Category Code Message
Validation unableToDeletePLRReservation Unable to remove the Permanent Licensing reservation. In order to remove PLR, Permanent Licensing deregistration must be in-progress.
Validation specifyFqdnRedirectHostname You must specify an FQDN network object for Redirect to Hostname.
Validation pppoeNotSupportedOnHANode PPPoE is not supported on a node in HA mode.
Validation keyTypeEmpty Certificate encryption type is empty. You must specify a type.
Validation linaAAAServerTestConnectionInternalError Internal error occured while testing aaa-server connection with data-plane. Please check backend logs.
Validation contextCreationFailed Could not create device registration context. Please try again later.
Validation invalidUserRoleName The user role name was not provided in the request or the name is invalid.
Validation missingFilterProcessor Query processing failed due to a missing filter processor for class : "{0}"
Validation ipv4OrIpv6Required You must select either an Ipv4 or Ipv6 network.
Validation appFilterInvalidNumericValueHigh The numeric input for {0} is too high. The maximum value {1}.
Validation vtiCannotBeAddedToBridgeGroupInterface A Virtual Tunnel interface cannot be used in BGI
Validation missingValidator Validation failed due to a missing validator: "{0}"
Validation externalBrowserPackageMustBeUsedWithSamlAuthentication You can use an external browser package only if you configure SAML authentication to use the default OS browser.
Validation invalidInput Validation failed. Invalid input: "{0}"
Validation invalidOspfInterfaceConflictingMechanism Conflicting lost neighbor detection mechanism. Either hello-multiplier or dead-interval and hello-interval must be used but not both
Validation ipsecExcessIkev1Policies The maximum number of IKEv1 policies enabled has already been reached ({0})
Validation selfSignedInvalidEndDateFormat The self-signed certificate validity end date format is incorrect. The correct format is MMM dd HH:mm:ss yyyy z.
Validation objectNatSubnetNotAllowedInDynamicRuleTransNet The dynamic auto NAT rule cannot have subnet objects for the translated address: {0}
Validation RaVpnGroupPolicyAnyConnectClientProfileTypeExists The RAVPN Group Policy already has a profile for this type of AnyConnect Module
Validation ipv6PoolMissingPrefixLength Missing prefix length in IPV6 address pool
Validation DHCPServerNoInterfaceIpAddress The interface must have an IP address because it is used as a DHCP Server
Validation DHCPServerAutoConfigInterfaceInDHCPRelay DHCP Server default interface, {0}, is used by an enabled DHCP Relay Agent.
Validation SecurityIntelligenceDNSPolicyGlobalBlacklistCanNotBeChanged DNS policy global Block list can not be changed
Validation manualNatSubnetNotAllowedInDynamicRuleTransSrc The dynamic manual NAT rule cannot have subnet objects for the translated source: {0}
Validation geoUpdateError_11 Unable to update the Geolocation database, please retry the update
Validation dnsServersipv6management You cannot use an IPv6 address for the DNS server because IPv6 is disabled on the management interface.
Validation onlyHttpLikeUrlsAreValid The URL must be either HTTP or HTTPS. No other protocols are allowed.
Validation ftdUpdateMgrError_233 Missing upgrade package. Cannot retry.
Validation cannotDeleteBaseLicense The base license cannot be removed
Validation nullBgpNeighborFilteringMaximumPrefixLimitRestartInterval Restart Interval can not be null.
Validation invalidBGPAddressFamilyMoreThanTwo Cannot have more than two address families.
Validation snmpFruInsertTrapNotSupportedOnVirtualPlatform SNMP FRU Insert Trap not supported on Virtual Platform.
Validation unexpectedPLRUnsuccessfulInstallation Unable to install Universal Permanent Licensing. Inputted code may be incorrect.
Validation contextActivationFailed Could not activate context. Please try again.
Validation s2sIkev1PolicyNotEnabledForAuthType Authentication Type in IKEv1 has been set to "{0}" but none of the IKE Policies has a matching authentication type.
Validation accessListEntriesNotUnique Access List entries must be unique.
Validation aaaInvalidUseLocalConfig {0} AAA setting using "{1}" type for the "{2}" field must set the "useLocal" field to {3}
Validation filterNotSupported Filter property not supported
Validation vdbBootstrap Adding VDB updates to database
Validation diskFileNameIsEmpty Disk file name cannot be null or empty string
Validation duplicateMetricsName Cannot configure same metric-name across metric-groups.
Validation unableToCreatePTP Unable to create PTP.
Validation ftdUpdateMgrError_160 Too late to cancel upgrade. Use the 'upgrade retry' API to retry.
Validation manualNatOrigSrcAndDestIpVersionMismatch The original source and original destination addresses must have the same IP version
Validation staticRouteDupIdentifier Static routes must be identifiable by a unique combination of interface, network, and gateway values
Validation objectNat66OrigAddrPrefixShorterThanTransAddrPrefix The IPv6 prefix of the original address subnet "{0}" must be greater than or equal to the IPv6 prefix of the translated address subnet "{1}"
Validation networkObjectIsADhcpRelayServer This NetworkObject is used by the DHCP Relay Service which only supports the HOST type.
Validation cannotEnableCTSFlag The interface cannot be configured in {0} mode and have CTS enabled.
Validation exceededEtherChannelObjectLimit You have exceeded the limit of 48 EtherChannel objects allowed on this system.
Validation invalidFlexCliInterfaceValue {0} value must be an existing PhysicalInterface, SubInterface, or a BridgeGroupInterface Object
Validation pppoeIpv4AddressIsDynamic The pppoe IPv4 IPAddress is set to be dynamically provided by the PPPOE server. No ip address or mask should be provided.
Validation invalidHAFailoverPeerPollTimeUnit Peer Poll time unit must be MILLISECONDS or SECONDS
Validation vtiHardwareNameNonEditable Hardware name for the Virtual Tunnel Interface is a non-editable field, and must be null.
Validation UnsupportedBgpAFIPv6Vrf IPv6 address is not supported for user defined virtual router.
Validation haConfigurationDoesNotExist High Availability is not configured, so the attempted HA join failed. Please reconfigure HA and re-try joining HA.
Validation otherRunningJobCannotTriggerUpgrade Another job {0} is in progress, cannot trigger upgrade now. Please retry once the other job is completed.
Validation s2sVTIIkeV1V2BothEnabled You cannot enable both IKEv1 and IKEv2 for route-based site-to-site VPN connection profiles.
Validation DHCPServerPrimaryWINSHost DHCP server primary WINS server must be host type: {0}
Validation DHCPServerIPPoolSize DHCP server IP address range must not exceed 256 entries: {0}
Validation invalidEigrpInterfaceNoIP Cannot configure neighbor on interfaces without IP address. Assign an IPv4 address to the interface.
Validation connectorMsgSendError Connector failed to send the message.
Validation invalidOspfDuplicateDefaultArea 0.0.0.0/0.0.0.0 is already used, only one area can be set as a default area
Validation invalidLicenseCount This is an invalid number of license requests. Please specify the count as 1
Validation mgmtInterface The Management interface {0} cannot be configured for DHCP Relay.
Validation invalidHoldTime Hold time must be 0 or greater than 2 seconds.
Validation invalidTemplateInstance Instance does not match with the template it uses. Found mismatch in the properties "{0}" of SmartCLI instance with name "{1}".
Validation cannotRetrieveHAStatus Failed to retrieve current device's HA configuration status
Validation invalidEigrpBVINetwork Bridge group interface falls on the same network. EIGRP can not be configured on BVI interface.
Validation unsupportedOperation This operation is not supported in the specified API version
Validation unExpectedExitCodeFromScript The script returned an unexpected exit code, {0}.
Validation ddnsWebURLShouldBeNull Web URL should be set to null.
Validation ddnsRunTimesRequired run times should not be null.
Validation missingPerformanceTier Performance Tier attribute is required
Validation PullUpgradeInitiationFailed Pull upgrade job initiation failed
Validation expiredCertificateUpload The uploaded certificate has already expired. Please upload an unexpired certificate.
Validation manualNatDest46AnyIpv6NotValid The network corresponding to the full range of IPv6 addresses, i.e. ::/0, cannot be used in the destination of an IPv6 to IPv4 manual NAT rule
Validation RulesImportSystemDefinedGroup You cannot select system defined rule groups. {0} is a system defined rule group.
Validation invalidIpAddress Invalid IP address
Validation invalidCronString Invalid cron string for updates.
Validation PullSignValidationFailed Image signature verification failed
Validation invalidEigrpProcessUpdated Cannot change Autonomous System when editing EIGRP process.
Validation objectNat46Ipv6PrefixTooLong The translated address IPv6 network prefix length must be less than or equal to 96 in an IPv4 to IPv6 auto NAT rule: {0}({1})
Validation DNInvalidCN CN is invalid, should be in format CN=
Validation pppoeInvalidUserName Invalid PPPoE user name. User name can not contain a question mark, space, or a semicolon.
Validation geoUpdateError_2 No valid support contract found. Contact sales or support for more information
Validation invalidEigrpNeighborIPSubnet Specified neighbor IP address should be on the same subnet to the interface.
Validation invalidSmartCliIPValue {0} value must be a valid IPv4 or IPv6 address
Validation invalidFlexCliNegateLineSyntax Syntax error with Flex Config CLI negate line: {0}
Validation geoUpdateError_15 A newer version of GeoDB is already installed.
Validation aceSourceEmptyDestinationIsNot The source network list cannot be empty when the destination network list has entries.
Validation intfUsedInVTI Interface {0} is the source for a virtual tunnel interface.
Validation objectNat64Ipv6HostCountTooHigh The IPv6 host count {0} in the original address exceeds the maximum allowed {1} in an IPv6 to IPv4 auto NAT rule
Validation invalidFMCConnectivityInterfaceManagementOnly Management-only interface "{0}" cannot be assigned to Connectivity Interface.
Validation unknownCertKeyType Only '.der,.pem,.crt,.cer,.cert,.key' files are allowed for upload
Validation cannotContainDHCPIpv4Address The interface is configured in {0} mode. It cannot contain a DHCP IPV4 address.
Validation DHCPServerWithDefaultPassiveInterface You cannot use a passive mode interface for the DHCP server default interface.
Validation incompatibleBackupFile Backup file is incompatible with this Hardware and/or the SW version.
Validation ftdUpdateMgrError_231 Missing upgrade script. Cannot retry.
Validation sruUpdateError_15 Internal error occurred while updating Rule Update. Please contact technical support
Validation nextHopInvalidSettingCombination Cannot provide Specific IP(s) when Next Hop uses peer address.
Validation diagIntfMgmtIntfIpv4 You cannot configure the same IPv4 address for the management interface and the diagnostic physical interface.
Validation duplicateName Validation failed due to a duplicate name: "{0}"
Validation invalidOspfAreaIdValue Area ID must be an integer between 0 and 4294967295 or an IPv4 address
Validation memberInterfaceCannotBeUpdated An interface that is a member interface of either a VLAN or Port Channel cannot be associated with {0} object.
Validation deviceAlreadyEnrolled The device is already enrolled with Cisco cloud.
Validation BasePolicyMustBeSystemDefined The base policy must be defined by the system.
Validation minPrefixLessThanMaxPrefix The minimum prefix length should be less than the maximum prefix length.
Validation apihostnameFormatInvalid API Hostname must start with 'api-' and end with '.duosecurity.com'
Validation ftdCertNotFound FTD Certificate not found.
Validation VrfNameChange You cannot change the virtual router name.
Validation invalidEigrpNetworkObject EIGRP does not support Network Object with address 0.0.0.0/0.0.0.0.
Validation invalidSmartCliNegateLineSyntax Syntax error with Smart CLI negate line: {0}
Validation invalidObjectNameSpaceAllowed The name "{0}" is invalid. The name can start with an alphanumeric character or an underscore. It can contain spaces and the special characters +, ., _, and -. However, the name cannot include a leading or trailing space.
Validation ipv6OptionsCannotBeTrue The interface {0} is configured in {0} mode. You cannot turn on IPV6 options: ipv6-enabled, auto-config, suppress-RA or enable DHCP for IPv6 address and non-address configuration.
Validation acRuleDestinationZonePassive You cannot use a passive mode security zone as a destination zone in rule {0}.
Validation natRuleImpactWithVRFConfig The source and destination interfaces belong to different virtual routers. Please ensure you have configured appropriate routes across the virtual routers for this rule to function correctly.
Validation invalidSyslogPort Invalid port for Syslog Server. Either use the default ports, which are 514 for UDP or 1470 for TCP, or specify a port in the 1025-65535 range.
Validation invalidInterfaceSelectedInDdns Invalid type of interface selected, the only types allowed are PhysicalInterface and SubInterface.
Validation MultipleGroupsReplace You can only specify a single rule group if using the REPLACE option.
Validation createFTSIndexFailed Failed to create indices for objects and rules. Full Text Search will not work.
Validation invalidEigrpExceededLimit Only one EIGRP process allowed per device.
Validation networkWithoutNetmask The type Network requires a netmask. To specify a single host, either use the type Host, or use {0}/255.255.255.255.
Validation invalidLowercaseObjectName The name "{0}" is invalid. The name can start with an alphanumeric lowercase character or an underscore. The name cannot contain uppercase characters. It can contain the special characters +, ., _ and -. The name cannot contain spaces.
Validation s2sVTINoTunnelSource You must assign the tunnel source for the virtual tunnel interface if you want to use it for a site-to-site VPN connection.
Validation timeZoneInvalidDSTDateRange The dstDateRange section is incomplete. To configure a dstDateRange, you must specify the startDateTime and the endDateTime.
Validation timeRangeInvalidDate Invalid effective start or end date time. The start time must be prior to the end time. Use the format YYYY-MM-DDTHH:MM, with time in 24-hour notation.
Validation invalidRoleARN RoleARN field should be of the format [arn:partition:service::account-id:resource-type/resource-id].
Validation invalidOspfNetwork {0} is not a legal network
Validation dnsServerGroupNameCannotBeDefault DefaultDNS is a reserved name. Please enter a different name.
Validation appFilterApp The application filter must have valid application parameter values. {0}.
Validation reservedAddressForInternalUsageNotAllowedAsFMCHost FMC Host of "{0}" is reserved for internal usage.
Validation invalidOspfSummaryAddress OSPF does not support summary address 0.0.0.0/0.0.0.0
Validation atleastOneSyslogServerRequired Atleast one Syslog Server Configuration is required to enable Syslog filter.
Validation objectNatRouteLookupAndIntfInTransNet You cannot select the Perform Route Lookup option if you select interface for translated source
Validation invalidMinHoldTime Minimum hold time must be 0 or greater than 2 seconds.
Validation onlyIPv6NetworkObjectsAllowed Only IPV6 networks are allowed.
Validation moreThanOneFilterNotSupported This object type does not support more than one filter parameter.
Validation interfaceHasDhcpRelayAgent Interface {0} cannot be configured as type DHCP since it is currently configured as a DHCP Relay Agent.
Validation sruDownloadSuccess Rulepack successfully downloaded
Validation invalidSmartCliNetworkObjectValue {0} entity value must be an existing Network Object
Validation cannotModifyMemberInterfacesInEtherChannel You cannot modify an interface that is a member interface in an EtherChannel.
Validation vdbUpdateError_3 The update server did not have a file applicable to this device. Try again later. If the problem persists, contact Technical Support.
Validation invalidEigrpOutgoingRouting Distribute List Out cannot be configured without Distribute List IN.
Validation invalidSmartCliInterfaceValue {0} entity value must be an existing PhysicalInterface, SubInterface, or a BridgeGroupInterface Object
Validation certKeyTypeNotFound Certificate digital signature is not supported. Supported types are: RSA, ECDSA, EdDSA.
Validation SslRulesWithDeletedCategoriesDisabledPolicy Some of the SSL decryption rules refer to deleted URL Categories. Number of SSL decryption rules affected: {0}. Enable the SSL Decryption policy, remove deleted URL categories in the rules, or replace them with new ones. You can then disable the policy.
Validation vtiIPTypeMustBeStatic The IP Type for VTI must be STATIC.
Validation RaVpnConnProfAuthentictaionServerNotSpecified Authentication Identity source not specified.
Validation missingIdentityRuleWithAuth Because there are no identity rules that require authentication, no users or groups defined in the directory can be matched. Configure at least one identity rule that requires authentication before configuring user-based access control rules.
