity realm directory interface does not have a logical name | |||
Validation | vdbUpdateError_7 | Peer certificate cannot be authenticated with known CA certificates | |||
Validation | AnyConnNatNoInsideNet | NAT exempt functionality requires at least one inside network | |||
Validation | invalidAddress | Invalid address | |||
Validation | acRuleDestProtocolNotAllowedWithSrcPort | You cannot add a destination protocol object with non-empty source ports: {0} | |||
Validation | SSLCipherUnsupportedAlgorithms | Configured cipher algorithms {0} are either not supported in this version of FTD or not a valid algorithm for the selected protocol versions. | |||
Validation | invalidSecret | Secret cannot be blank or a masking string or a single digit or start with a digit followed by spaces and cannot contain the special character ? | |||
Validation | invalidSmartCliPortValue | {0} entity value must be an existing TCPPortObject or UDPPortObject | |||
Validation | unableToParseIseConfigTestOutput | An error occurred trying to parse the response from ISE. | |||
Validation | staticRouteDefaultNetworkWrongInterface | Default {0} static routes must all use the same interface. Change one or both of the static routes on these interfaces: {1} | |||
Validation | cannotUseFQDNIPRangeNetworkObjects | Cannot use Network objects with FQDN or IP Range type configuration | |||
Validation | sruUpdateError_16 | Rulepack was successfully installed but skipping deployment as this is a STANDBY device. | |||
Validation | alreadySyncing | There is already a sync going on. Please wait | |||
Validation | RaVpnGPTunnelNetworksRequired | Tunnel Networks have to be specified. | |||
Validation | bgpNeighborFilterDistributedListSameFilterDirection | Prefix list and Distribute list can not co-exist for same filter direction. | |||
Validation | DHCPServerIPPoolBroadcast | DHCP server IP address range {0} must not include the broadcast address: {1} | |||
Validation | cliCommandUnSupportedCharacters | Character {0} not allowed in CLI Console. | |||
Validation | appFilterAppNotFound | Application filter application not found {0}. | |||
Validation | ipsecDupIkev2Encryption | Cannot have duplicate encryption methods | |||
Validation | s2sIkev1PolicyNotEnabledForAuthType | Authentication Type in IKE-V1 has been set to "{0}" but none of the IKE Policies has a matching authentication type. | |||
Validation | AnyConnMaxConnTimeoutInvalid | Anyconnect maximum connection timeout cannot be greater than 4473924 minutes | |||
Validation | invalidDisabledLoggingValues | When the logging option is set to disabled, the log level and log interval must be null. | |||
Validation | SSLSettingSameProtocolVersion | You cannot refer to multiple SSL Cipher objects with overlapping Protocol versions in Data SSL Cipher Settings. Overlapping versions are {0} part of Cipher objects {1}. | |||
Validation | invalidSmartCliUnsupportedNumericValue | {0} value cannot have signs or leading zeros | |||
Validation | haPrimaryAndSecondaryAddressesRequired | Both primary and secondary {0} addresses must be provided for {1}. | |||
Validation | licenseCannotBeUpdated | Licenses cannot be updated | |||
Validation | RaVpnSecAuthCommPwdNotSpecified | Common Password is required | |||
Validation | appTagInvalidName | Invalid application tag name {0}. | |||
Validation | staticRouteNoInterfaceName | Interface used for static route must have a logical name | |||
Validation | errorDuringInfoFetchFromSys | Error occurred during system information fetching. | |||
Validation | PullInvalidFilename | Filename is invalid | |||
Validation | RaVpnGroupPolicyInvalidNumberVal | Invalid Value. Valid range is {0} to {1}. | |||
Validation | denyMtuChangeOnUnnamedInterface | You cannot change MTU on an unnamed interface. MTU must be set to 1500 on an unnamed interface | |||
Validation | invalidHAFailoverPeerHoldTimeUnit | Peer hold time unit must be MILLISECONDS or SECONDS | |||
Validation | duplicateSubInterfaceId | Subinterface ID {0} already exists for {1} | |||
Validation | cannotAssignDHCPWhenHAIsEnabled | Interface {0} cannot be assigned a DHCP address when HA is enabled. | |||
Validation | cannotUseBGIMemberInterfaces | The interface is part of a bridge group. You cannot configure management access list rules for a bridge group member. | |||
Validation | s2sIkev1MaskedKeyNotAllowed | Masked value for IKE-V1 pre-shared key is not allowed with connection profile creation | |||
Validation | haConfigurationModificationNotAllowed | HA Configuration cannot be modified as the node is already in HA | |||
Validation | s2sCryptoRestrictedIkev1Policy | Your licensing setting does not allow to enable IKE-V1 policy with strong encryption. Please use DES only | |||
Validation | metricBandwidthNullMetricTypeNotNull | Metric Bandwidth cannot be null when Metric Type is not null. | |||
Validation | invalidPortRange | Invalid port range. Beginning port must be less than ending port. | |||
Validation | aaaSpecifiedAuthIdentitySourceNotSupported | Specified authentication identity source is not supported | |||
Validation | invalidRealmId | Invalid realm ID | |||
Validation | atLeastOneEntryRequired | Should have at least one entry | |||
Validation | sruUpdateError_0 | Rulepack successfully installed | |||
Validation | manualNatNoDestNatWithSrcNat46 | Missing destination translation with IPv4 to IPv6 translation on source addresses | |||
Validation | ntpDuplicate | NTP server {0} is specified more than once. Please remove duplicate servers. | |||
Validation | invalidAsciiCharacterForLina | The name and password can contain any printable ASCII alphanumeric or special character except spaces and question marks. Printable characters are ASCII codes 33-126. | |||
Validation | subInterfaceNotAllowedInSecurityZone | SubInterfaces are not allowed in a security zone with mode passive. | |||
Validation | hardwareNameCannotBeNull | Hardware name cannot be null. | |||
Validation | InvalidBgpNeighborDupPrefixListFilter | Only one prefix list can be configured in either direction | |||
Validation | invalidOspfInterfaceNoIP | Cannot configure neighbor on interfaces without IP address. Assign an IPv4 address to the interface | |||
Validation | standbyWithoutActiveMacAddress | Standby MAC Address cannot be specified without an active MAC Address. | |||
Validation | usedHAInterface | The {0} must be an unused interface | |||
Validation | DHCPServerWrongNetworkProtocol | DHCP server IP address range must use IPv4 addresses | |||
Validation | bridgeGroupInterfaceMemberPassive | You cannot add a passive mode interface to a bridge group. | |||
Validation | vdbUpdateError_10 | The latest VDB update is already installed | |||
Validation | s2sFQDNNetwork | Site-to-site profiles cannot have FQDN type network objects | |||
Validation | invalidOspfNsfConflictingConfiguration | Conflicting NSF graceful restart configuration | |||
Validation | ipAddressTypeMismatch | The IP addresses for {0} must be either IPv4 or IPv6 not both. | |||
Validation | invalidRangeBadOrder | Invalid range. The end IP address must be greater than the start IP address | |||
Validation | bridgeGroupInterfaceCannotHaveIpv6AddressOfBgpNetwork | This IPv6 address is part of a network that is being used in the BGP configuration. You cannot assign an IPv6 address from this network to a bridge group interface. | |||
Validation | cannotUpdateUnauthenticatedUser | Cannot perform update on unauthenticated user | |||
Validation | OpenSSLCipherDetailsNotAvailable | Unable to load the Open SSL protocol cipher details. | |||
Validation | prefixNotAllowed | Invalid range. Prefix/subnet mask is not allowed in range object. | |||
Validation | invalidHAFailoverThreshold | When the interface failure threshold unit is set to {0}, then the valid range is between {1} and {2}. | |||
Validation | appTagInvalidDesc | Invalid application tag description {0}. | |||
Validation | ipsecPolicyNeedPrf | Policy must have at least one pseudorandom function | |||
Validation | prefixListIpAddressNotUnique | IP address/mask value should be unique across all entries in the prefix list. | |||
Validation | SslRulesWithDeprecatedCategories | Some of the SSL decryption rules refer to deprecated URL Categories. Number of SSL decryption rules affected: {0}. | |||
Validation | CertStatusIsValidNullCheck | IsValid cannot be null | |||
Validation | interfaceCannotHaveIpv4AddressOfBgpNetwork | This IPv4 address is part of a network that is being used in the BGP configuration. You cannot assign an IPv4 address from this network to a management-only interface or subinterface. | |||
Validation | invalidOspfProcessUpdated | Cannot change process ID when editing OSPF process | |||
Validation | invalidLicenseForDeployment | Deployment is blocked. This device does not have a base license. You cannot deploy changes. | |||
Validation | threadError | Error occurred during thread sleep. | |||
Validation | ipsecPolicyInvalidLifetime | Lifetime value not in range: {0} | |||
Validation | DHCPServerSecondaryWINSHost | DHCP server secondary WINS server must be host type: {0} | |||
Validation | AnyConnNoIpv4InsideNetwork | With {0} as an IPv4 address pool, you must have at least one IPv4 inside network specified | |||
Validation | invalidFlexCliTemplateUnsupportedChar | Template cannot contain unsupported character sequence {0} | |||
Validation | AnyConnOutsideIntfAddrOverLap | Cannot use an address pool with range {0} because it contains the address used on the selected outside interface {1} | |||
Validation | objectNat64AnyIpv6NotValid | The network corresponding to the full range of IPv6 addresses, i.e. ::/0, cannot be used in an IPv6 to IPv4 object NAT rule | |||
Validation | maxOneInterface | Either data interface or management interface can be selected. | |||
Validation | invalidOperationOSPFNeighborDefined | Operation cannot be performed when an OSPF neighbor is enabled for this network | |||
Validation | invalidNetworkSubtypeForFlexPolicy | The FlexConfig policy contains a variable for a network object of an unsupported type. | |||
Validation | invalidFqdnDnsResolution | The fully-qualified domain name DNS resolution type is invalid. | |||
Validation | invalidFilterCondition | Invalid filter condition is provided. | |||
Validation | unsupportedNGFWInterfaceSpeed | Unsupported NGFW Interface Speed on SSP platform | |||