Validation deploymentCannotBeStartedWhenBaseIsMissing Deployment cannot be started when 'BASE' license is missing
Validation invalidOspfVirtualLinkMD5NotEnabled The selected authentication type is message digest. You must also configure the message digest key
Validation cannotBlankIntfNameUsedInDIMA Cannot blank out the name of interface when its used in management access rule.
Validation unknownSlaOperation Unknown SLA Operation: {0}
Validation invalidFlexCliTemplateNull Template cannot be null
Validation invalidAuthAction Invalid authentication action in identity rule. You can select No Auth or Active Auth only.
Validation deleteObjWithRel You cannot delete the object because it contains {0}. You must remove the object from all parts of the configuration before you can delete it.
Validation invalidDupOutRouteFilter Duplicate configuration found for outgoing route filter
Validation uniqueEtherChannelIDNeeded EtherChannel ID is already in use. You must specify a unique channel ID.
Validation invalidFlexCliTemplateIndexRef Index reference is not supported
Validation interfaceMigrateSourceAndDestinationCannotBeMembersOfEtherChannelInterface Source and destination IDs cannot belong to members of an EtherChannel Interface.
Validation duplicateVlanId VLAN ID {0} is already used in {1}
Validation UnsupportedNetworkObjectTypeForVpn Network Object is being used in RavpnConnectionProfile {0} , type can't be edited to FQDN or HOST
Validation invalidNetwork The given network {0} cannot be found.
Validation s2sPfsGroupNotValidIkev1 Only PFS groups 2,5,14 can be used with IKEv1 enabled
Validation InvalidBgpNeighborMigrationLocalAsRemoteAsNumber Cannot have local-as number same as remote-as number.
Validation invalidLocalUserInRule The local user selected in the rule is not valid.
Validation InvalidIOCForNap Inspector Override Config for Network Analysis Policy {0} is not valid.
Validation natDestIntfNotNamed The interface used for NAT rule destination interface must have a name
Validation invalidVersion Validation failed due to an invalid version: "{0}"
Validation geoUpdateError_4 Error downloading rule update, file is corrupt (MD5 does not match). Please contact Technical Support or try again later.
Validation InvalidRuleImportMode Invalid rule import mode.
Validation cdoTokenTooLong The authentication token length exceeds the limit of 32
Validation cannotUseIntfWithPassiveMode You cannot use an passive mode interface to configure data interface.
Validation cloudNoResponse Snort 3 cloud update failed: No response from the update server or connection timeout. Please try again.
Validation ftdUpdateMgrError_242 Retry is not allowed at this time. Use the 'upgrade cancel' API to cancel.
Validation manualNatDest46Ipv6PrefixTooShort The translated destination IPv6 network prefix length must be greater than or equal to 64 in an IPv4 to IPv6 manual NAT destination translation: {0}
Validation acRuleNullRuleAction You must specify an access rule action
Validation pppoeDoesNotRequireStandbyIP A Standby IP address should not be provided for interfaces with PPPoE type.
Validation s2sNetworksMixedToStrict Local networks contain both IPv4 and IPv6 but remote networks contain only {0} addresses
Validation invalidOspfAreaTypeConfiguration Multiple area types defined for the same area
Validation scheduleExist Unable to schedule job {0}. A schedule is pending.
Validation SecurityIntelligenceURLPolicyMoreThanOne Cannot have more than one Security Intelligence URL Policy.
Validation cannotAddS2SVpnInterfaces Interface {0} is used for a site-to-site VPN. You cannot include it in an ECMP traffic zone.
Validation AnyConnProxyServerPortTooLong Proxy Server Host and Port should be within 100 characters
Validation invalidPerformanceTier The format of the provided Performance Tier is invalid
Validation acRuleNullEventLogAction You must specify an event logging action for the access rule
Validation RaVpnOutsideIntfAndPortDiffFromFDM The selected outside interface ({0}) and port ({1}) combination is currently being used in a management access list to allow FDM connections. You cannot use this same combination for RA VPN. To use the same interface, please configure a different port number for the RA VPN connection.
Validation invalidASPathName ASPath name must be a numeric value between 1 and 500
Validation manualNatTransDestIsNull You must specify a translated destination network
Validation invalidOspfv2IP {0} must be an IPv4 address
Validation filterOperatorNotSupported Operator not supported for "{0}" filter for this type of object.
Validation manualNatDest64Ipv4AnyIsNotAllowedWithNat46WellKnownPrefix The translated destination cannot be IPv4 "any" with the well known NAT46 prefix "64:ff9b::" in the original destination
Validation ipWithoutPrefix The IPv6 address requires a prefix.
Validation haActionDuringDeployment HA action cannot be performed during an ongoing deployment process.
Validation manualNatOrigSrcHasIpv6AndIpv4Addresses The original source network should not contain both IPv4 and IPv6 addresses
Validation deprecatedApplicationIsUsedInAccessRule Deprecated applications found in the following Access Rule {0}, please remove them: {1}.
Validation pppoeNotSupportedBGI Bridge Group interface member {0} cannot be set to PPPoE.
Validation invalidPort Invalid port. Valid ports are from 1 to 65535.
Validation aceSourceDestinationNoMatchingIPV IP version of source and destination network objects do not match.
Validation dnsDuplicate DNS server {0} is specified more than once. Please remove duplicate servers.
Validation invalidOspfOutRouteFilterIdNotFound No process found for the given protocol and identifier
Validation invalidFlexCliPortValue {0} value must be an existing TCPPortObject or UDPPortObject
Validation storeFilesWithRuleAction File Rule validations failed. Store Files can only be ALL for DETECT_FILES and BLOCK_FILES rule actions.
Validation invalidFlexCliDuplicateVariable A variable with name {0} already exists in the configuration
Validation timeRangeInvalidDailyIntervalTime Invalid dailyStartTime. The dailyStartTime must be prior to the dailyEndTime.
Validation unsupportedSSPInterfaceDuplex Unsupported SSP Interface Duplex on NGFW
Validation invalidApplicationProtocolForDownload File Rule validations failed. IMAP and POP3 application protocols support only DOWNLOAD direction of transfer.
Validation invalidSmartCliLineNotRepeatable This command cannot be repeated but it appears more than once in the configuration. Please remove the repeated commands
Validation sysDefinedRuleCantChange Cannot change or delete a system defined intrusion rule.
Validation invalidRavpnLicense RA-VPN license is not enabled
Validation SecurityIntelligenceDNSPolicyGlobalWhitelistCanNotBeChanged DNS policy global Do Not Block list can not be changed
Validation haBreakInterfaceOptionCannotBeEmpty Interface Option cannot be null or empty.
Validation onlyIPv4NetworksAllowed Only IPV4 networks are allowed - {0}
Validation netModSwitchRequireInterfaceScan Some interfaces have been added to or removed from the device. Please perform an interface inventory scan before updating the network module.
Validation invalidOspfInterfaceSecretRequirements Secret {0} does not meet the password requirements for {1}
Validation connectorResetError Connector reset failed due to an internal error.
Validation invalidOutRouteFilterId Process identifier is required for the chosen protocol
Validation snmpAuthAlgorithmShouldBeNull Authentication Algorithm should not be provided for SNMP Users with NOAUTH security level.
Validation invalidFlexCliCharLimitExceeded A cli command exceeded character limit
Validation pppoeObjectFieldsAreRequired The pppoe object fields (vpdnGrpName, pppoeUser, pppoePassword) are required fields.
Validation duplicateNetwork Found duplicate use of NetworkObject {0}.
Validation memberIntefaceCannotBeCtsEnabled An interface with CTS enabled cannot be a member of an EtherChannel.
Validation CannotCreateNap You cannot create a Network Analysis Policy.
Validation DHCPServerOverlapOutsideInterface A DHCP server is already configured for {0}. You cannot use DHCP to obtain the IP address on an interface running DHCP server. Please select a different interface.
Validation geoDbBootstrap Adding Geolocation updates to database
Validation pppoeStaticAddressMaskMustBe32 The pppoe static ip address must have a mask of 32.
Validation iseNetworkFilterInvalid You cannot use an FQDN or RANGE network object or an IPV6 Address in the Identity Services Engine configuration.
Validation evalNotUsed Evaluation mode cannot be stopped as it is not currently in use
Validation primaryAndSecondaryIseConflict Primary and Secondary ISE Server address cannot be the same
Validation invalidFlexCliTemplateEmpty Template cannot be empty
Validation haBreakFromNegotiation The units in this HA pair are in negotiation. You cannot execute {0} until negotiation is finished.
Validation AnyConnServerCertNeedsIssuerCommonName The Server certificate {0} requires issuer common name
Validation invalidThreatLicenseForFileRule Missing Threat License. Creating or updating the file rule requires this license.
Validation identityRealmNullDirectoryConfig No directory configuration defined for the realm.
Validation invalidIPAddressRange DHCP server IP address range is invalid
Validation acRuleDupUrlCat More than one URL matcher is specified for URL category {0}
Validation haFullDeploymentNeeded Before attempting {0}, all pending changes need to be deployed.
Validation staticRouteNetworkMatchesInterfacePrefix There is already a route for {0}/{1} because of the implicit route for the interface {2}, {3}/{4}. Do not define routes for networks configured on an interface. If the interface has been disabled, deploy the changes before defining route.
Validation RaVpnPasswordManagementNotAvailable Password Management is only available when AAA is selected.
Validation invalidBgpAggregateTimerVrf The aggregate timer value should match the aggregate timer value in General Settings.
Validation backupDoesNotExist Backup does not exist.
Validation cloudServiceInfoUnsupportedMethod You cannot create, update, or delete cloud service info.
Validation invalidSpecialRealmId Invalid Special Realm creation operation
Validation authTokenContainSpecialChar The registration key is invalid.
Validation s2sNoIkev1RemoteAnyNetwork For IKEv1 connections, specific local networks with a remote network spanning the entire IP address space is not allowed
Validation objectNatDestIntfIpv6DisabledWithIpv6InTransNetwork Destination interface "{0}" is not IPv6 enabled. You cannot use IPv6 addresses in the translated network
Validation emptyPLRAuthorizationCode Authorization code not given. In order to install Permanent Licensing reservation, you must input the authorization code.
Validation invalidSmartCliLineSyntax Syntax error with Smart CLI line: {0}
Validation vdbUpdateError_16 A newer version of VDB is already installed.
Validation invalidRetryInterval Retry interval has to be in the range {0} and {1}
Validation mgmtIPandGatewayNotSameSubnet The gateway {1} is not in the same subnet defined by the management address, {0}/{2}. The management and gateway addresses must be in the same subnet.
Validation DHCPServerSecondaryDNSOnly DHCP server secondary DNS server cannot be specified unless a primary DNS server is also specified
Validation monitoredInterfaceCannotBeShutdown Cannot disable HA monitored interface on this platform. Please remove interface monitoring, perform deploy and then disable the interface.
Validation invalidIpv4Address Invalid IPv4 address
Validation AnyConnIdleTimeoutInvalid AnyConnect idle timeout must be 1-35791394 minutes
Validation vdbUpdateError_5 The system could not download the update file. Please try again later.
Validation invalidSmartCliAccessListValue {0} entity value must be an existing Standard or Extended Access List Object
Validation RuleAreOverriddenUnderPolicy Intrusion Rule(s) {0} are overridden under Intrusion Policy [{1}];
Validation s2sAnyNetworkOneProfile Only one Site-to-Site VPN profile can exist if local and remote networks are both unset in a profile
Validation noUpgradeStatusScript The script file {0} is missing.
Validation invalidSmartCliNumericValue {0} value is not a valid integer
Validation netModNotEnabled The interface {0} cannot be {1} since the Network Module is disabled. Enable NetworkInterfaceModule{2} in order to perform the {3} operation.
Validation manualNatPortNotAllowedWithDnsEnabled You cannot enable DNS reply with port translation in a manual NAT rule
Validation invalidFTSFilterValue The search filter contains an unsupported character. Supported characters are [a-z A-Z 0-9 * . , _ -].
Validation invalidPerAccessListLoggingValues When the logging option is set to per access list, the log level and log interval may not be null.
Validation staticRouteInconsistentGatewayProtocol Static route inconsistent protocol version for gateway: IPv4 vs IPv6 {0}
Validation invalidCustomWebURLParams The following parameters in web URL are invalid:
Validation vpnIntfCannotBeMemberOfUserDefinedVrf Interface {0} is assigned to a custom virtual router. You can configure VPN on interfaces that belong to the global virtual router only.
Validation cryptoNonCompliantIkev2ProposalForIntegrityType The upgraded IKEv2 proposals use MD5 as Integrity which is not supported on this FTD version: {0}.
Validation invalidQualifierText "{0}" is not a valid qualifier. Quailifier text can optionally begin with a forward slash followed by one or more alphabets, numbers, or underscore.
Validation ErrorParsingStderrFile Encountered an error when reading the stderr file.
Validation InvalidRuleGroupName Could not find a custom rule group with the name of {0}.
Validation vlanIdBeingUsedByVlanInterface VLAN ID {0} is being used by VLAN interface "{1}" and cannot be assigned to a subinterface's vlan id.
Validation InvalidCountryContinentSelection Validation failed. You cannot include country "{0}" because continent "{1}" is already included.
Validation acRuleCannotHaveMultipleModes You cannot use security zone of different modes in a rule.
Validation invalidOspfLsaTimers Incorrect LSA timer configuration, expected initial-delay <= min-delay <= max-delay
Validation bridgeGroupInterfaceIsOutsideInterfaceInAnyConnectProfile The interface {0} selected as outside interface in AnyConnectProfile {1}
Validation manualNatDest66HostInOrigDestNotAllowedWithSubnetInTransDest The IPv6 host object "{1}" in the original destination is not allowed with an IPv6 subnet object "{0}" in the translated destination
Validation invalidOspfNeighborIPAddress Specified neighbor IP address belongs to one of the interfaces on the device
Validation vdbUpdateError_11 Version mismatch, unable to proceed
Validation invalidActiveAuthPort Invalid port for Active Auth. Port must be either 855 or in the 1025-65535 range
Validation mismatchedVersion Another user or the system updated this object while you were editing it. Please refresh the browser page and redo your changes.
Validation notInRange The value has to be between {0} and {1}
Validation noUpgradeInitiated No upgrade action has been initiated.
Validation invalidOspfInterfaceNoConfiguration Configuration is not specified for the selected interface
Validation manualNatRouteLookupAndIntfInOrigDest You cannot select the Perform Route Lookup option if you select interface for original destination
Validation thresholdExceedsTimeout The threshold value should not exceed the timeout value
Validation invalidEigrpNeighborIPAddress Specified neighbor IP address belongs to one of the interfaces on the device.
Validation cloudServiceCannotBeEnabledIfNotEnrolled A cloud service cannot be enabled if the device is not enrolled in the cloud.
Validation acRuleSyslogOnWithEventLogOff You cannot enable syslog with event logging disabled
Validation bridgeGroupIsNotSupportedAsTargetInterface A bridge group member interface is not supported as the target interface.
Validation bridgeGroupMemberModeOnInvalidInterface You cannot set the interface mode type to BRIDGEGROUPMEMBER.
Validation InvalidSSPFactoryServiceClass Error while getting service class for a give model type {0}
Validation multicastMacAddress Invalid MAC address. MAC address must not have the multicast bit set (The second hexadecimal digit from the left cannot be an odd number.)
Validation externalBrowserPackageNotPresentWhenEnableExternalBrowserIsTrue You must select an external browser package when you configure SAML authentication to use the default OS browser.
Validation natSrcModePassive Source interface {0} is in passive mode. You cannot use a passive mode interface in NAT rules : {1}
Validation SystemDefinedRule You cannot modify system defined rules. {0} is a system defined rule.
Validation CustomInstanceName Instance name cannot end with "_custom".
Validation bridgeGroupInterfaceReferencedInS2SVPN The following Interfaces are used in S2S VPN configuration: {0}. This feature is not compatible with a bridge group member interface. You must remove the interfaces from the configuration before you can add them to the bridge group.
Validation invalidSmartCliActionDependency Operation cannot be performed due to a dependency in the object {0}
Validation CannotFindIOCByUuid Inspector Override Config specified by uuid {0} could not be found. Use "default" for uuid.
Validation switchModeNotAllowedInSecurityZone Switch mode is not allowed in a security zone.