Validation | authTokenNotEqual32 | The registration key must be 32 characters. | |||
Validation | onlyIPv4NetworkObjectsAllowed | Only IPV4 networks are allowed. | |||
Validation | AnyConnNatNoInsideIntf | NAT exempt functionality requires at least one inside interface | |||
Validation | manualNatNoInterfaceSelectedWithRouteLookup | Please specify at least one interface to enable route lookup | |||
Validation | invalidIdentitySourceGroup | "identitySourceGroup" field can only be of type {0} | |||
Validation | s2sCryptoRestrictedIkev2Policy | Your licensing setting does not allow to enable IKE-V2 policy with strong encryption. Please use DES only | |||
Validation | nameUseAAAReservedKeyWord | You cannot use a reserved AAA keyword as your Identity Source name: "{0}" | |||
Validation | sruUpdateError_14 | Error running Rule update | |||
Validation | bridgeGroupInterfaceCannotHaveIpv4AddressOfBgpNetwork | This IPv4 address is part of a network that is being used in the BGP configuration. You cannot assign an IPv4 address from this network to a bridge group interface. | |||
Validation | conflictingInterface | All syslog servers should have same interface type. i.e either all servers should have management interface or all should have data interfaces. | |||
Validation | invalidOspfRedistIsisRequiredDisabled | Routing level must be specified to enable redistribution of ISIS protocol | |||
Validation | unnamedInterfaceInSecurityZoneNotAllowed | This interface is part of security zone: {0}. You must remove the interface from all zones before you can remove the interface name. | |||
Validation | DHCPServerInterfaceInBridgeGroup | The interface {0} is already a member of the bridge group interface {1} and hence cannot be configured as a DHCP server | |||
Validation | manualNatSrc46Ipv6RangeObjNotAllowedInTransSrc | You cannot use an IPv6 range network object as the translated source in an IPv4 to IPv6 manual NAT source translation rule: {0} | |||
Validation | invalidBgpNeighborBridgeGroupInterface | BGP Neighbor can not be on the same network as Bridge group interface | |||
Validation | PullUpgradeCompleteMessage | Pull is completed | |||
Validation | invalidSmartCliPolicyListValue | {0} entity value must be an existing Policy List Object | |||
Validation | bgpAsDotNotationNotEnabled | You must enable AS dot notation to use the X.Y number format. | |||
Validation | haBreakFromStandby | You cannot execute {0} on the standby unit. Please log into the active unit to break HA. If you need to disable HA on this unit only, first suspend HA. Then you can execute {0}. | |||
Validation | onlyPrefixOrAccessList | The list should contain either all Access List objects or all Prefix List objects. | |||
Validation | DHCPServerIPPoolAsClient | DHCP server IP address range is not valid if its already defined as a DHCP Client. | |||
Validation | interfaceInDHCPServer | The following interfaces are configured as DHCP Servers {0}. You must remove them before you can add the interfaces to a bridge group | |||
Validation | geoUpdateError_3 | The update server did not have a file applicable to this device. Try again later. If the problem persists, contact Technical Support. | |||
Validation | checksumError | Error in {0} checksum. The file is corrupt, obtain a new copy. | |||
Validation | invalidMethod | Validation failed, invalid method "{0}" marked as @AutoValidating | |||
Validation | manualNatSrc66OrigSrcIpv6PrefixTooShort | The original source IPv6 prefix must be greater than or equal to 64 in an IPv6 to IPv6 manual NAT source translation: {0} | |||
Validation | ipsecDupIkev2Group | Cannot have duplicate DH groups | |||
Validation | invalidObjectForTimeRangeAnnotation | Invalid object type for TimeRange annotation. | |||
Validation | UnlockDeviceWithoutAcceptEula | The End User License Agreement has not been accepted. The device remains locked until you accept the EULA. | |||
Validation | invalidNetworkSubtypeForIdentityRuleSource | The identity rule source criteria contains a network object of an unsupported type. | |||
Validation | emptyLocations | Please select at least one country or continent | |||
Validation | nestedNetworkGroupCycleDetected | The network group {0} includes a nested reference to the group you are editing. A network group cannot include references to itself. Please remove {0} | |||
Validation | alreadyInEval | Evaulation mode has already been used, you cannot start evaluation mode again | |||
Validation | cannotDeleteReferredLocalUserInRule | Cannot delete local user object because it is being used by an access or SSL rule. | |||
Validation | standbyIPNotInSameSubnetOfActiveIPAddress | Standby IP Address should be in the same subnet as the active IP Address. | |||
Validation | bgpInvalidMinHoldTime | Minimum hold time should be less than hold time | |||
Validation | appFilterInvalidProductivityValue | Invalid application filter business relevance value {0}. | |||
Validation | AnyConnNoIpv6InsideNetwork | With {0} as an IPv6 address pool, you must have at least one IPv6 inside network specified | |||