Validation MustSpecifySecurityLevelForRuleGroup You must specify a security level for the rule group.
Validation intfMigrationExportNothingToExport Nothing to migrate.
Validation SyslogServerInterfaceInBridgeGroup The interface {0} is already a member of the bridge group interface {1} and hence cannot be configured as a Syslog server
Validation DHCPServerClient You cannot configure DHCP server on a interface that obtains its IP address using a DHCP client
Validation vdbUpdateError_8 Unspecified error when doing remote update. VDB download failed
Validation invalidInterfaceJoin The interface provided cannot be used for the join operation. Valid interfaces are interfaces with type PhysicalInterface.
Validation upgradeScriptNotFound The script file {0} is missing.
Validation appFilterMissingUuid The application filter should have a UUID {0}.
Validation dataInterfaceHttpsPortOutOfRange Invalid Custom Data Interface HTTPS Port range. Port range must be between 1 to 65535.
Validation invalidSmartCliBranchUsage Branch commands are not in accordance with branching usage
Validation invalidOspfInterfaceManagementOnly You cannot enable OSPF on management-only interfaces
Validation ftdUpdateMgrError_159 Cancel upgrade failed. Use the 'upgrade status' API for details.
Validation interfaceMigrateSourceAndDestinationCannotBeMembersOfBridgeGroupInterface Source and destination IDs cannot belong to members of a Bridge Group Interface.
Validation manualNatSrcIntfIsNullWithIntfInOrigDest Source interface cannot be any if you select interface in original destination
Validation addressDoesNotMatchNetmask The IP Address {0} does not match with netmask {1}. To specify a network use {2}/{3}. To specify a host use {4}/255.255.255.255.
Validation bridgeGroupInterfaceMemberIpv6UnsupportedOptions Bridge Group member interface {0} cannot turn on IPV6 options: ipv6-enabled, auto-config, suppress-RA or enable DHCP for IPv6 address and non-address configuration
Validation snmpNullAuthenticationAlgorithm Authentication algorithm can not be null for SNMP users with security level AUTH and PRIV.
Validation cannotCreateWithMask Unable to create object using a secret mask containing asterisks (*).
Validation smartAgentInitializationError Unable to initialize Smart Agent, which communicates with the Smart Licensing server. Please reboot the system and try enabling/disabling licenses again. If the problem persists, please contact Cisco Technical Support.
Validation RuleMsgEmpty Msg field is missing for intrusion rule: {0}.
Validation snort3LatestRuleExists The latest Snort3 rulepack is already installed
Validation expiredLicenseGracePeriod The grace period for the base license has expired. You cannot deploy changes until you apply a new license.
Validation BinderRuleMissingWhenField Binder Rule is missing "when" field.
Validation lspFilePermission Failed to obtain read/write permission for file: {0}.
Validation maxECMPStaticRouteLimitReached You cannot have more than 8 equal-cost static routes.
Validation invalidUserTypeInRule The users in the rule should be of type TrafficUserEntry or TrafficGroupEntry
Validation unableToRetrieveTiers Unable to retrieve tiers.
Validation invalidNetworkSubtypeForIdentityRuleDestination The identity rule destination criteria contains a network object of an unsupported type.
Validation ErrorParsingRulesData Encountered an error when parsing the rules data: {0}
Validation performanceTierUpdateNotAllowedForPLR Performance Tier update operation is not allowed for PLR mode. To change the tier deregister device and register in with new tier.
Validation invalidFlexCliBlockNotFound Referenced block {0} is not found
Validation identitySourceIDIsNullOrEmpty The identity source ID cannot be null or empty
Validation invalidServerSecretKey The server secret key is invalid. It can contain the special characters: $, &, -, _, ., +, @ but should not contain spaces.
Validation invalidOrMissingUserRole No user role could be obtained from identity source response for external user.
Validation manualNatSrc46DynamicNotAllowed Dynamic NAT is not allowed in a manual NAT rule for IPv4 to IPv6 source address translation
Validation provisionUnsupportedMethod The update and delete methods are not supported for the Provision API.
Validation fqdnIdAssignmentFailure Unable to assign the FQDN ID to the FQDN network object.
Validation featureCapabilitiesParseException Exception thrown while parsing application context files for Feature Capabilities
Validation cannotRestoreInHAMode You cannot restore a backup while the device is part of a high availability group. Please break HA and then perform the restore operation.
Validation staticRouteDupNetworkValue Static route duplicate network value: {0}
Validation intfMigrationExportValidationFailed Please fix validation errors and resubmit. {0}
Validation multipleDHCPRelayEntities Multiple DHCPRelay entities found.
Validation invalidEigrpDuplicateRouting {0} routing interface already configured.
Validation cannotEditDeleteSpecialRealm Cannot edit the Special Realm
Validation memberInterface This interface is a member interface of either a VLAN or Port Channel. You cannot update its properties or refer to it from other policies or objects.
Validation snmpBothTrapAndPollCannotBeEnabled Both Trap and Poll cannot be enabled for SNMP Host with Host Group type.
Validation invalidLinkLocalIPAddress The IP address "{0}" is not a link-local address
Validation ipv6OverlappingSubnet This IPv6 address exists in the subnet of the {0} interface.
Validation invalidDHCPClientInternalRouting You must specify a static address for the management IP when you route management traffic through the data interfaces. Using DHCP client to obtain an address is not allowed.
Validation ftdUpdateMgrError_239 Upgrade in progress. Cannot retry.
Validation invalidOspfRouteMapInterfaceVrf Interface {0} used in route map should belong to the virtual router {1}.
Validation invalidPlatform Tiered licensing is only support on virtual platforms.
Validation nameMustBeNull The interface is configured in {0} mode. You cannot name this interface.
Validation vlanNotAssociatedWithPortMode VLAN {0} is not associated with switch port mode of the interface
Validation invalidOspfRedistOspfIdentifier Identifier value {0} does not match any OSPF processes in use
Validation invalidV6StartCompatible IPv4-compatible IPv6 as start address is not supported.
Validation s2sMaxBackupPeer The number of backup peers exceeds the maximum count of 9.
Validation invalidOspfDuplicateProcess An OSPF process already exists with the given Process ID
Validation geoUpdateError_5 The system could not download the update file. Please try again later.
Validation invalidAction Invalid Action {0}
Validation invalidUpdateFile The uploaded file is not valid.
Validation adiCliTestTimedout The connection test timed out.
Validation emptySGTTags There must be at least one SGT tag.
Validation smartCliUpgradeFailed SmartCLI upgrade failed due to a system error, please contact the support.
Validation PullFileCertificateError File upload failed - Https Certificate Issue -
Validation InvalidPeerHoldTime You cannot enter a hold time value that is less than 3 times the peer poll time
Validation s2sOverlapChosenNetworks Site-to-site profile has {0} network objects that have overlapping address space: {1}, {2}
Validation unsupportedIkevOneEncryption The following encryption algorithms are not supported for IKEv1 policies: 3DES.
Validation ftdUpdateMgrError_244 Upgrade not in failed state. Cannot retry.
Validation invalidFileName The filename is invalid
Validation acPolicySyslogOnWithEventLogOff You cannot specify a syslog server because connection logging is disabled.
Validation unsupportedIkevOneHash MD5 Hash is not supported in IKEv1 Policies.
Validation ipsecPolicyNeedEncryption Policy must have at least one encryption method
Validation invalidPublicKey Public key is not valid
Validation subIntfReuseDupVlanId VLAN ID {0} is already deployed on sub-interface {1} which is being deleted or modified. Please deploy current changes before re-using this VLAN ID.
Validation licenseValidationFailed License certificate validation failed. The Smart License servers might not have been available. Please try again.
Validation acRuleProtocolNotAllowedInSrcPorts A protocol object is not allowed in the source ports field: {0}
Validation cannotAddSubInterfacesToEtherChannelMemberInterfaces You cannot add subinterfaces to physical interfaces that are part of an EtherChannel.
Validation unableToGeneratePLRReleaseCode Unable to generate PLR Release Code. In order to generate a release code, Permanent Licensing must be enabled or be in-progress to be enabled.
Validation RaVpnConnectionProfileSAMLNoFallbackOrSecondary If the primary authentication source is SAML, you cannot specify a fallback or secondary authentication source.
Validation manualNatTranslatedDestCannotIncludeNetworkGroupWithFQDN The translated destination cannot include a network group that contains an FQDN network object
Validation serverAllowedInterfaceTypes Invalid type of DCHP Relay Server interface, the only types allowed are PhysicalInterface, SubInterface, VLAN, VTI, and EtherChannelInterface.
Validation upgradeInProgress Upgrade process is still running. Cannot cancel current running upgrade.
Validation invalidSlaThreshold The threshold value has to be between 0 and 2147483647 milliseconds.
Validation cannotUpdateNullKey Missing existing encrypted string, The asterisk (*) is not an allowed character.
Validation snmpServerHostsManagerAddressDuplicates The same address is repeated in the SNMP hosts list. You can specify a manager address only once.
Validation operationalSLAAPIUnsupportedMethod The method is not supported.
Validation fqdnIdNotAvailable All FQDN IDs have been assigned.
Validation minCantBeGreaterThanMax Minimum File Size cannot be greater than maximum File Size.
Validation invalidAuthenticationPort Authentication port has to be in the range {0} and {1}
Validation AnyConnOutsideCannotBePassive The interface {0} added to AnyConnectProfile is invalid, the outside interface cannot be in passive mode
Validation RangeInvalidEnd Invalid End Address
Validation emptyLdapName You must specify an LDAP attribute name.
Validation InvalidUserVrfNameAsGlobal 'Global' is a reserved keyword for Virtual Router. Please use other name for the virtual router.
Validation powerOverEthernetCannotBeNull Power over ethernet cannot be set to null on the {0} physical interface.
Validation PullFileUnsupportedProtocol Unsupported protocol used in downloadUrl. Only http or https can be used.
Validation invalidFlexCliUnsupportedVariableType {0} is not a supported variable type
Validation targetInterfaceInvalidName Interface used for SLA monitor must have a logical name
Validation cloudEventsCanNotBeToggled Cannot toggle cloud event.
Validation invalidFMCConnectivityInterfacePPPoENotSupported PPPoE is not supported on Connectivity Interface.
Validation HTTPNoProxyServer proxyServer must not be null, Please enter the proxy server IP address.
Validation invalidVariableName The name "{0}" is invalid. The name can start with an alphanumeric character or an underscore. It can contain the special characters +, _ and -
Validation PullUpgradeFailed Pull Upgrade job failed
Validation pppoeCannotAddBridgeGroupInterfaceMember Interface {0} is a member of BridgeGroup Interface {1}. You cannot enable PPPoE on it.
Validation ruleUrlCatStateDeleted {0} rule must not contain an URL Category whose state is DELETED.
Validation InvalidRuleId Could not find a rule with the ID of {0}.
Validation mismatchedOrdinal Ordinal should remain same on update
Validation invalidSmartCliNumericMinValue {0} value cannot be less than {1}
Validation AccessRulesWithDeprecatedCategories Some of the access rules refer to deprecated URL Categories. Number of access rules affected: {0}
Validation performanceTiersNotChanged Performance Tier is the same as currently applied.
Validation lspInstallerFailed Snort 3 rule package installation failed: Package installer failed with a exception.
Validation acRuleDestTcpPortWithOtherSrcPort When you specify destination TCP ports, the source ports should either be empty or contain at least one TCP port
Validation cryptoNonCompliantIkev1PolicyForGroup The upgraded IKEv1 policies use either of DH groups 1 or 2 which is not supported on this FTD version: {0}.
Validation nestedReferenceCircle A circular reference is found between nested entity {0} and {1}
Validation snmpHostMaxCount Max count of SNMP Hosts is 4000.
Validation SSLPolicyNoDecryptCAForResign You must identify an internal CA certificate to use for decrypt re-sign rules in the SSL decryption policy
Validation bridgeGroupInterfaceReferencedInSyslogServer The following Interfaces are used in Syslog configuration: {0}. This feature is not compatible with a bridge group member interface. You must remove the interfaces from the configuration before you can add them to the bridge group.
Validation cannotChangeDescriptionOfDynamicDNSTrustedCAGroup You cannot change the description of Dynamic-DNS-Trusted-CA-Group.
Validation ConfigErrors There are some configuration errors. Please fix them, deploy the configuration, and proceed with the upgrade. Check the pending changes for items that might need attention.
Validation webCertAlreadyExists A Web Server Certificate already exists.
Validation DuplicateInstanceName Duplicate Instance name found.
Validation cannotHaveNullCertForPolicyWithActiveRule Cannot have a null certificate for Identity Policy which has an active rule
Validation objectUsageInvalidNameParam Name parameter used in object usages search for type "{0}" is invalid.
Validation hostBlank Host must not be empty or blank.
Validation RuleGroupCustomIDNotAllowed Custom rule groups do not support custom IDs.
Validation manualNatDnsNotAllowedWithDest You cannot enable DNS reply translation when doing destination address translation
Validation cloudRegionUnsupportedMethod You cannot create, update, or delete cloud regions.
Validation InvalidClassType Un-supported class type found in rule: {0}. Supported class types for the installed LSP are [{1}].
Validation sruUpdateError_11 Not enough disk space on root/Volume
Validation useHostForSingleAddress Use Host to specify a single address.
Validation manualNatSrc66HostInTransSrcNotAllowedWithSubnetInOrigSrc The IPv6 host object "{1}" in the translated source is not allowed with an IPv6 subnet object "{0}" in the original source
Validation parentInterfaceIsPassive You cannot create a subinterface on the Passive interface {0}
Validation adiCliTestUnknownFailure The connection test failed with an unknown error.
Validation invalidKey Invalid key.
Validation s2sCryptoRestrictedIkev2Policy Your licensing setting does not allow to enable IKEv2 policy with strong encryption. Please use DES only
Validation appFilterInvalidCatValue Invalid application filter category value {0}.
Validation linkLocalIPAddressNotAllowed The IP address {0} cannot be a link-local address
Validation manualNatStaticRuleEmpty No network or port translation is specified with static NAT rule
Validation invalidEigrpRouteMapInterfaceVrf Interface {0} used in route map should belong to the virtual router {1}.
Validation aaaUsernameCannotContainSpaces Username cannot contain spaces
Validation deleteDepStatusObj Cannot delete on-going Deployment Status object: {0}
Validation cannotDisableRegenAfterFailure You cannot disable regeneration deployment mode. There was a deployment failure, and the system must perform a successful full deployment (forceRefreshDeploymentData=true) before partial deployments are possible again.
Validation aaaUpdatingProtocolType Updating the protocol type for a rule is not supported
Validation staticRouteWrongNetworkType Wrong network type for static route: {0}
Validation passwordNoNumber Password does not contain a number
Validation loopbackAddressNotAllowed The IP address cannot be a loopback address.
Validation DeviceSetupAlreadyDone The initial device setup is complete. You can now manage the device and change the configuration.
Validation autoNegNotALlowedWithSelectedInterfaceSpeed AutoNeg cannot be set to True when interface speed is lower than 1g, or interface speed is set at 10g.
Validation AnyConnACPkgInvalid AnyConnect client package {0} is invalid for the given platform
Validation vtiMaxLimit You cannot create more than {0} Virtual Tunnel Interfaces.
Validation acRuleUrlCatRepBothNull URL category and reputation are both any or null in one of the URL matchers
Validation invalidUuid Validation failed due to an invalid UUID: "{0}"
Validation disabledEtherChannelHAInterface EtherChannel {0} must be enabled.
Validation snmpInvalidEncryptionAlgorithm Encryption algorithm can not be null for SNMP users with security level AUTH and PRIV.
Validation contextStatusFailed Could not retrieve device registration context status. Please try again later.
Validation manualNatOrigDestHasIpv6AndIpv4Addresses The original destination network should not contain both IPv4 and IPv6 addresses
Validation CannotUpdateSystemDefinedIntrusionPolicy You cannot update an intrusion policy that is defined by the system.
Validation invalidMalwareLicenseForFileRule Missing Malware License. A file rule that stores files, or that uses the MALWARE_BLOCK or MALWARE_CLOUD_LOOKUP actions, requires this license.
Validation manualNatSrc46AnyIpv6NotValid The network corresponding to the full range of IPv6 addresses, i.e. ::/0, cannot be used in the source of an IPv4 to IPv6 manual NAT rule
Validation ipsecNoEnabledIkev1Policies Cannot disable or delete IKEv1 policy, need at least one policy active while a site-to-site connection profile using IKEv1 exists
Validation invalidEtherChannelHAInterface EtherChannel {0} must have at least one physical interface member.
Validation FMCHostOrNatIdRequired Either FMC Host/IP Address or NAT ID is required.
Validation acRuleUnnamedInterfaceInDestZone Destination security zone {0} contains an un-named interface that cannot be used in an access rule
Validation passwordCannotBeNull Password field cannot be null
Validation AnyConnProxyExceptListTooLong All addresses and ports in the proxy exception list combined can be no more than 255 characters
Validation acPolicyInvalidIdentityPolicyWithDisabledRealm You cannot configure the identity policy with a disabled realm.
Validation AnyConnIOErrorXMLFile {0} error while reading file.
Validation RaVpnGroupPolicyDeleteDefaultGP Default Group Policy (DfltGrpPolicy) cannot be deleted.
Validation certKeyTypeEmpty You must specify whether this file is a certificate or key. Please set the fileType to cert or key.
Validation invalidSlaTimeout The timeout value has to be between 0 and 604800000 milliseconds (7 days)
Validation manualNatSrc46Ipv6HostObjNotAllowedInTransSrc You cannot use an IPv6 host network object as the translated source in an IPv4 to IPv6 manual NAT source translation rule: {0}
Validation snmpUsersGroupHostType User Group as SNMPAuthentication cannot be provided for SNMP Host with v3 security configuration.
Validation InvalidBgpNeighborMigrationRemoteAsBgpAsNumber Cannot have remote-as number same as BGP AS number.
Validation vdbUpdateError_2 No valid support contract found. Contact sales or support for more information
Validation natOrigMappedPortsAreNotBothTcpOrBothUdp The original and translated ports should be either both TCP ports or both UDP ports
Validation duplicateZone Selected interface is already assigned to security zone {0}
Validation variablesetmodify Cannot add a new or delete an existing variable.
Validation switchModeNotSupportedOnInterface Switch mode is not supported on this interface.
Validation ipAddressRangeIsBlocked The IP address {0} is part of an internally reserved range, (from={1} to={2}), please choose an address outside this range.
Validation invalidBgpRedistribution Redistribution for {0} is not supported for user defined virtual router.
Validation BinderRuleInstanceInvalid Instance name/type combo is invalid.
Validation deleteUmbrellaDnsServerGroup You cannot delete the system-defined CiscoUmbrellaDNSServerGroup object.
Validation InvalidMalwareLicenseForCloudRegistration Missing Malware License. This license is required for registering with another AMP cloud.
Validation passwordDictWord Password contains a dictionary word
Validation onlyStandardOrExtendedAccessList The list should contain either all Standard Access List objects or all Extended Access List objects
Validation invalidThreatLicenseForFilePolicy Missing Threat License. The associated file policy or rule requires this license.
Validation snort3IntrusionRuleNotFound Can not find the intrusion rule {0} for the current version.
Validation objectNat46Ipv6HostObjNotAllowedInTransAddr You cannot use an IPv6 host network object as the translated address in an IPv4 to IPv6 auto NAT rule: {0}
Validation manualNatDest64PrivateIpv4IsNotAllowedWithNat46WellKnownPrefix The private IPv4 address "{1}" in translated destination "{0}" is not allowed with the well known NAT64 prefix "64:ff9b::" in the original destination
Validation acRuleMixedIpv4v6AddressInDestNetworks Destination networks contain both IPv4 and IPv6 addresses
Validation cloudRegionIsRequiredForEnrollment You should specify the cloud region when enrolling with the cloud.
Validation policyRuleIdNotEditable The policy rule ID cannot be modified by editing the rule. Current rule-ID in the DB is {0}, rule-ID from request is {1}
Validation AnyConnNoCAServerCert CA Server certificate is required
Validation invalidToken The format of the provided token is invalid. The length of the token must not exceed 140 characters
Validation RangeInvalidStart Invalid Start Address
Validation invalidOspfAreaTypeVLConfiguration Virtual link cannot be configured on areas of type NSSA or Stub
Validation cannotCreateFMCRegistrationSettingsInHAMode Your device has HA enabled. HA is not supported with this feature.
Validation manualNatDest46Ipv6HostCountTooHigh The IPv6 host count {0} in the translated destination exceeds the maximum allowed {1} in an IPv4 to IPv6 manual NAT destination translation
Validation invalidLoggingListProvideStartId Please provide message start ID.
Validation manualNatDest64Ipv6RangeObjNotAllowedInOrigDest You cannot use an IPv6 range network object as the original destination in an IPv6 to IPv4 manual NAT destination translation rule: {0}
Validation invalidSecretKey Secret Key field should contain only Alpha-Numeric characters with length equals 40.
Validation RuleNameMustUnique A custom rule: {0} with same GID:SID already exists in the database, rule creation failed.
Validation smartAgentMakingAlreadyInProgress Smart Agent making already in progress.
Validation invalidSyslogProtocol Invalid protocol for Syslog Server. Protocol must be either TCP/UDP.
Validation invalidQualifiedPath "{0}" is not a valid qualified path. A quailified path must resemble a file path beginning with a forward slash and can have alphabets, numbers, underscore, or forward slash.
Validation attemptToChangeNoneditSubInterfaceId Validation failed, attempt to change a non-editable subinterface ID
Validation invalidDHCPRelayInterface Interface used for DHCP Relay Service is null.
Validation invalidOspfInterfaceBviSelected You cannot enable OSPF on a bridge group or bridge group member interface.
Validation ftdUpdateMgrError_238 Cancel upgrade in progress. Cannot retry.
Validation s2sOutsideIntfNotNamed Site-to-Site VPN outside-interface does not have logical name: {0}
Validation invalidObjectForNotInDHCPRelayInterfaceAnnotation Validation could not be performed successfully. Field is not of the correct type for annotation.
Validation unsupportedMemberInterfaceType Member interfaces in EtherChannels can only be physical interfaces.
Validation cleanOrCustomListFileInvalidEntries Invalid entries. Each entry should contain a single SHA-256 value followed by a description.
Validation RaVpnConnectionProfileExists There is one or more RAVPN Connection Profile(s) still on the device. Please remove all of them before removing RAVPN configuration.
Validation cleanOrCustomListFileInvalidType Invalid file type. The uploaded file must be a simple text file with a .csv file name extension and with entry containing a single SHA-256 value followed by a description.
Validation invalidTemplate The template "{0}" is invalid. The name can start with an alphanumeric character or an underscore. It can contain the special characters +, ., _, -, '{{', and '}}'
Validation packageDownloadSuccess Pre-toggle update succeeded.
Validation ftdUpdateMgrError_241 Upgrade was interrupted by system restart. Use the 'upgrade cancel' API to cancel.
Validation invalidHAFailoverPeerPollTime Peer poll time must be between 200 and 999 milliseconds, or 1 and 15 seconds.
Validation securityIntelligenceBlacklistPolicyUnsupportedNetwork The Security Intelligence Block list contains an unsupported network : {0}
Validation natTranslatedDestNetworkObjNotSupported The translated destination does not support this network object.
Validation interfaceMigrateSourceAndDestinationCannotBeMembersOfVlanInterface Source and destination IDs cannot belong to members of a VLAN Interface.
Validation staticRouteNetworkAddressMatchesInterfaceAddress This IP address is associated with the Static Route and can not be the same as IP address of the interface {0}.
Validation AnyConnAuthMethodMustBeAAAAndClientCertificate Auth method must be {0} for Prefill username from certificate on user login window
Validation resetCannotBeTrueWithRuleAction File Rule validations failed. Reset can be true only for BLOCK_FILES and MALWARE_BLOCK rule actions.
Validation moreThanOneISE You cannot create more than one ISE configuration
Validation CryptoRestrictedSSLCipher Data SSL Cipher Settings uses SSL Ciphers with strong encryption, which is not allowed by your licensing setting.
Validation geoUpdateError_7 Peer certificate cannot be authenticated with known CA certificates
Validation intfMigrationExportFailed Failed at export step. Unable to export the configuration due to error {0}
Validation snmpServerNameCannotBeUpdated SNMP Server name can not be updated.
Validation s2sVTIOnly1Allowed If you enable static VTI, you must select a single interface for a site-to-site VPN connection.
Validation vtiMTUMustBeSameAsSourceMTU The MTU value for a VTI must be the same as the MTU value for the associated tunnel source interface, which is {0}.
Validation invalidSmartCliPrefixListValue {0} entity value must be an existing IPv4 or IPv6 Prefix List Object
Validation acPolicyDefaultActionIsNull The access policy default action setting is null
Validation containsInvalidChar the field cannot contain the following character ';'
Validation redundantTokenForEnrollmentViaSmartLicense You should not specify the token when enrolling with the cloud using Smart License.
Validation manualNatSrc64Ipv6PrefixTooShort The original source IPv6 network prefix length must be greater than or equal to 64 in an IPv6 to IPv4 manual NAT source translation: {0}
Validation invalidSmartCliBooleanValue {0} value must be set to either true or false
Validation anyIPWithoutPrefix The IP address requires a prefix.
Validation invalidFlexCliUnsupportedAsciiText Non-printable ASCII text detected. If you are using copy/paste, some hidden ASCII characters might be included. Please try a different source editor, or type in the required text
Validation dadIsOutOfRange DAD (Duplication Address Detection) attempts must be between 0 and 600
Validation removedInterfaceCannotBeEnabled Interface {0} is no longer present and cannot be enabled
Validation staticRouteWrongOptionalGateway Gateway is mandatory when the egress interface belongs to the same virtual router as route you are defining.
Validation cryptoNonCompliantIkev1ProposalForAuthMethod The upgraded IKEv1 proposals use ESP_MD5_HMAC authentication which is not supported on this FTD version: {0}.
Validation invalidEigrpIpv4Address Only IPV4 networks are allowed.
Validation dhcpAutoConfigEnabled DHCP Relay Agent cannot use the same interface {0} used for DHCP Server auto-config.
Validation commonInterfaces Both a DHCP Relay Agent and a Server cannot be configured on the same interface {0}. DHCP Relay service cannot receive DHCP requests and forward them on the same interface.
Validation bridgeGroupInterfaceMemberEmptyName Bridge Group interface member {0} cannot have empty name
Validation AnyConnDnsInvalid {0} is not a valid IP and not a valid DNS server
Validation interfaceNameEmptyForMonitoring You can monitor an interface only if the interface has a name.
Validation DuplicateEntry Duplicate entry found for Intrusion Rule with ID {0}.
Validation SecurityIntelligenceDNSPolicyBlacklistContainsWhitelistItem DNS policy Block rules cannot contain Do Not Block rules.
Validation networkInterfaceModuleFieldsReadOnly You cannot edit the read-only fields of the Network Interface Module. You may only edit the enabled field for the Network Interface Module.
Validation sruUpdateError_7 Peer certificate cannot be authenticated with known CA certificates
Validation SystemDefinedRuleGroupNotAllowed Cannot associate a custom rule with system-defined rule group: {0}.
Validation bgpGracefulRestartTimeWithoutGracefulRestart Graceful restart should be enabled before setting restart time
Validation broadcastAddressNotAllowed You cannot assign a broadcast address as the IP address of an interface.
Validation interfaceCombineNeedsDeployment Interface {0} has pending changes. You must deploy the changes before you can combine it.
Validation invalidAAARadiusMaxFailedAttempts Max Failed Attempts must be in the range 1 to 5
Validation acRuleTimeRangeObjectInvalidSize Only one TimeRange Object should be associated with an ACL policy.
Validation multicastAddressNotAllowedAsFMCHost FMC Host of "{0}" cannot be a multicast address.
Validation bridgeGroupMemberInterfaceReferencedInVirtualRouter The following interfaces are referenced by Virtual Router: {0}. This feature is not compatible with a bridge group member interface. You must remove them before you can add the interfaces to a bridge group.
Validation nullValue Value cannot be null.
Validation ipsecCryptoRestricted Usable cryptography types are currently restricted by the licensing status of the device
Validation missingCertificates Missing the following certificate from the trust chain: {0}
Validation haMandatoryDeploymentNeeded Before attempting {0}, you must complete a successful deployment job.
Validation dnsServersMaximumLimit A maximum of two IPv4 and two IPv6 DNS servers is allowed.
Validation ftdUpdateMgrError_133 Update type missing or invalid.
Validation invalidNatId NAT ID of "{0}" is invalid. It can start with an alphanumeric character or an underscore. It can contain the special characters +, ., _ and -
Validation snort3ToggleSuccessWithUpdate Successfully switched to Snort version 3 with rule package updated.
Validation DHCPServerAutoConfigServer You cannot define a DHCP server on the same interface used for the auto config default interface: {0}
Validation invalidSlaId ID value must be between 1 and 2147483647.
Validation s2sDupBackupPeerIpAddr Duplicate IP address found in two or more backup peers. Provide unique backup peer addresses.
Validation RACPrfInsideIntfHasNoName The interface {0} added to RaVpn should have a logical name.
Validation manualNatRouteLookupAndIntfInTransSrc You cannot select the Perform Route Lookup option if you select interface for translated source
Validation duplicateTunnelID Tunnel ID {0} is already used by tunnel "{1}"
Validation AccessRulesWithDeletedCategories Some of the access rules refer to deleted URL Categories. Number of access rules affected: {0}.
Validation invalidAuthType Invalid authentication type in identity rule. Only Basic, NTLM, Negotiate and Response page methods are supported.
Validation insufficientDiskSpace Insufficient disk space.
Validation vdbUpdateError_13 Unable to update VDB database, please retry the update
Validation interfaceUsedInAAA Interface name cannot be empty. It is used in RADIUS server "{0}"
Validation SSLRuleNullEventLogAction You must specify an event logging action for the SSL rule
Validation dupliacteTemplateIdentifier A template with same identifier already exists. {0}
Validation invalidSmartCliEnumValuesNull Allowed enum values cannot be null or empty
Validation invalidFlexCliMissingVariable Referenced variable {0} is not configured
Validation manualNatTranslatedDestHasIpDNSMismatchWithTranslatedSrc The DNS resolution for the FQDN used in the translated destination must include an IP address of the same version (IPv4 or IPv6) as the translated source address
Validation NoRuleImportFile You must specify a file to upload.
Validation acRuleMixedIpv4v6AddressInSrcNetworks Source networks contain both IPv4 and IPv6 addresses
Validation bgpInvalidHoldTime Hold time should be greater than keep alive time
Validation haDeploymentCouldNotAutoRecover Could not auto-recover, check logs for details. Please retry {0} deployment.
Validation interfaceBreakoutCreate An error occurred while breaking out Network Module interface {0}
Validation invalidSlaNumOfPackets The number of packets has to be between 1 and 100.
Validation connectorGenerateTokenError Connector token was not generated.
Validation bridgeGroupInterfaceInvalidCreation Cannot create more than one Bridge Group Interface. Please delete the existing one before creating a new Bridge Group Interface.
Validation interfaceInDHCPServerOverlapsNetwork The following interfaces have overlapping subnets and a DHCP server is already configured on one of them: {0}
Validation regexPatternNotUnique Regular expression pattern should be unique across all entries.
Validation interfaceInDHCPRelayService The interface {0} is already configured as part of the DHCP Relay Service. You must remove it before adding it to a bridge group.
Validation s2sCryptoRestrictedIkev1Policy Your licensing setting does not allow to enable IKEv1 policy with strong encryption. Please use DES only
Validation invalidOspfExceededLimit Only two OSPF processes are allowed per virtual router
Validation invalidSmartCliDependentEnabled You cannot enable a dependent command when the parent command is disabled
Validation intfMigrationExportUnableToCreateSqliteFile Unable to create the sqlite file.
Validation cryptoNonCompliantIkev2PolicyForGroup The upgraded IKEv2 policies use either of DH groups 1, 2 or 24 which is not supported on this FTD version: {0}.
Validation subinterfacesCannotContainAnotherSubinterface A subInterface cannot contain another subInterface.
Validation diskFileNameIncorrectExt Disk file name extension is not {0}: {1}
Validation invalidSmartCliIPV6PrefixListValue {0} entity value must be an existing IPv6 Prefix List Object
Validation s2sBackupPeerIkev1InvalidKey Invalid IKEv1 pre-shared key. It must contain 1-128 ASCII printable characters, no whitespace, no single or double quotation marks, no question marks and cannot be a single digit
Validation createWithUuid Validation failed, attempting to create a new object while specifying a UUID
Validation wrongObjectUsagesTypeParam Type parameter is of the wrong class type.