Validation | bgpInvalidGracefulRestartAndStalepathTimeDifference | There should be at least 240 secs difference between the restart timeand the stale path time | |||
Validation | diskFileNotFound | Cannot find a file with name: {0} | |||
Validation | SSLCipherProtocolMissingAlgorithms | Selected protocol versions {0} should have at least one supported algorithm assigned. | |||
Validation | invalidSmartCliStandardCommunityListValue | {0} entity value must be an existing Standard Community List Object | |||
Validation | existingConnection | The device is already operating in evaluation mode or it was registered with Smart Software Manager. Please reload the web page to continue | |||
Validation | illegalNumBitsForMask | Invalid number of bits for mask - {0}. Mask cannot be greater than 128 | |||
Validation | invalidSubnetMask | Invalid subnet mask. | |||
Validation | PullUpgradeInitiationSSLError | Pull upgrade job initiation failed due to an SSL verification error. | |||
Validation | manualNatDest64AnyIpv6NotValid | The network corresponding to the full range of IPv6 addresses, i.e. ::/0, cannot be used in the destination of an IPv4 to IPv6 manual NAT rule | |||
Validation | invalidHAFailoverInterfaceHoldTimeUnit | Interface hold time unit must be MILLISECONDS or SECONDS | |||
Validation | InvalidBgpNeighborRoutesRemovePrivateAs | Private AS cannot be removed for IBGP peers. You cannot configure if BGP AS number is same as remote-as number. | |||
Validation | communityNumbersNotUnique | Community numbers must be a unique set of values. | |||
Validation | interfacePairShouldBeInSameBridgeGroup | Interface pair must be in the same bridge group to enable bypass | |||
Validation | jobRunning | The task you are requesting is already in progress or it is queued to start. | |||
Validation | aaaInvalidUsername | Username cannot be empty or contain spaces | |||
Validation | defaultActionCannotBeChanged | You cannot change the default action in the identity policy | |||
Validation | haActionOnInvalidState | The current node state {0} does not allow HA {1} action. | |||
Validation | invalidRange | Invalid range | |||
Validation | invalidOspfNsfNone | Disabling NSF requires all LLS capability, Cisco helper, Opaque LSA, and IETF helper be negated | |||
Validation | geoUpdateError_4 | Update file is corrupted | |||
Validation | haInterfaceNameNotEmpty | You cannot use a named interface for {0}. Please edit the interface and remove the name, or select a different interface. | |||
Validation | manualNatDestIntfIpv6DisabledWithIpv6InTransSrc | Destination interface "{0}" is not IPv6 enabled. You cannot use IPv6 addresses in the translated source | |||
Validation | standardAccessListNetworksNotUnique | Standard Access List entries must have unique networks across all entries. | |||
Validation | newInstanceWithDuplicateId | Validation failed, attempting to create a new object with duplicate ID | |||
Validation | invalidOspfRedistBgpIdentifier | Identifier value {0} does not match the BGP autonomous system number in use | |||
Validation | invalidLengthFqdn | The fully-qualified domain name cannot be more than 128 characters. | |||
Validation | overlappingSubnet | The IP address, {0}/{1}, cannot overlap with the subnet of interface {2} | |||
Validation | unsupportedSSPInterfaceSpeed | Unsupported SSP Interface Speed on NGFW: {0} | |||
Validation | ipsecPolicyInvalidPriority | Priority value not in range: {0} | |||
Validation | contextGetFailed | Could not get device registration context. Please try again later. | |||
Validation | manualNatSrc66OrigSrcPrefixShorterThanTransSrcPrefix | The IPv6 prefix of the original source subnet "{0}" must be greater than or equal to the IPv6 prefix of the translated source subnet "{1}" | |||
Validation | AccessSslRulesWithNewlyAddedCategories | The following URL categories are new and not yet active: {0}. Please also add one or more active URL category to the rule. | |||
Validation | s2sIkev2InvalidLocalKey | Invalid IKE-V2 pre-shared local key. It must contain 1 to 128 ASCII printable characters, no whitespace, no single or double quotation marks, no question marks and cannot be a single digit | |||
Validation | IntfAddedIsOutside | The interface {0} is already added as an outside interface. | |||
Validation | dnsServerGroupCannotBeRenamed | The DNS server group {0} is being used in the data interface settings. Before you can rename the group, you must remove it from that setting. | |||
Validation | DHCPServerAutoConfigFalseWithInterface | DHCP Server default interface cannot be set if Auto Configuration is off | |||
Validation | appFilterDupRisk | Duplicated risk selected: {0} | |||
Validation | loggingListNameSubString | Name cannot be substring of one of existing list's name. | |||
Validation | maxPrefixLimitCanNotBeDifferent | Cannot have different values for maximum prefix limit. | |||
Validation | genericTimeout | Timeout: {0} | |||
Validation | invalidOspfRedistEigrpIdentifier | Identifier value {0} does not match the EIGRP autonomous system number in use | |||
Validation | reservedAddressNotAllowed | The IP address cannot be a reserved address (240.x.x.x to 255.x.x.x). | |||
Validation | invalidSmartCliExtendedAccessListValue | {0} entity value must be an existing Extended Access List Object | |||
Validation | appFilterEmptyMatchers | The application filter has empty match conditions. | |||
Validation | cannotChangeIdentitySourceOfUser | You cannot update the identitySourceId of a user. | |||
Validation | ipAddressIsBlocked | The IP address {0} is reserved. You cannot assign it to the interface. | |||
Validation | noToken | In order to register, you must provide a token obtained from your Smart Software Manager Account | |||
Validation | acRuleLogFilesInvalidAction | You cannot enable Log Files because there is no file policy selected for this rule. | |||
Validation | unresolvableUrl | Hostname cannot be resolved to an IP address. | |||
Validation | unableToCreateBypassPair | Unable to create hardware bypass pairs | |||
Validation | cliCommandEmpty | Please enter a command. | |||
Validation | SSLPolicyDefaultActionBlockorDND | Default action for SSL policy can only be block or do-not-decrypt | |||
Validation | bypassInterfacePairEmpty | The hardware bypass pair contains no interfaces | |||
Validation | bgpInvalidAggregationToAnyIP | Aggregating to default is not allowed | |||
Validation | InvalidBgpNeighborDupASPathFilter | Only one as-path can be configured in either direction | |||
Validation | SSLPolicyOnlyTCPPorts | SSL rule cannot use non-TCP port object {0}, referenced in {1} ports | |||
Validation | s2sIkev1Ikev2BothDisabled | IKE-V1 and IKE-V2 cannot be both disabled. You must enable either one or both | |||
Validation | invalidSmartCliStringValueBlank | {0} value cannot be null or blank | |||
Validation | bridgeGroupInterfaceRederencedInBridgeGroup | The following interfaces are referenced by another Bridge Group Interface: {0}. You must remove them before you can add the interfaces to a bridge group. | |||
Validation | haBothLinksAreOnSameSubnet | The failover and statefulFailover addresses must not be on the same {0} subnet. | |||
Validation | objectNatPortNotAllowedWithDnsEnabled | You cannot enable DNS reply translation with port translation in an auto NAT rule | |||
Validation | InvalidBgpNeighborNeighborHopsRemoteAsBgpAsNumber | ttl-security should allow to configure for EBGP peers. You cannot configure if BGP AS number is same as remote-as number. | |||
Validation | DHCPServerInterfaceName | This interface is being used as a DHCP server. You cannot remove the interface name until you change the DHCP server configuration. | |||
Validation | manualNatSrc46Ipv6PrefixTooLong | The translated source IPv6 network prefix length must be less than or equal to 96 in an IPv4 to IPv6 manual NAT source translation rule: {0}({1}) | |||
Validation | unknownHostIP | Could not determine device management IP address. | |||
Validation | DHCPServerInvalidPlatformSupport | DHCP Server Configuration is not supported for vFTD Platforms. | |||
Validation | manualNatDest66TransDestIpv6PrefixTooShort | The translated destination IPv6 prefix must be greater than or equal to 64 in an IPv6 to IPv6 manual NAT destination translation: {0} | |||
Validation | AnyConnAuthenticationIdentitySourceNotSupported | Authentication identity source of type {0} is not supported. | |||
Validation | DHCPServerSecondaryDNSHost | DHCP server secondary DNS server must be host type: {0} | |||
Validation | versionMismatch | This upgrade is for software versions greater than or equal to {0} and less than {1}. | |||
Validation | interfaceisPassive | The selected interface {0} used in syslog server cannot be in passive mode. | |||
Validation | DHCPServerInterfaceMgmt | DHCP server cannot be configured on the management interface. | |||
Validation | appFilterInvalidRiskName | Invalid application filter risk name {0}. | |||
Validation | invalidOspfSpfTimers | Incorrect SPF timer configuration, expected initial-delay <= min-hold-time <= max-wait-time | |||
Validation | invalidCloudCommunicationSettings | Could not update the cloud communication settings, please retry. | |||
Validation | AnyConnInsideNetNoPool | {0} address pool is required if {0} inside networks are specified | |||
Validation | connectorIOError | Connector failed to connect. Please check the connection. | |||
Validation | RaVpnGroupPolicyRenameDefaultGP | Default Group Policy (DfltGrpPolicy) cannot be renamed. | |||
Validation | acRuleOverlapCountryContinentSrcNetworks | The source networks should not contain both country {0} and continent {1} | |||
Validation | acRuleDestUdpPortWithOtherSrcPort | When you specify destination UDP ports, the source ports should either be empty or contain at least one UDP port | |||
Validation | invalidHAFailoverInterfaceHoldTime | Interface hold time must be between 5 and 75 seconds. | |||
Validation | s2sMultipleOutsideIntf | Site-to-Site VPN connection profile can only have a single outside interface | |||
Validation | manualNatTransDestHasIpv6AndIpv4Addresses | The translated destination network should not contain both IPv4 and IPv6 addresses | |||
Validation | objectNatTransNetworkHasIpv6AndIpv4Addresses | The translated address cannot contain both IPv6 and IPv4 addresses | |||