Validation cannotCreateWithUnnamedInterface You cannot create or edit an identity realm object to contain a directory configuration using unnamed interface.
Validation RuleGroupOverrideSecurityLevelNotAllowed Custom intrusion rule group must not include an override security level.
Validation acRuleSrcUdpPortWithOtherDestPort When you specify source UDP ports, the destination ports should either be empty or contain at least one UDP port
Validation missingRealmInPassiveAuthIdentityRule No realm found in an identity rule that uses the Passive Auth action.
Validation AnyConnProxyServerNull Proxy Server Address/host cannot be null
Validation DHCPServerSecondaryWINSOnly DHCP server secondary WINS server cannot be specified unless a primary WINS server is also specified
Validation unsupportedIkevOneGroup The following Diffie-Hellman groups are not supported in IKEv1 policies: 1, 2.
Validation CanNotUpdateAParentGroup You cannot update a parent group:{0}
Validation objectNat66HostInTransAddrNotAllowedWithSubnetInOrigAddr The IPv6 host object "{1}" in the translated address is not allowed with an IPv6 subnet object "{0}" in the original address
Validation bgpInvalidASNumberUpdated Cannot change as-number when editing BGP protocol
Validation deploymentInProgress Could not initiate upgrade: deployment is in progress. Please wait for deployment to finish, then try again.
Validation dhcpEnabled DHCP Relay Service cannot be enabled if the DHCP Server feature is also enabled on any interface.
Validation invalidLoggingListRangeCollision Message ID/range overlaps with existing range.
Validation AnyConnDnsMissing At least one DNS has to be provided for AnyConnect VPN profile
Validation smartAgentManagerCannotBeRemade SmartAgentManager cannot be remade
Validation updateCertAndKey You must update both certificate and private key.
Validation interfaceMigrateDestinationMustBePresent Destination ID must belong to a present interface.
Validation s2sLifetimeSec Site to Site profile Lifetime Range should be between 120 and 2147483647 seconds
Validation noIntrusionRuleFound Cannot find a intrusion rule with provided UUID.
Validation vlanInterfaceNotAllowedWhenSecurityZoneInPassive Security zone in passive mode cannot have VLAN interfaces associated with it.
Validation acPolicyInvalidDefaultActionWithNullIps Invalid default action {0}, only Block or Trust is allowed without intrusion inspection
Validation duplicateOrdinal Validation failed due to duplicate Ordinal
Validation s2sInsideIntfNotNamed Site-to-Site VPN inside interface for NAT exempt does not have a logical name
Validation ipsecDupIkev2Integrity Cannot have duplicate integrity methods
Validation invalidV6StartMapped IPv4-mapped IPv6 as start address is not supported.
Validation AnyConnNullRealmEncryptionType Realm server encryption type cannot be null
Validation unsupportedNGFWInterfaceDuplex Unsupported NGFW Interface Duplex on SSP platform
Validation cannotMoveContainedEntityToDifferentContainer The contained entity cannot be moved to a different container in an update request
Validation IOCSystemDefinedNAPUpdate You cannot update the inspector override config of a TALOS defined Network Analysis Policy.
Validation upgradeCancelOnFailureNotAvailable Parameter {0} is not available for this upgrade image.
Validation invalidFlexCliLineBlacklist Block list CLI error: {0}
Validation DHCPIntfModeIsPassive You cannot configure a DHCP server on a passive mode interface.
Validation invalidObjectForNotMemberInterfaceAnnotation Validation could not be performed successfully due to a server issue. Please reach Cisco Technical Support.
Validation contextDeletionFailed Unregistration process failed. Please try again later.
Validation noRetryScript The script to retry upgrade is not available at this stage.
Validation incompatibleStartEndAddress Start and End Addresses must be the same IP type.
Validation realmIdChanged The realm ID cannot be modified
Validation AnyConnOutsideIntfInDIMA The selected outside interface is currently being used in a management access list and cannot be simultaneously used for AnyConnect VPN
Validation s2sRRIMulitpleInterface Reverse Route cannot be enabled on multiple interfaces
Validation DapXmlUserMssgInvalid DAP user message cannot exceed more than 490 characters
Validation invalidAAARadiusGroupDeadtime Dead Time must be between 0 and 1440 minutes
Validation invalidOspfDuplicateBackbone A backbone area already exists in the configuration
Validation RaVpnGPSplitDomainsRequired Split DNS Domains have to be specified.
Validation certificateKeyMismatch Certificate and Private key do not match
Validation vdbUpdateError_0 VDB successfully updated
Validation ntpNotFound Cannot find NTP settings.
Validation invalidFMCConnectivityInterfaceType Invalid type of interface selected.
Validation objectNat64Ipv6PrefixTooShort The original address IPv6 network prefix length must be greater than or equal to 64 in an IPv6 to IPv4 auto NAT rule: {0}
Validation manualNatDest66TransDestPrefixShorterThanOrigDestPrefix The IPv6 prefix of the translated destination subnet "{0}" must be greater than or equal to the IPv6 prefix of the original destination subnet "{1}"
Validation Neo4JConfFileParsingFailed Configuration file for neo4j was either not found or there was a failure while parsing it.
Validation AnyConnServerCertNeedsSubjectCommonName The Server certificate {0} requires subject common name
Validation SSLRuleTls13OnlyOnSnort3 TLS 1.3 requires Snort version 3
Validation baseRealmDisabled The realm used in the identity rule has been disabled.
Validation missingUuid Validation failed due to an invalid UUID: null
Validation vpnOnlyWithPlusOrApex VPN-only license cannot be enabled with PLUS or APEX
Validation interfaceIsMemberOfBGI Interface {0} cannot be a member of a Bridge Group Interface and be used by DHCP Relay Service at the same time.
Validation invalidRegistrationKey Registration Key of "{0}" is invalid. It can start with an alphanumeric character or an underscore. It can contain the special characters +, ., _ and -
Validation PullFileExtensionFailed This file extension {0} is not supported for the given fileType {1}.
Validation invalidVariableSetInstance Instance does not match with the template it uses. Found mismatch in the properties "{0}" of SmartCLIVariableSet having qualifiedPath "{1}".
Validation staticRouteInconsistentNetworkProtocol Static route inconsistent protocol version for network: IPv4 vs IPv6 {0}
Validation noPcbSerialNumber Cannot register because serial number is unavailable; try again.
Validation haLinkNotOnSameSubnet The primary and secondary addresses of {0} must be on the same subnet.
Validation deviceMustBeSmartLicensed Device must be Smart Licensed when enrolling with {0} account.
Validation AnyConnExcessPackages Can have only one AnyConnectPackages
Validation missingRealmInActiveAuthIdentityRule No realm found in an identity rule that uses the Active Auth action.
Validation unsupportedIkevTwoGroup DH Groups DH1, DH2 and DH24 are not supported in IKEv2 Policies.
Validation ftdUpdateMgrError_131 Invalid update mode.
Validation manualNatSrc46Ipv4AnyIsNotAllowedWithNat46WellKnownPrefix The original source cannot be IPv4 "any" with the well known NAT46 prefix "64:ff9b::" in the translated source
Validation NoValidAction Un-supported rule action [{0}] found in rule: {1}. Supported rule actions are ALERT and DROP.
Validation IntrusionRuleGroupNotFoundWithName Unable to find the IntrusionRuleGroup with name: {0}.
Validation appFilterInvalidProductivityName Invalid application filter business relevance name {0}.
Validation RuleGroupHasOrphanRuleHasOverride Failed to delete Intrusion Rule Group: {0}. With cascadeDelete option, rule group along with rules that only belong to this group are deleted. Remove overridden state from rules before deletion.
Validation expiredCertificatePaste The certificate has already expired. Please enter an unexpired certificate.
Validation indexListSizeIncorrect Error when getting the indices of the filtered container objects.
Validation couldNotInitializeUpgrade Could not initiate upgrade.
Validation sruUpdateError_1 Connectivity problems. Unable to download the rule update. Please try again later.
Validation invalidObjectForNotHaInterfaceAnnotation Invalid object type for NotHAInterface annotation.
Validation invalidSyncType This is an invalid value for syncing. If you would like to sync, please set sync to be true
Validation unsupportedFecMode Forward Error Correction mode {0} is not supported on this platform.
Validation passwordNoSpecial Password does not contain a special character
Validation invalidEmptyFqdn The fully-qualified domain name is empty. Please specify a name.
Validation NapNotSupportedInSnort2 Network Analysis Policies are not available in Snort 2.
Validation lspInstallScriptMissing Failed to locate an install script for LSP package installation.
Validation invalidSmartCliNetworkValue {0} entity value must be an existing NetworkObject or NetworkObjectGroup
Validation etherChannelDuplexMatchMemberInterfaceDuplexCapability EtherChannel duplex must match member interface duplex capability.
Validation invalidInterfaceForPolicyList A policy list cannot include passive interfaces or bridge group member interfaces or an interface which is part of the high availability configuration.
Validation invalidIntegrationObject Integration target object is inValid.
Validation DHCPServerInvalidName DHCP server is already configured on this interface: {0}
Validation manualNatDest64DynamicNotAllowed Dynamic NAT is not allowed in a manual NAT rule for IPv4 to IPv6 destination address translation
Validation duplicateValidationUsage Validation usages should not contain duplicates.
Validation bridgeGroupInterfaceMemberHasDHCPIpv4Address Bridge Group interface member {0} cannot contain a DHCP IPV4 address
Validation invalidConnectionTypeUpdate Connection type can be updated only in Evaluation Mode. For other cases you have to unregister and register with a desired connection type.
Validation UnlockDeviceProvidedEulaIsNotCorrect The provided End User License Agreement does not match with the End User License Agreement from the server.
Validation natDynamicRuleNotSupportRouteLookup Dynamic NAT does not support the Perform Route Lookup option
Validation performanceTiersNotSupported Performance Tiers are not supported on current platform
Validation facAddPerlGeneralError An unexpected error occurred while creating a Firepower Analytics Center entity
Validation duplicatesClasses Duplicate classes: {0} are not allowed.
Validation attemptToChangeNoneditVlanInterfaceId Validation failed, attempt to change a non-editable vlan interface ID.
Validation bgpInvalidASNumber The AS number in BGP should be same as AS number configured in BGP General Settings.
Validation XmlConfigNotBase64Encoded XML configuration must be Base64 encoded
Validation geoUpdateError_0 GeoDB successfully installed
Validation InvalidPredefinedUserVrfName Virtual Router with name {0} is predefined and cannot be used.
Validation eciMemberInterfacesCannotHaveSubInterfaces EtherChannel member interfaces cannot contain physical interfaces that have subinterfaces.
Validation RaVpnSpecialIdentityNotAllowed Special-Identities-Realm not allowed as IdentitySource for RAVPN.
Validation ipsecEmptyIkev2Encryption There must be at least one method of encryption
Validation timeRangeInvalidDailyInterval The daily interval specification is incomplete. To configure a daily interval, you must specify the days, the daily start time, and the daily end time.
Validation vtiIPv6NotSupported IPv6 is not supported on this interface, please remove the ipv6 field and try again.
Validation activeAuthCertInvalidStartEndDate The value or format of the start or end date of the uploaded certificate is invalid
Validation SSLRuleNeedVersion Need at least one SSL/TLS version checkbox selected
Validation emptyGroup A group should contain at least one object.
Validation bridgeGroupInterfaceMemberHasIpv4Address Bridge Group interface member {0} cannot contain IPV4 address
Validation cryptoCompliantS2SIkev1Proposal The S2S VPN connection profile {0} is using IKEv1 proposals with strong encryption which is not allowed by your licensing setting, please de-reference them and use DES only: {1}
Validation interfaceCannotHaveIpv4AddressOfBgpNeighbor An interface cannot have the same IPv4 address as a neighbor in BGP.
Validation invalidOspfBackboneArea A backbone area cannot be of type nssa or stub
Validation DapXmlRecordNameInvalid DAP record name must be between 4 and 64 characters
Validation mntCertNotFound MNT Certificate not found.
Validation lockInvalidLock Attempting to acquire an invalid lock: "{0}"
Validation unsupportedIkevTwoEncryptionStrong The following encryption algorithms are not supported in IKEv2 policies when strong encryption is enabled: DES.
Validation sruUpdateError_3 The update server did not have a file applicable to this device. Try again later. If the problem persists, contact Technical Support.
Validation IntfTypeInvalid A virtual router can include physical or subinterfaces only. Interface {0} is of an unsupported type.
Validation unsupportedMethodForCurrentDelegate The following method is not supported for this Smart Agent Delegate.
Validation adminFecCanBeSetOnlyToAutoWhenAutoNegIsEnabled Updating interface {0} FEC mode to a different value than AUTO is not allowed when auto negotiation is enabled.
Validation unsupportedIkevTwoIntegrity The following integrity hashes are not supported for IKEv2 Policies: MD5.
Validation SecurityIntelligenceDNSPolicyNoFeedProvided You must specify at least one DNS object (feed, category, or list) on a DNS rule.
Validation nullBgpNeighborFilteringMaximumPrefixLimitOption Neighbor Maximum Prefix Option can not be null.
Validation packageOutOfDate Uploaded package version is lower than the one present on device. Skipping upload.
Validation lspVersionLowerThanMin LSP installation failed because the candidate package has a lower version than the minimum compatible version[{0}] allowed by the current system software.
Validation invalidGateway The Gateway entered is invalid
Validation invalidOspfRedistOspfSelfIdentifier Identifier cannot be Process ID of the same OSPF process
Validation ipsecEmptyIkev2Integrity There must be at least one method of integrity checking
Validation failedToExportPendingChangesToFile Unable to export pending changes to the file.
Validation networkAddressNotAllowed You cannot assign a network address "{0}/{1}" as the IP address of an interface.
Validation manualNatSrcIntfIpv6DisabledWithIpv6InOrigDest Source interface "{0}" is not IPv6 enabled. You cannot use IPv6 addresses in the original destination
Validation invalidOspfAreaRange 0.0.0.0/0.0.0.0 represents default and cannot be added as a range
Validation sysInfoFileNotFound Unable to find file {0}
Validation postUpgradefeaturelistChanged The featureList in PostUpgradeFlags cannot be modified.
Validation PullUpgradeInitiated Pull upgrade job initiated
Validation raVpnConnectionProfileDhcpServerMaxLimit A maximum of 10 DHCP servers is allowed.
Validation geoUpdateError_16 This version of GeoDB is already installed.
Validation SSLPolicyAppMustHaveSSL SSL rule cannot contain applications that do not use SSL
Validation invalidSmartCliIPV4PrefixListValue {0} entity value must be an existing IPv4 Prefix List Object
Validation ftdUpdateMgrError_243 Retry is not allowed. Contact Cisco TAC.
Validation httpsPortCannotConflictSshPort HTTPS Port cannot conflict with default SSH port value 22.
Validation bridgeGroupInterfaceCannotHaveIpv4AddressOfBgpNeighbor This IPv4 address is part of a neighbor that is being used in the BGP configuration. You cannot assign the same IPv4 address to a bridge group interface.
Validation invalidMetricsGroups At least one metrics group should be configured.
Validation haBreakFromConfig The units in this HA pair are synchronizing configuration. You cannot execute {0} until synchronization is complete.
Validation invalidLoggingListParams Please provide either log level or message ID.
Validation invalidSmartCliRouteMapValue {0} entity value must be an existing Route Map Object
Validation s2sVTIMaxUniqueIpsecProfiles You cannot create more than {0} unique IPSec profiles. Uniqueness is determined by the combination of IKEv1/v2 proposals and certificates, connection type, DH group and SA lifetime. You can reuse existing profiles.
Validation s2sIkev2NoEnabledPolicy Cannot enable site-to-site IKEv2 without enabling any IKEv2 policy
Validation PullUnknownError Some unknown error occured
Validation IntrusionRuleOverrideStateCannotBeNull You must specify an override state.
Validation CannotDeleteNap You cannot delete a Network Analysis Policy.