Validation | emptyAddressPoolForNatEnabled | NAT Exempt cannot be enabled when there is no client address assignment pool configured on any RAVPN connection profile or any of the group policies. | |||
Validation | natOtherOptionsNotSupported | The following options are not supported and should not be selected in NAT rules: {0} | |||
Validation | bridgeGroupInterfaceIdNotEditable | The bridge group interface ID cannot be modified by editing the bridge group interface. Current bridge group interface ID in the DB is {0}, bridge group interface ID from request is {1} | |||
Validation | SSLRuleSyslogWithEventOff | Syslog cannot be used if events for the SSL rule are turned off | |||
Validation | cryptoCompliantIkev1Policy | The IKE-V1 policies are using strong encryption which is not allowed by your licensing setting, please disable them or use DES only: {0} | |||
Validation | updateEntityWithoutChanges | This update request contained no changes to the object. The request is not processed. | |||
Validation | appFilterTypeInvalid | Invalid application filter entry type {0}. | |||
Validation | invalidVariableValue | Variable value is not valid. {0} | |||
Validation | emptyValue | Value cannot be empty. | |||
Validation | RaVpnSecAuthPrefillPasswdBothNotSpecified | One of Password Type or Prefill Username has to be configured. | |||
Validation | subnetConflictWithStaticRoutes | There is already a static route for the {0}/{1} network, which conflicts with address {2}/{3}. To assign this address to an interface, you must first delete the static route | |||
Validation | prefixGreaterThanMask | The {0} prefix length should be greater than the IP address subnet mask value. | |||
Validation | cannotChangeExternalUserPassword | You cannot change the password for an externally authenticated user. Change the password in the external AAA server instead. | |||
Validation | bgpDuplicateInjectMapEntryNotAllowed | Duplicate Inject Map Entries are not allowed. | |||
Validation | objectNat46Ipv4AnyIsNotAllowedWithNat46WellKnownPrefix | The original address cannot be IPv4 "any" with the well known NAT46 prefix "64:ff9b::" in the translated address | |||
Validation | BannerTooLong | Banner display string cannot be longer than {0} | |||
Validation | s2scaCertUsedAsInternalCertificate | CA or self-signed certificate cannot be used as identity certificate for authentication between Site-to-Site VPN peers. Please provide a valid identity certificate for successful VPN establishment. | |||
Validation | invalidInterfaceHoldTime | You cannot enter an interface hold time value that is less than 5 times the interface poll time. | |||
Validation | DuplicateAnyConnNoRealmServerHosts | Realm servergroup {0} has duplicate server hosts {1},Realm server hosts must be unique. | |||
Validation | systemDefinedObject | You cannot modify or delete system defined objects. | |||
Validation | SSLCipherInvalidSecurityLevelForProtocolVersion | Security level {0} not applicable for protocol versions {1} | |||
Validation | objectNat46AnyIpv6NotValid | The network corresponding to the full range of IPv6 addresses, i.e. ::/0, cannot be used in an IPv4 to IPv6 object NAT rule | |||
Validation | invalidOspfNsfCiscoOnly | NSF Cisco requires LLS capability, Cisco helper enabled and Opaque LSA, IETF helper negated | |||
Validation | invalidNetmask | The Network mask entered is invalid | |||
Validation | invalidCharacters | Cannot contain special characters {0} | |||
Validation | scheduleInvalidName | Invalid schedule name | |||
Validation | updateEasysetupStatusWithoutPasswordChange | Password has not been changed, unable to update easy setup status | |||
Validation | invalidPlatformLogSettings | Platform log settings property cannot be accepted on this platform. | |||
Validation | haNoneMatchingAddresses | When using the same interface for both the failover and statefulFailover, their addresses must match. | |||
Validation | missingIdentityPolicyinAccessPolicy | You cannot disable the realm because an identity policy that uses it is associated with an access control policy. | |||
Validation | modelMismatch | This upgrade is not for this device model. | |||
Validation | acRuleCannotUseReservedRuleName | You cannot use the reserved hidden rule name: {0} | |||
Validation | taskRunning | The task is queued/in-progress. Task cannot be deleted. | |||
Validation | acRuleDestinationZoneCannotBePassive | When you specify source zone as passive mode zone, the destination zone should be empty | |||
General | accessDeniedHaStandbyWriteProhibited | This device is part of a high availability (HA) pair and is currently not in the active state. With few exceptions, you cannot edit the configuration for this device. To make any changes, please log into the active unit. | |||
General | NetworkParticipationNeedsLicenseRegistration | Before enrolling in Cisco Success Network, you must register the device with Cisco Smart Software Manager. Please register the device on the Smart License page. | |||
General | failedToConnect | Unable to ping {0}. Please verify that the DNS server addresses are correct and the the interface is connected to a gateway that can reach the internet. | |||
General | badCredentials | Bad Credentials | |||
General | invalidNeighborGeneralDescription | Neighbor General description cannot contain spaces or question mark | |||
General | deviceRegistrationContextCreationInprogress | Device registration context creation in progress. | |||
General | HitcountInvalidFilterKey | Invalid filter key is provided | |||
General | FailedStringToJsonConversion | Failed to convert String to Json. | |||
General | FailedJsonToStringConversion | Failed to convert Json to String. | |||
General | HitcountCliParseFailure | Failed to parse output from FTD CLI | |||
General | changePasswordInvalidBlank | Invalid password: A blank password is not allowed. | |||
General | tooManyFailedAttempts | Too many failed attempts. You must wait before you can try again. | |||
General | unknownError | An unexpected error occurred. | |||
General | unableToResolveRadiusServerIdentitySource | Could not resolve RADIUS identity source address | |||
General | exportCommittedConfig | Committed state configuration. Cannot export if deployment is not performed. | |||
General | couldNotFindStatus | The requested deployment status id, {0}, does not exist. | |||
General | deviceAlreadyRegistered | The device was already enrolled. | |||
General | invalidFile | Invalid export file. | |||
General | prefixNameContainsInvalidChar | Prefix name cannot contain characters other than a-z, A-Z, 0-9, -, and _ | |||
General | failedToAuthenticateUser | Failed to authenticate user | |||
General | cliCommandExecutionTimeOut | Command execution timed out. Please try again. | |||
General | cryptoFtdKeyFailure | Server failed to encrypt the FTD certificate key | |||
General | errorConnectingToRadiusIdentitySource | Error connecting to RADIUS identity source | |||
General | userNotFound | User not found | |||
General | accessDeniedDueToUserRole | You do not have access to edit this feature based on your User Role. | |||
General | CliCommandFileParsingError | Exception occurred while parsing the command file. | |||
General | couldNotGetValidURLResources | Failed to get the list of valid URL resource names for authorization enforcement | |||
General | timeout | The attempt to ping {0} timed out. Please verify that the interface is connected to a gateway that can reach the internet. | |||
General | injectionDetected | Invalid input data | |||
General | invalidSessionId | User session id is not valid. | |||
General | cannotFindHTTPSAAASetting | You cannot connect using HTTPS due to possible database corruption. If this device is the secondary device in a high-availability pair, synchronization might have failed; please try deploying from the primary again to trigger a sync to the secondary. Otherwise, please contact Cisco TAC. | |||
General | AdapterLoadingFailed | Failed to load the encoder/decoder {0} for the model {1} | |||
General | AdapterTemplateMappingNotFound | Smart CLI Template mapping not found for the model {0} | |||
General | importFail | Unable to import database | |||
General | failedToAuthenticateAgainstLocal | Failed to authenticate user against local identity source | |||
General | unableToResolveSourceIP | Unable to resolve source IP of the incoming HTTP request | |||
General | accessDeniedConfigImportInProgress | The device is importing its configuration from the peer unit. After the import completes, you might need to log in again. | |||
General | currentlyInDeadTime | Failed to authenticate user against identity source group because it is currently in dead time | |||
General | ProcessTimedOut | Process timed out. Please try again later. | |||
General | exportMixedConfig | Mixed state configuration. Cannot export if deployment is not performed. | |||
General | exportFail | Unable to export database | |||
General | couldNotFindFile | Failed to find Lina CLI file, {0}. | |||
General | standbyDeviceLoginError | This is the standby unit in a high availability group. The system has determined that you have never logged into the active unit. You must log into the active unit at least once before you are allowed to log into the standby unit. Please log into the active unit, deploy changes, and then you can log into this unit. | |||
General | NetworkParticipationSuccess | Completed enrollment in Cisco Success Network | |||
General | invalidDynamicAuthorizationPort | Dynamic authorization port must be between 1024 and 65535 | |||
General | errorOccurredWhileProcessingRadiusClient | Error occurred while processing RADIUS client | |||
General | errorGettingPermissions | Error occurred when getting the access rights for the user | |||
General | unknownHost | Unknown Host: {0} | |||
General | NetworkParticipationFailure | Could not complete enrollment in Cisco Success Network. | |||
General | cliCommandExecutionFailed | Command execution failed. | |||
General | rsyncFail | Failed to download file {0} via rsync for database import | |||
General | unsupportedImport | Unsupported import type: {0} | |||
General | unableParseFile | Unable to parse file | |||
General | tokenExpiredUnAuthorizedAccess | The access token has expired. You are no longer authorized. Please refresh the token or authenticate again. | |||
General | failedToSyncWebUiCertificateToDevice | Failed to synchronize the Web UI Certificate to the device. | |||