Validation ipsecMixedCombinedNormalEncryption Cannot mix combined mode (GCM) and normal mode encryption in an IKEv2 policy
Validation ecmpZonesWithIdentityRules You should configure the same Identity Rules to all ECMP Traffic Zone member interfaces. Interfaces from ECMP Traffic Zones: "{0}" should be applied the same Identity Policies. Please make sure you configure ECMP Traffic Zones/Identity Rules accordingly.
Validation InvalidBasePolicySet The Base Policy Set for the Intrusion Policy is not a Cisco TALOS defined policy
Validation operationalLinaCommandError Error while running the configuration command {0}. Response is: {1}.
Validation noRollbackAvailable Cancel upgrade is not available at this stage.
Validation invalidMetricsName Validation failed due to invalid metric-name.
Validation cdoTokenNotNullIfActionNullOrAutoEnrollNetworkParticipation Cisco Defense Orchestrator token should be null if action is 'null' or 'AUTO_ENROLL_NETWORK_PARTICIPATION'
Validation interfaceFieldReadonly {0} is not user configurable, You cannot edit the read-only fields of the Interface.
Validation sruUpdateError_2 No valid support contract. Unable to download the rule update
Validation cannotDeleteRealm Cannot delete any realm
Validation AnyConnNoRealmServer Realm server is required
Validation intfMigrationViolationsExist Violations in {0} object(s). Use API explorer to get the entire list of violations against each object for this task.
Validation unableToInstallReservationWhileReservationAlreadyInstalled A reservation is already installed on this device. You cannot install the reservation again.
Validation expiredCertificateMgmtWebServer The chosen certificate has already expired. Please apply an unexpired certificate.
Validation vtiSourceCannotBeInUserVRF Cannot have a virtual tunnel interface with tunnel source interface "{0}" as the source interface is part of a user VRF.
Validation interfaceIsDHCPClient DHCP Relay Agent cannot use the interface {0} since it is currently configured as a DHCP client.
Validation invalidApplicationProtocolForUpload File Rule validations failed. SMTP application protocol supports only UPLOAD direction of transfer.
Validation invalidFileTypeAndFileTypeCategory File Rule validations failed. None of the file types or file type categories are supported by the specified attributes.
Validation managementInterfaceCannotBeDisabled You cannot disable the Management interface
Validation pxGridCertNotFound pxGrid Certificate not found.
Validation CannotFindNapByUuid Network Analysis Policy specified by uuid {0} could not be found.
Validation SAMLSignAndCert If a signature type is specified, an FTD certificate must be identified in order to perform signature.
Validation invalidV6Compatible IPv4-compatible IPv6 addresses are not supported.
Validation AnyConnInvalidAuthenticationIdentitySource You must select an identity realm or radius group as the authentication identity source if you select Local as the fallback identity source.
Validation timeZoneInvalidTime The DST day recurrence specification is incomplete. To configure a dstDayRecurrence, you must specify the startTime and endTime where start time must be prior to the end time in the format HH:MM.
Validation s2sBackupPeerIkev1MaskedKeyNotAllowed Masked value for IKEv1 pre-shared key is not allowed when creating a new backup peer or updating the IP address for an existing backup peer.
Validation invalidRegexPattern The regular expression pattern is not valid. The pattern must not contain any question marks, or spaces.
Validation ecmpZoneWithConfigAccessRules You should apply the same Access Rules to all ECMP Traffic Zone member interfaces. Interfaces from ECMP Traffic Zones: "{0}" should have the same Access rules. Please make sure you configure ECMP Traffic Zones/Access Rules accordingly.
Validation invalidFMCConnectivityInterfaceNoIP Cannot configure on interfaces without IP address. Assign an IPv4 or IPv6 address to the Connectivity Interface.
Validation EmptySSLCipherProtocolVersionList You must specify at least one SSL Protocol version
Validation stringTooLong The string {0} length exceeds the limit of {1}
Validation IntfAlreadyUsed The interface {0} is already used in another VRF. An interface can be part of only one VRF at a time.
Validation autoNegNotAllowedOnManagementInterface AutoNeg cannot be set for management interface.
Validation nameNull Name must not be null.
Validation invalidAllConfigured Individual metric-groups configuration not required if All is configured.
Validation emptyBypassList The hardware bypass list is empty
Validation unknownValidationError System failed to validate the request due to an internal error, please contact support.
Validation provideAtLeaseOneField You must define at least one option to create a valid certificate.
Validation interfaceNameRequired Interface associated with a syslog server should have a non-empty NAME.
Validation cryptoNonCompliantIkev1ProposalForEncryptionType The upgraded IKEv1 proposals use ESP_3DES Encryption which is not supported on this FTD version: {0}.
Validation interfaceCannotHaveIpv6AddressOfBgpNetwork This IPv6 address is part of a network that is being used in the BGP configuration. You cannot assign an IPv6 address from this network to a management-only interface or subinterface.
Validation RuleGroupDefaultSecurityLevelNotAllowed Custom intrusion rule group must not include a default security level.
Validation maxECMPZoneCountReached You can create a maximum of 256 ECMP traffic zones.
Validation emptyInterfaceNameNotAllowedInDdns An interface associated with the DDNS service must have a name.
Validation dnsServersCannotBeEmpty You must specify at least one DNS server.
Validation invalidFTSFilter You cannot combine a full-text search (filter=fts~) filter with any other filter parameter in a single request.
Validation SSPServerUnavailable SSP Server Unavailable
Validation AnyConnInvalidModuleTypeProfile Invalid module type in AnyConnect Client profile
Validation AnyConnPoolIpvMismatch Network object {0} IP version is not correct
Validation interfaceShouldBeInGlobalVRF Interface(s) {0} associated with {1} should belong to Global Virtual Router.
Validation snort3NoSGTDESTSupport Snort 3 does not support Access Rule with Destination SGT. Checkout the following rule(s): {0}
Validation invalidFqdn The fully-qualified domain name is invalid.
Validation CannotUpdateDefaultNapName You cannot update the name of the default Network Analysis Policy.
Validation invalidPasswordChar Invalid password. It cannot contain spaces and special character @
Validation unableToGeneratePLRRequestCode Unable to generate PLR Request Code. In order to generate a request code, you must enable Permanent Licensing first.
Validation memberInterfaceCannotBeUsed An interface used by DHCP Relay Service cannot be associated with {0} object. Interfaces: {1}
Validation invalidNetworkSubTypeObjectsForPolicy Unsupported type of network object: {0}. The object names are: {1}.
Validation vdbUpdateError_1 Unable to connect to update server
Validation invalidOspfDuplicateArea Area ID must be unique per OSPF process
Validation invalidEigrpWILDANY 0.0.0.0 is not a valid Router ID..
Validation interfaceWithECMPStaticRoutes Interface "{0}" has these equal-cost static routes: [{1}].
Validation registrationKeyLengthOutOfRange Registration Key of "{0}" should be no less than {1} and no more than {2}.
Validation invalidMacAddress Invalid MAC address. The allowed format is H.H.H, where H is a 16-bit hexadecimal digit.
Validation CertStatusSelfSignedNullCheck IsSelfSigned cannot be null
Validation invalidFlexCliSecretValue {0} value must be an existing Secret Object
Validation NoAssociatedIPSFound Failed to find an IPS associated with the default policy {0}.
Validation appFilterMissingValue The application filter should have a value {0}.
Validation appFilterInvalidNumericValueLow The numeric input for {0} is too low. The minimum value {1}.
Validation natSourceIntfNotNamed The interface used for NAT rule source interface must have a name
Validation timeZoneInvalidCustomSetting Invalid Custom Setting for TimeZone Object.TimeZone Object custom configuration can be either done by DAY or DATE not by both.
Validation invalidLine Line is not valid. {0}
Validation manualNatDestIntfIsNullWithIntfInTransSrc Destination interface cannot be any if you select interface for the translated source
Validation interfaceNameNull Cannot associate an interface with no logical name.
Validation invalidOspfInterfaceNetworkMismatch Interface {0} IP address does not belong to the specified network {1} of area {2}
Validation timeZoneInvalidDate Invalid startDateTime. The startDateTime must be prior to the endDateTime. Use the format YYYY-MM-DDTHH:MM, with time in 24-hour notation.
Validation invalidURLfilterLicense URL filtering license is not enabled
Validation appFilterDupClassificationType Duplicated classification type selected: {0}
Validation RuleNotFoundInRuleGroup Could not find rule {0} in rule group {1}.
Validation invalidOspfRedistDuplicateConf Multiple configurations found for the protocol {0}
Validation cfgImpInvalidExcludeEntitiesMatchers Invalid exclude-entities matchers. Each matcher must have format like 'id=', 'type=' or 'name=': {0}
Validation invalidPrivateKey Private key is not valid
Validation noConnection This device is currently not registered or in evaluation mode for Smart Licensing
Validation unableToInstallPLRAuthCode Unable to install PLR Authorization Code. In order to install a PLR Authorization Code, you must enable PLR and generate a request code.
Validation agentAllowedInterfaceTypes Invalid type of DCHP Relay Agent interface, the only types allowed are PhysicalInterface, SubInterface, VLAN, and EtherChannelInterface.
Validation realmInterfaceNotNamed Identity realm directory interface does not have a logical name
Validation invalidAddress Invalid address
Validation IntrusionRuleNotFound Unable to find the IntrusionRule with ID:{0}.
Validation acRuleDestProtocolNotAllowedWithSrcPort You cannot add a destination protocol object with non-empty source ports: {0}
Validation FMCRegistrationCurrentPendingChanges Cannot start FMC registration while there are current pending changes.
Validation SecurityIntelligenceDNSPolicyGlobalWhitelistShouldBeFirstElement The DNS policy global Do Not Block rules should be in the first position in the Do Not Block list.
Validation acPolicyInvalidNap The selected network analysis policy cannot be used in the access policy.
Validation SSLCipherUnsupportedAlgorithms Configured cipher algorithms {0} are either not supported in this version of FTD or not a valid algorithm for the selected protocol versions.
Validation cannotUseFQDNIPRangeNetworkObjects Cannot use Network objects with FQDN or IP Range type configuration
Validation domainNameFeedUpdateError The feed with the ID {0} was not downloaded.
Validation sruUpdateError_16 Rulepack was successfully installed but skipping deployment as this is a STANDBY device.
Validation s2sVTIRRINotAllowed You cannot configure reverse route injection when using a static virtual tunnel interface for a site-to-site VPN connection.
Validation cryptoCompliantIkev2Policy The IKEv2 policies are using strong encryption which is not allowed by your licensing setting, please disable them or use DES only: {0}
Validation s2sCryptoEnabledIkev2Proposals S2S VPN uses IKEv2 proposals with DES encryption. DES is not supported when strong encryption is enabled.
Validation loopbackAddressNotAllowedAsFMCHost FMC Host of "{0}" cannot be a loopback address.
Validation unsupportedLACPModeForPlatform Specified EtherChannel LACP Mode type is not supported on this platform.
Validation extraCertificates One or more extraneous certificates were selected: {0}
Validation sslUpgradeFailed SSL Policy upgrade failed due to a system error. Please contact Cisco Technical Support.
Validation cannotFindOutsideInterface Please verify that outside interface is configured and connected to a gateway that can reach the internet.
Validation RaVpnGPTunnelNetworksRequired Tunnel Networks have to be specified.
Validation cliCommandUnSupportedCharacters Character {0} not allowed in CLI Console.
Validation SystemDefinedRuleGroup You cannot modify system defined rule groups. {0} is a system defined rule group.
Validation ipsecDupIkev2Encryption Cannot have duplicate encryption methods
Validation SSLCipherUnsupportedProtocolVersions Protocol version DTSLV1_2 is not supported in {0} FTD model.
Validation PullFileDiskSpaceNotAvailable File upload failed - Insufficient disk space.
Validation FMCRegistrationSettingsDoesNotExist FMCRegistrationSettings object does not exist. Please make sure you create one before you start FMC Registration.
Validation snmpFruRemoveTrapNotSupportedOnVirtualPlatform SNMP FRU Remove Trap not supported on Virtual Platform.
Validation haPrimaryAndSecondaryAddressesRequired Both primary and secondary {0} addresses must be provided for {1}.
Validation RaVpnSecAuthCommPwdNotSpecified Common Password is required
Validation staticRouteNoInterfaceName Interface used for static route must have a logical name
Validation errorDuringInfoFetchFromSys Error occurred during system information fetching.
Validation checksumUrlHasToBeMandatory Checksum URL is required if update frequency is set to five minutes, otherwise it is optional.
Validation memberInterfacesNotSameSpeedCapabilities EtherChannel member interfaces cannot have different speed capabilities.
Validation denyMtuChangeOnUnnamedInterface You cannot change MTU on an unnamed interface. MTU must be set to 1500 on an unnamed interface
Validation invalidHAFailoverPeerHoldTimeUnit Peer hold time unit must be MILLISECONDS or SECONDS
Validation invalidIntegrationTargetsLimit You cannot associate more than one integration target.
Validation cannotUseBGIMemberInterfaces The interface is part of a bridge group. You cannot configure management access list rules for a bridge group member.
Validation staticRouteDupGatewayForDiffInterfaces You cannot use the same gateway for routes on more than one interface.
Validation vtiTunnelIdNotInRange Invalid range for tunnelId. The allowed range is {0}-{1}.
Validation geoUpdateError_14 GeoDB operation timed out.
Validation haConfigurationModificationNotAllowed HA Configuration cannot be modified as the node is already in HA
Validation s2sVTIRemoteBackupPeersNotAllowed You cannot configure remote backup peers when using a static virtual tunnel interface for a site-to-site VPN connection.
Validation metricBandwidthNullMetricTypeNotNull Metric Bandwidth cannot be null when Metric Type is not null.
Validation etherChannelAutoSpeedNotInMemberInterfaceSpeedCapability EtherChannel speed cannot be set to AUTO, the selected member interface(s) do not have AUTO speed capability.
Validation s2sVTIOnlyVTITypeAllowed If you enable static VTI, you must select a virtual tunnel interface for the site-to-site VPN connection profile.
Validation staticRouteDupGatewayForDiffInterfacesConfigCheck Some static routes use the same gateway and different interfaces. Number of static routes affected: {0}.
Validation invalidRealmId Invalid realm ID
Validation sruUpdateError_0 Rulepack successfully installed
Validation atLeastOneEntryRequired Should have at least one entry
Validation manualNatNoDestNatWithSrcNat46 Missing destination translation with IPv4 to IPv6 translation on source addresses
Validation unsupportedIkevTwoEncryption The following encryption algorithms are not supported in IKEv2 policies: 3DES, NULL.
Validation cannotBeEtherChannelMemberInterfaces The interface "{0}" is a member of a EtherChannel. You cannot use it in an ECMP Traffic Zone.
Validation NetmaskProvidedWithNoIPAddress A Netmask has been provided with no IP address.
Validation PullFileTimeoutFailed File upload failed due to timeout
Validation InvalidBgpNeighborDupPrefixListFilter Only one prefix list can be configured in either direction
Validation emptyCustomURLValue Custom URL should be provided for the CUSTOM Region.
Validation invalidIPV4NetworkObject Invalid objects are: {0}.
Validation bridgeGroupInterfaceMemberPassive You cannot add a passive mode interface to a bridge group.
Validation usedHAInterface The {0} must be an unused interface
Validation DHCPServerWrongNetworkProtocol DHCP server IP address range must use IPv4 addresses
Validation standbyWithoutActiveMacAddress Standby MAC Address cannot be specified without an active MAC Address.
Validation ipAddressTypeMismatch The IP addresses for {0} must be either IPv4 or IPv6 not both.
Validation invalidRangeBadOrder Invalid range. The end IP address must be greater than the start IP address
Validation OpenSSLCipherDetailsNotAvailable Unable to load the Open SSL protocol cipher details.
Validation cannotUpdateUnauthenticatedUser Cannot perform update on unauthenticated user
Validation invalidHAFailoverThreshold When the interface failure threshold unit is set to {0}, then the valid range is between {1} and {2}.
Validation exceedsMemberInterfacesLimit EtherChannel cannot contain more than 16 active physical interfaces.
Validation VRFNotSupported VRF is not supported in the current platform.
Validation ipsecPolicyNeedPrf Policy must have at least one pseudorandom function
Validation prefixListIpAddressNotUnique IP address/mask value should be unique across all entries in the prefix list.
Validation passwordsMustNotBeBlank The password has not been changed from the default. You must specify a new password as well as the existing password.