General | couldNotResolveAuthorization | Failed to resolve authorization for current user | |||
General | HitcountDBReadFailure | Failed to read from hit count database tables | |||
General | SecurityIntelligenceScheduleDisableError | Exception occurred while disabling default Security Intelligence feed download schedule. | |||
General | couldNotLogoutUser | Could not terminate session. Please try again. | |||
General | versionMismatch | Failed to import the configuration from the active peer. The software version of the peer, {0}, does not match the software version of this unit, {1}. Please install the same software version on each peer. Then, ensure that you make the currently active peer the active peer again, and deploy the configuration from the active unit. | |||
General | instanceExist | An object of this type already exists. You have only one object of this type. | |||
General | timedOutConnectingToRadiusIdentitySource | Timed out connecting to RADIUS identity source | |||
General | noAuthorizationFoundForUser | No external authorization cisco-av-pairs were found; unable to authorize user | |||
General | userRoleInvalid | The user role is invalid. Please specify a valid user role. | |||
General | cannotFindAAASetting | Unable to authenticate, please contact your system administrator. | |||
General | conflictingAuthorizationFoundFromProvider | Conflicting authorization cisco-av-pairs were received from the AAA provider this user. Unable to resolve the authorization profile for this user | |||
General | getparamsArgumentLength | Argument length less than 1 | |||
General | failedToConnect | The device was unable to connect to the Smart Licensing server. This might indicate a gateway problem for the management interface. Please select Evaluation Mode for now. Then, after completing setup, go to Device > System Settings > Management Interface and verify the management address and gateway configuration. There must be a path from the management IP address to the Internet to complete Smart License registration. You can then go to Device > Smart License and try registering again. | |||
General | interfaceNeedsToBeSpecified | Interface to connect to radius server "{0}" needs to be specified. | |||
General | testConnectionSucceeded | The connection test succeeded | |||
General | deviceContextActivationFailed | Could not activate context. Please try again. | |||
General | errorOccurredUpdatingUser | Error occurred when updating user information | |||
General | unauthorizedUserCustomTokenCreation | Unauthorized to create custom token. Custom Token can be created by local Admin users only. | |||
General | exportDeploymentOngoing | Deployment in progress. Cannot export: {0}. | |||
General | HitcountDBCreateFailure | Failed to initialize hit count database tables | |||
General | HitcountDBUpdateFailure | Failed to update hit count values in database tables | |||
General | changePasswordFailed | Current password is not correct. You must enter the correct current password to change it. | |||
General | cannotFindHTTPSAAASettingHA | The server is busy. Please try again later. | |||
Deployment | checksumTimeoutError | The deployment process could not retrieve the checksum. Please run deployment again. | |||
Deployment | currenrPolicyBundleUpdateFailed | Configuration is partially deployed and not completed. Please run deployment again. | |||
Deployment | archiveError | Error creating deployment archive | |||
Deployment | failedEncryptionOnCertificateKey | Failure in encrypting the certificate key. | |||
Deployment | deployInProgress | You cannot start deployment with a deployment job already in progress | |||
Deployment | generalError | Internal error during deployment: {0} | |||
Deployment | invalidNodeState | Failed to run {0} deployment because the node is in {1} state. | |||
Deployment | alreadyQueued | There is already a deployment task pending. Wait until it completes before deploying changes again. | |||
Deployment | sruInfoLoadFail | The rule installation is corrupted. Please run a rule update to fix the problem. | |||
Deployment | deltaCliError | Internal error during delta CLI generation | |||
Deployment | failedUnkownReason | Deployment failed for an unknown reason. Please try deploying changes again. If the problem persists, reboot the device and try again. If you continue to have problems, contact Technical Support. | |||
Deployment | nothingTodeploy | Nothing to Deploy. | |||
Deployment | ASAConfigExportFailedMessage | Deployment failed because exporting the Lina configuration failed. | |||
Deployment | invalidPeerState | Failed to run {0} deployment because the peer is not ready to synchronize configuration. Peer state: {1} | |||
Deployment | failedUnableToResolveHostname | Unable to resolve the hostname {0} with exception {1}, failing the deployment | |||
Deployment | sensorExportFailedMessage | Deployment failed because exporting the Sensor configuration failed. | |||
Deployment | timeoutError | The deployment process timed out. Please run deployment again. | |||
Deployment | missingHaConfiguration | Failed to read Interfaces from HAConfiguration object. |