Validation CertStatusIsValidNullCheck IsValid cannot be null
Validation invalidOspfProcessUpdated Cannot change process ID when editing OSPF process
Validation interfaceCannotHaveIpv4AddressOfBgpNetwork This IPv4 address is part of a network that is being used in the BGP configuration. You cannot assign an IPv4 address from this network to a management-only interface or subinterface.
Validation DHCPServerSecondaryWINSHost DHCP server secondary WINS server must be host type: {0}
Validation invalidFlexCliTemplateUnsupportedChar Template cannot contain unsupported character sequence {0}
Validation invalidFMCConnectivityInterfaceMode Physical interface {0} is not in ROUTED mode. Only ROUTED mode Physical interfaces can be assigned to Connectivity Interface.
Validation evalNotStarted The evaluation mode was not started
Validation invalidFqdnDnsResolution The fully-qualified domain name DNS resolution type is invalid.
Validation unsupportedNGFWInterfaceSpeed Unsupported NGFW Interface Speed on SSP platform
Validation invalidFilterCondition Invalid filter condition is provided.
Validation haConfigurationCloudServicesFailure Unable to set the state of the box according to the content of the cloud communication settings object.
Validation dhcpRelayEnabled DHCP feature cannot be enabled when DHCP Relay Agent is running.
Validation interfaceTrafficImpactWithConfig One or more interfaces were moved from one virtual router to another. Any existing connections on moved interfaces will be dropped.
Validation duplicateSyslogServerIPAddressAndPortNumber Two Syslog Servers cannot have same IP address and port number. Duplicate IP address: {0} and port number: {1}
Validation duplicateBridgeGroupInterfaceId Bridge Group interface ID {0} is already being used.
Validation nameUseAAAReservedKeyWord You cannot use a reserved AAA keyword as your Identity Source name: "{0}"
Validation bridgeGroupInterfaceCannotHaveIpv4AddressOfBgpNetwork This IPv4 address is part of a network that is being used in the BGP configuration. You cannot assign an IPv4 address from this network to a bridge group interface.
Validation invalidOspfRedistIsisRequiredDisabled Routing level must be specified to enable redistribution of ISIS protocol
Validation unsupportedIkevTwoIpsecEncryptions The following encryption algorithms are not supported in IKEv2 IPsec proposals: 3DES, AES-GMAC, AES-GMAC-192, AES-GMAC-256.
Validation deviceUnenrollAlreadyInProgress The device unenrollment process is already in progress.
Validation interfaceBreakoutNotSupported Breaking out Interface is not supported for interface {0}
Validation DHCPServerInterfaceInBridgeGroup The interface {0} is already a member of the bridge group interface {1} and hence cannot be configured as a DHCP server
Validation invalidImportValue Importing Intrusion Rule has invalid override state {0}
Validation invalidBgpNeighborBridgeGroupInterface BGP Neighbor can not be on the same network as Bridge group interface
Validation PullUpgradeCompleteMessage Pull is completed
Validation invalidSmartCliPolicyListValue {0} entity value must be an existing Policy List Object
Validation cannotAddManagementAccessInterface Interface {0} is configured to allow management access. You cannot include it in an ECMP Traffic Zone.
Validation OverriddenAndDefaultStateInputNotAllowed Inputs are not allowed for overriddenState and defaultState fields.
Validation timeoutExceedsFrequency The timeout value should not exceed the frequency value
Validation haBreakFromStandby You cannot execute {0} on the standby unit. Please log into the active unit to break HA. If you need to disable HA on this unit only, first suspend HA. Then you can execute {0}.
Validation onlyPrefixOrAccessList The list should contain either all Access List objects or all Prefix List objects.
Validation invalidInterfaceMode Interface "{0}" cannot be added to ECMP Traffic Zone. Only interfaces with ROUTED mode are allowed.
Validation invalidEnumForFilter Value {0} not supported for filter {1}. Options are {2}.
Validation interfaceInDHCPServer The following interfaces are configured as DHCP Servers {0}. You must remove them before you can add the interfaces to a bridge group
Validation maxInterfaceLimitInsideZone An ECMP Traffic Zone can contain a maximum of 8 interfaces.
Validation timeRangeInvalidISODate Invalid effective start or end date time. Use the ISO format YYYY-MM-DDTHH:MM, with time in 24-hour notation.
Validation invalidMethod Validation failed, invalid method "{0}" marked as @AutoValidating
Validation InstanceMissingDataField Instance is missing data field.
Validation manualNatSrc66OrigSrcIpv6PrefixTooShort The original source IPv6 prefix must be greater than or equal to 64 in an IPv6 to IPv6 manual NAT source translation: {0}
Validation unsupportedIkevTwoPrf MD5 Hash is not a supported PRF Type in IKEv2 Policies.
Validation ipsecDupIkev2Group Cannot have duplicate DH groups
Validation invalidObjectForTimeRangeAnnotation Invalid object type for TimeRange annotation.
Validation UnlockDeviceWithoutAcceptEula The End User License Agreement has not been accepted. The device remains locked until you accept the EULA.
Validation emptyLocations Please select at least one country or continent
Validation nestedNetworkGroupCycleDetected The network group {0} includes a nested reference to the group you are editing. A network group cannot include references to itself. Please remove {0}
Validation duplicateFqdnInList There is already an interface configured with the FQDN {0}.
Validation standbyIPNotInSameSubnetOfActiveIPAddress Standby IP Address should be in the same subnet as the active IP Address.
Validation unsupportedDuplexType Specified EtherChannel Duplex type is not supported.
Validation snmpIpv6ManagerAddressHostGroup IPv6 manager networks are not allowed for SNMP Hosts with Host Group type.
Validation AnyConnNoIpv6InsideNetwork With {0} as an IPv6 address pool, you must have at least one IPv6 inside network specified
Validation diskFileNotFound Cannot find a file with name: {0}
Validation SSLCipherProtocolMissingAlgorithms Selected protocol versions {0} should have at least one supported algorithm assigned.
Validation interfaceFecCanBeSetOnlyFor25GSpeedCapInterface Interface {0} doesn't support 25G Speed Capability; you cannot set the FEC mode.
Validation OrphanRuleExist If Intrusion Rule Group {0} is deleted then the following Intrusion Rules will not belong to any RuleGroup: {1}. Rules for this group can be deleted with the group by using cascadeDelete option.
Validation invalidSubnetMask Invalid subnet mask.
Validation PullUpgradeInitiationSSLError Pull upgrade job initiation failed due to an SSL verification error.
Validation ISETagInvalid Invalid SGT with tag: {0} and externalId: {1}.
Validation invalidHAFailoverInterfaceHoldTimeUnit Interface hold time unit must be MILLISECONDS or SECONDS
Validation communityNumbersNotUnique Community numbers must be a unique set of values.
Validation invalidSecret Secret cannot be blank or a masking string or a single digit or start with a digit followed by spaces and cannot contain a question mark or semicolon
Validation multipleAgentsOnInterface Only a single DHCP Relay Agent can be configured on interface {0}.
Validation interfacePairShouldBeInSameBridgeGroup Interface pair must be in the same bridge group to enable bypass
Validation featureCapabilitiesWriteException Exception thrown while trying to write Feature Capabilities to file {0}
Validation realmSequenceNotAllowedForActiveAuthIdentityRule Realm Sequence object cannot be used in an Active Auth identity rule.
Validation defaultActionCannotBeChanged You cannot change the default action in the identity policy
Validation invalidRange Invalid range
Validation invalidOspfNsfNone Disabling NSF requires all LLS capability, Cisco helper, Opaque LSA, and IETF helper be negated
Validation haInterfaceNameNotEmpty You cannot use a named interface for {0}. Please edit the interface and remove the name, or select a different interface.
Validation standardAccessListNetworksNotUnique Standard Access List entries must have unique networks across all entries.
Validation cannotCreateFMCRegistrationSettingsWithFlexConfigPolicy The device has a FlexConfig Object. You must remove all FlexConfig configuration before proceeding.
Validation cfgImpDuplicateImportJob You cannot start a new configuration import job because either an existing job is already running or an import job is scheduled to run
Validation newInstanceWithDuplicateId Validation failed, attempting to create a new object with duplicate ID
Validation ipsecPolicyInvalidPriority Priority value not in range: {0}
Validation contextGetFailed Could not get device registration context. Please try again later.
Validation duplicateLdapValue Duplicate LDAP attribute value {0} in LDAP attribute map {1} is not allowed.
Validation manualNatSrc66OrigSrcPrefixShorterThanTransSrcPrefix The IPv6 prefix of the original source subnet "{0}" must be greater than or equal to the IPv6 prefix of the translated source subnet "{1}"
Validation snmpEncryptPasswordShouldBeNull Encryption Password should not be provided for SNMP Users with NOAUTH and AUTH security levels.
Validation AccessSslRulesWithNewlyAddedCategories The following URL categories are new and not yet active: {0}. Please also add one or more active URL category to the rule.
Validation s2sBackupPeerIkev2InvalidLocalKey Invalid IKEv2 pre-shared local key. It must contain 1-128 ASCII printable characters, no whitespace, no single or double quotation marks, no question marks and cannot be a single digit
Validation cancelFMCRegistrationJobAlreadyInProgress Cancel FMC registration job is already in progress.
Validation dnsServerGroupCannotBeRenamed The DNS server group {0} is being used in the data interface settings. Before you can rename the group, you must remove it from that setting.
Validation snmpNullAuthenticationPassword Authentication password can not be null for SNMP users with security level AUTH and PRIV.
Validation DHCPServerAutoConfigFalseWithInterface DHCP Server default interface cannot be set if Auto Configuration is off
Validation appFilterDupRisk Duplicated risk selected: {0}
Validation loggingListNameSubString Name cannot be substring of one of existing list's name.
Validation maxPrefixLimitCanNotBeDifferent Cannot have different values for maximum prefix limit.
Validation genericTimeout Timeout: {0}
Validation invalidSmartCliExtendedAccessListValue {0} entity value must be an existing Extended Access List Object
Validation appFilterEmptyMatchers The application filter has empty match conditions.
Validation cannotChangeIdentitySourceOfUser You cannot update the identitySourceId of a user.
Validation hostNull Host must not be null.
Validation unexpectedPLRUnsuccessfulCancellation Unable to cancel Universal Permanent Licensing.
Validation cannotProceedHaActionWithRegenFlag The device is part of an HA pair. You cannot force data regeneration during deployment when joining or breaking HA.
Validation noToken In order to register, you must provide a token obtained from your Smart Software Manager Account
Validation cloudEventsCanNotBeEnabledWithEmptyEventTypes You must select at least one type of event.
Validation acRuleLogFilesInvalidAction You cannot enable Log Files because there is no file policy selected for this rule.
Validation nameBlank Name must not be empty or blank.
Validation unresolvableUrl Hostname cannot be resolved to an IP address.
Validation unableToCreateBypassPair Unable to create hardware bypass pairs
Validation cliCommandEmpty Please enter a command.
Validation NoBasePolicySet No Base Policy Set for Intrusion Policy
Validation facDeletePerlGeneralError An unexpected error occurred while deleting a Firepower Analytics Center entity
Validation SSLPolicyOnlyTCPPorts SSL rule cannot use non-TCP port object {0}, referenced in {1} ports
Validation InvalidBgpNeighborDupASPathFilter Only one as-path can be configured in either direction
Validation RaVpnInvalidPasswordPeriod Password notification period is between 1-180 days.
Validation haBothLinksAreOnSameSubnet The failover and statefulFailover addresses must not be on the same {0} subnet.
Validation objectNatPortNotAllowedWithDnsEnabled You cannot enable DNS reply translation with port translation in an auto NAT rule
Validation InvalidBgpNeighborNeighborHopsRemoteAsBgpAsNumber ttl-security should allow to configure for EBGP peers. You cannot configure if BGP AS number is same as remote-as number.
Validation staticRouteInvalidIpTypeForSlaMonitor The SLA monitor cannot be referenced by IPV6 static route entry
Validation HTTPProxyNotAuthenticated authenticate is set to false, please remove the username and password or set null.
Validation unknownHostIP Could not determine device management IP address.
Validation cannotConfigureIPv6Address The interface is configured in {0} mode. You cannot configure an IP v6 address on {0} interface.
Validation ecmpZoneWithConfigSSLRules You should configure the same SSL Rules to all ECMP Traffic Zone member interfaces. Interfaces from ECMP Traffic Zones: "{0}" should have the same SSL rules. Please make sure you configure ECMP Traffic Zones/SSL Rules accordingly.
Validation DHCPServerSecondaryDNSHost DHCP server secondary DNS server must be host type: {0}
Validation bgpUpgradeFailed BGP upgrade failed due to a system error, please contact the support.
Validation interfaceisPassive The selected interface {0} used in syslog server cannot be in passive mode.
Validation invalidOspfSpfTimers Incorrect SPF timer configuration, expected initial-delay <= min-hold-time <= max-wait-time
Validation CannotUpdateSystemDefinedPolicyRule You cannot update a rule for a system defined policy.
Validation RaVpnGroupPolicyRenameDefaultGP Default Group Policy (DfltGrpPolicy) cannot be renamed.
Validation noHardwareNameProvided No hardware names where provided in the url. Please provide a hardware name or a list of hardware names separated by commas in the hardwareName filter of the url.
Validation invalidDuplicateAccessSecretKey Validation failed due to duplicate Access and Secret key.
Validation acRuleOverlapCountryContinentSrcNetworks The source networks should not contain both country {0} and continent {1}
Validation mgmtMtuInvalidRange Invalid MTU value. The MTU can be 68-1500 (IPv4) or 1280-1500 (IPv6).
Validation acRuleDestUdpPortWithOtherSrcPort When you specify destination UDP ports, the source ports should either be empty or contain at least one UDP port
Validation invalidHAFailoverInterfaceHoldTime Interface hold time must be between 5 and 75 seconds.
Validation s2sMultipleOutsideIntf Site-to-Site VPN connection profile can only have a single outside interface
Validation timeRangeInvalidISOTime Invalid effective start or end time. Use the ISO format YYYY-MM-DDTHH:MM, with time in 24-hour notation. The hour (HH) must be 0-23, and the minutes (MM) must be 0-59.
Validation selfSignedLeafWithChain Self-signed certificates cannot have a trust chain.
Validation ddnsPasswordRequired Password is required.
Validation noServers No DHCP relay server configured. No relaying can be done without at least one Server.
Validation objectNatTransNetworkHasIpv6AndIpv4Addresses The translated address cannot contain both IPv6 and IPv4 addresses
Validation bridgeGroupInterfaceIdNotEditable The bridge group interface ID cannot be modified by editing the bridge group interface. Current bridge group interface ID in the DB is {0}, bridge group interface ID from request is {1}
Validation SSLRuleSyslogWithEventOff Syslog cannot be used if events for the SSL rule are turned off
Validation RuleGroupNeeded The Intrusion Rule {0} must belong to at least one rule group.
Validation BinderRuleMissingUseField Binder Rule is missing "use" field.
Validation updateEntityWithoutChanges This update request contained no changes to the object. The request is not processed.
Validation appFilterTypeInvalid Invalid application filter entry type {0}.
Validation invalidVariableValue Variable value is not valid. {0}
Validation pppoeDuplicateVpdnUserName The Username is the same as the PPPoE username from interface {0}.
Validation invalidDuplicateInstrumentationKey Validation failed due to a duplicate instrumentation key.
Validation emptyValue Value cannot be empty.
Validation invalidIntegrationTarget At least one integration target should be configured.
Validation RaVpnSecAuthPrefillPasswdBothNotSpecified One of Password Type or Prefill Username has to be configured.
Validation unsupportedApiVersion The API version specified is not supported. The supported API versions are {0}
Validation subnetConflictWithStaticRoutes There is already a static route for the {0}/{1} network, which conflicts with address {2}/{3}. To assign this address to an interface, you must first delete the static route
Validation conflictingFlexConfigPolicyDHCPRelay You can not add FlexConfig objects with prohibited commands to the FlexConfig policy while the DHCPRelay feature is enabled. You must either remove the prohibited commands from the objects, or remove the objects from the FlexConfig policy.
Validation objectNat46Ipv4AnyIsNotAllowedWithNat46WellKnownPrefix The original address cannot be IPv4 "any" with the well known NAT46 prefix "64:ff9b::" in the translated address
Validation BannerTooLong Banner display string cannot be longer than {0}
Validation invalidInterfaceHoldTime You cannot enter an interface hold time value that is less than 5 times the interface poll time.
Validation DuplicateAnyConnNoRealmServerHosts Realm servergroup {0} has duplicate server hosts {1},Realm server hosts must be unique.
Validation systemDefinedObject You cannot modify or delete system defined objects.
Validation s2sIkev2ProposalsEmpty IKEv2 proposals cannot be null or empty
Validation invalidOspfNsfCiscoOnly NSF Cisco requires LLS capability, Cisco helper enabled and Opaque LSA, IETF helper negated
Validation invalidNetmask The Network mask entered is invalid
Validation fmcConnectivityInterfaceIsRequired Either Data interface or management interface should be selected.
Validation updateEasysetupStatusWithoutPasswordChange Password has not been changed, unable to update easy setup status
Validation haNoneMatchingAddresses When using the same interface for both the failover and statefulFailover, their addresses must match.
Validation acRuleCannotUseReservedRuleName You cannot use the reserved hidden rule name: {0}
Validation invalidBgpScanTime The scan time value should match the scan time value in General Settings.
Validation modelMismatch This upgrade is not for this device model.
Validation acRuleDestinationZoneCannotBePassive When you specify source zone as passive mode zone, the destination zone should be empty
Validation timeZoneInvalidTimeConfigurationDayRecurrence Invalid time configuration for dstDayRecurrence. Start Time configuration including startMonth,startWeek,startDayOfWeek,startTime should be less than End Time configuration including endMonth,endWeek,endDayOfWeek,endTime.
Validation invalidType Invalid type provided, please check all permitted types in the model.
Validation GlobalVRFDelRequested Global VRF can not be deleted.
Validation externalBrowserPackageWithFileAlreadyExists An external browser package with the following name already exists: {0}
Validation acRuleDestUdpProtocolNotAllowedWithUdpDestPort You cannot add a destination UDP protocol object with destination UDP ports: {0}
Validation manualNatRouteLookupDestNetworkMismatch The Perform Route Lookup option is available for identity NAT only. The original and translated destination networks must be identical to use the option.
Validation InvalidBinderRuleToDisabledInstance You cannot configure binder rules for disabled inspectors; the following inspectors violate this rule: {0}.
Validation manualNatSrc64Ipv6HostCountTooHigh The IPv6 host count {0} in the original source exceeds the maximum allowed {1} in an IPv6 to IPv4 manual NAT source translation
Validation s2sVTIOnly1ProfilePerVTI The virtual tunnel interface "{0}" is already being used in another site-to-site VPN connection. You can use a single VTI in one site-to-site VPN connection only.
Validation invalidV6EndCompatible IPv4-compatible IPv6 as end address is not supported.
Validation maxServers Only up to {0} DHCP servers can be configured for relaying.
Validation lockInvalidUnlock Attempting to acquire an invalid lock: "{0}"
Validation vtiIPCannotOverlapRavpnAddressPool Interface {0} cannot be in the address pool range {1} used in RAVPN connection profile {2}.
Validation invalidSmartCliRequiredDisabled {0}: This is a required command. You cannot disable it
Validation s2sIkev2InvalidLocalKey Invalid IKEv2 pre-shared local key. It must contain 1 to 128 ASCII printable characters, no whitespace, no single or double quotation marks, no question marks and cannot be a single digit
Validation passwordTooLong Password is too long. The password needs to be less than 129 characters long
Validation invalidNumberOfTrackedObjects The number of tracked objects cannot exceed {0}
Validation snmpAuthPasswordShouldBeNull Authentication Password should not be provided for SNMP Users with NOAUTH security level.
Validation IntfNameNullOrEmpty There is no interface name for the {0} interface. You can use named interfaces only in the virtual router.
Validation invalidCustomURLValue Custom URL should not be provided for the Region other than CUSTOM.
Validation sysInfoNullFileOrProcess Cannot create reader for null file or process
Validation managementOnlyCannotBeDisabled You cannot disable the management-only option on the Management interface
Validation noDatabaseAvailable Snort 3 rule package installation failed: There is no database available from the current rule package.
Validation staticRouteDupMetricForSameNetworks There is already a static route with the same networks. You must specify another metric.
Validation manualNatDest64Ipv6HostObjNotAllowedInOrigDest You cannot use an IPv6 host network object as the original destination in an IPv6 to IPv4 manual NAT destination translation rule: {0}
Validation invalidUsage Validation failed, method "{0}" cannot be used to process "{1}"
Validation snort3AnotherProcessRunning Another switching task is running.
Validation s2sIkev1MaskedKeyNotAllowed Masked value for IKEv1 pre-shared key is not allowed with connection profile creation
Validation duplicateUserInRule {0} is in the rule more than once.
Validation cannotEditIPOfNeighborInterface An interface cannot have the same IPv4 address as a neighbor in OSPF {0}.
Validation bridgeGroupInterfaceHardwareNameNotEditable The bridge group interface hardware name cannot be modified by editing the bridge group interface. Current bridge group interface hardware name in the DB is {0}, bridge group interface ID from request is {1}
Validation appFilterInvalidTypeName Invalid application filter type name {0}.
Validation shouldNotContainHTML HTML tags are not allowed
Validation manualNatOrigDestIsNull You must specify an original destination network
Validation bothCloudRegionAndActionTypeCannotBeNull Both Cloud Region and CloudActionType cannot be null.
Validation invalidOspfInterfaceConflictingNetwork OSPF area networks must all belong to Management interfaces or Data interfaces
Validation invalidUserIdentitySourceTypeInRule The identity source for the users in the rule should be of type IdentityRealmBase or LocalIdentitySource
Validation invalidBooleanQueryParam {0} must be either TRUE or FALSE.
Validation intfMigrationImportFailed Failed at import step. Unable to import the configuration due to error {0}
Validation ipsecPolicySamePriority Priority cannot overlap with existing policy: {0}
Validation versionSameError Device version {0} is already installed on the device.
Validation invalidInterfaceSelected Invalid type of interface selected, the only types allowed are PhysicalInterface, SubInterface, and EtherChannelInterface.
Validation bypassPairShouldContainTwoInterfaces The hardware bypass pair does not contain two interfaces that are allowed to be paired
Validation nullPlatformLogSettings Platform log settings cannot be null on this platform.
Validation unalbeToConvertResponse Unable to convert response using the specified API version. Please use the latest API version.
Validation bridgeGroupInterfaceReferencedInStaticRoute The following Interfaces are used in static route configuration: {0}. This feature is not compatible with a bridge group member interface. You must remove the interfaces from the configuration before you can add them to the bridge group.
Validation sysInfoIOException IO Exception thrown while trying to read System Information
Validation InputInconsistent Input values in the following fields {0} are different from the value in the ruleData. Exclude them from the request or match it with data in ruleData.
Validation AnyConnExcessFiles Can only have one AnyConnectPackageFile per platform
Validation snmpInvalidCommunityString SNMP Community is a case-sensitive value up to 32 alphanumeric characters long. Spaces are not permitted.
Validation emptyLdapValue There is an empty LDAP attribute value in LDAP attribute map {0}.
Validation identityRealmMultipleDirectoryConfig Multiple directory configurations are not allowed for the realm.
Validation invalidDupInAclRouteFilter Only one access list is allowed per interface
Validation vdbUpdateError_12 Error running VDB update
Validation RuleFileInvalid The rule file is invalid and the stderr output is available at the designated API.
Validation sruUpdateError_8 Rulepack download failed
Validation bridgeGroupMemberModeCannotChange You cannot change the mode of a bridge group member interface.
Validation bgpInvalidBgpNeighborAdvertiseMapConfiguration Cannot configure exist-map and non-exist map for the same advertise-route-map and exist-route-map.
Validation cryptoNonCompliantIkev1PolicyForEncryption The upgraded IKE-V1 policies: {0} use 3DES Encryption which is not supported on this FTD version.
Validation natPatOptionsNotSupported The PAT pool option is not supported in NAT rules
Validation unpersistedReferenceTarget Un-persisted reference target is detected, reference source is {0}, reference target is {1}
Validation invalidLoggingListName Severity level cannot be used as name. Name cannot be substring of severity level.
Validation snmpMaxHostTrapCount Max count of SNMP Host with enabled traps is 128.
Validation emptyCertificateString Certificate String cannot be empty.
Validation emptyFlexVariableName The variable name is missing in {0}
Validation UnsupportedNetworkObjectTypeForgroupPolicy Network Object is being used in RavpnGroupPolicy {0} , type can't be edited to FQDN or HOST
Validation interfaceIsRequired Either data interface or management interface should be selected.
Validation invalidManagementInterface Management interface "{0}" is not allowed in ECMP Traffic Zones.
Validation dhcpRelayMemberInterface This interface is used by the DHCP Relay Service. You cannot update its properties or refer to it from other objects.
Validation invalidDeviceMetricsIntegrationsLimit Only one Device Metrics Integrations object can be created.
Validation invalidLoggingListInvalidRange Message start ID cannot be greater than or equal to message end ID.
Validation invalidSystemUpgradeFile The uploaded file is not valid. Upgrade files must have file type REL.tar. Do not perform upgrades with file type .sh upgrade files.
Validation linaResponseTimedOut Cannot establish connection with data-plane. Request/Response timed out.
Validation s2sIkev2MaskedRemoteKeyNotAllowed Masked value for IKEv2 pre-shared remote key is not allowed with connection profile creation
Validation AnyConnACPrfOutsideIntfInBvi The interface {0} added to AnyConnectProfile is invalid, it is member of BridgeGroup.
Validation objectNatRouteLookupNetworksMismatch The Perform Route Lookup option is available for identity NAT only. The original and translated addresses must be identical to use the option.
Validation cannotHaveStaticRouteOnTheMemberOfBVI Bridge Group Member Interface: {0} cannot have static route entry
Validation noSupportedFileTypeForLocalMalwareAnalysis File Rule validations failed. You must add a file type or category that supports Local Malware Analysis.
Validation snmpInvalidEncryptionPassword Authentication password can not be null for SNMP users with security level PRIV.
Validation invalidTypeForFilter Value {0} not supported for filter {1}. Must be of type {2}.
Validation invalidOSPFAreaNetworkBrigeGroupInterface Bridge group interface falls in the same network as Area network. OSPF can not be configured on BVI interface
Validation AnyConnCryptoCompliance Current licensing status does not allow use of cryptography present in AnyConnect VPN
Validation appFilterInvalidTypeValue Invalid application filter type value {0}.
Validation invalidParentVrfId Invalid parent Virtual Router Id for the ECMP Traffic Zone.
Validation bridgeGroupInterfaceReferencedInNatRule The following Interfaces are used in NAT rules configuration: {0}. This feature is not compatible with a bridge group member interface. You must remove the interfaces from the configuration before you can add them to the bridge group.
Validation interfaceWithPppoeType HA cannot be enabled when interface {0} has PPPoE Type selected.
Validation cannotCancelFMCRegistrationJobBeingCleanedUp Cannot cancel FMC Registration Job because clean up is already in progress.
Validation bypassObjectNotFound The hardware bypass object not found
Validation invalidOspfNotEnabledOnInterface OSPF is not enabled on the interface {0} for the configured networks
Validation invalidHAInterface The {0} must be a physical or EtherChannel interface.
Validation upgradeFileNotFound Upgrade file not found.
Validation timeZoneInvalidDayRecurrence The dstDayRecurrence section is incomplete. To configure a dstDayRecurrence, you must specify the startMonth,startWeek,startDayOfWeek,startTime,endMonth,endWeek,endDayOfWeek and endTime.
Validation operationalLinaEmptyResponse Operational response can not be empty.
Validation ftdUpdateMgrError_235 Missing upgrade information file. Cannot retry.
Validation RaVpnSecAuthCommPwdNotValid Common Password cannot be specified.
Validation lspPackageNotSigned Downloaded rule update package is not correctly signed.
Validation unexpectedPLRUnsuccessfulEnable Unable to enable Universal Permanent Licensing.
Validation invalidOspfRedistOspfNone OSPF redistribution is not possible without enabling another OSPF process
Validation HTTPInvalidUserName Invalid Username. Support characters are [a-z 0-9].
Validation RaVpnGroupPolicyIntfAddrOverLap Interface cannot be in the address pool range {0} used in RAVPN group policy {1}
Validation conflictingActiveAuthPort The selected port {0} is currently being used in a management access list to allow FDM connections. You cannot use this same port for Identity Policy's Active Auth.
Validation s2sBackupPeerIkev2RemoteMaskedKeyNotAllowed Masked value for IKEv2 remote pre-shared key is not allowed when creating a new backup peer or updating the IP address for an existing backup peer.
Validation SslRulesWithDeprecatedCategoriesDisabledPolicy Some of the SSL decryption rules refer to deprecated URL Categories. Number of SSL decryption rules affected: {0}. Enable the SSL Decryption policy, remove deprecated URL categories in the rules, or replace them with new ones. You can then disable the policy.
Validation DHCPServerPrimaryDNSHost DHCP server primary DNS server must be host type: {0}
Validation noRealmId Realm ID is required
Validation passwordConsecutive Password contains consecutive characters
Validation AnyConnNoAddrPools IPv4 or IPv6 address pool is required
Validation geoUpdateError_8 Unspecified error when doing remote update. GeoDB download failed
Validation interfaceInHA This interface is being used in a high availability (HA) configuration. You cannot update its properties or refer to it from other policies or objects.
Validation s2sNatExemptIntfCannotBeBviMember Inside interface for NAT exempt cannot be a bridge-group member: {0}
Validation ftdUpdateMgrError_187 Revert failed.
Validation vtiCannotBeMonitoredInterface Virtual Tunnel Interface cannot be set as monitored interface.
Validation raCaCertUsedAsInternalCertificate A CA certificate cannot be used as identity certificate for authentication between remote access clients and FTD. Please provide a valid identity certificate for successful remote access VPN establishment.
Validation invalidBgpNextHopTriggerDelay The Next hop trigger delay value should match the next hop trigger delay value in General Settings.
Validation timeRangeInvalidRangeTime Invalid rangeStartTime. If rangeStartDay and rangeEndDay are equal, rangeStartTime cannot be equal to the rangeEndTime.
Validation operatorNotSupported Filter operator not supported
Validation invalidSmartCliSecretValue {0} entity value must be an existing Secret Object
Validation RaVpnGroupPolicyUnsupportedRekeyMethod SSL Rekey Method supports only 'NEW_TUNNEL' method.
Validation interfaceBreakoutNeedsDeployment Interface {0} has pending changes. You must deploy the changes before you can break it out.
Validation invalidUsernameChar Invalid username. It cannot contain spaces and special characters @ and :
Validation invalidOspfRedistribution Redistribution for {0} is not supported for user defined virtual router.
Validation cryptoNonCompliantIkev1PolicyForHash The upgraded IKE-V1 policies: {0} use MD5 Hash which is not supported on this FTD version.
Validation deprecatedSecurityProtocolTypeIsUsedInSslCiphers Deprecated security protocol version {0} is used in the following SSL Ciphers, please remove it: {1}.
Validation invalidOspfInterfaceSecretNotFound Secret {0} is not found
Validation SecurityIntelligenceDNSPolicyWhitelistContainsBlacklistItem DNS policy Do Not Block rules cannot contain Block rules.
Validation VRFDiagnosticIntfNotSupported You can assign the interface "{0}" to the global virtual router only.
Validation invalidLicenseGracePeriodStateForTestRequest Unable to change the license grace period state. The grace period state cannot be changed to not started or started when it is already expired. The grace period state cannot stay the same as well.
Validation snort3MandatoryDeploymentNeeded Before switching Snort version, you need to deploy all pending changes.
Validation failedDeploymentBeforeUpgrade Deployment before upgrade failed.
Validation identityRealmDuplicateADPrimaryDomain This AD Primary Domain is already used by realm {0}
Validation invalidFMCHost FMC Host of "{0}" is not a valid IP address.
Validation invalidConnectionTypeSync You cannot perform a sync if you are not registered
Validation RuleGroupEnabledUnderPolicies Intrusion Rule Group {0} is still enabled under the following policies: {1}. Disable the rule group in those policies before deletion or use the disableInAllPolicies option.
Validation nameUseReservedKeyWord You cannot use a reserved keyword as an object or group name: "{0}"
Validation timezoneMalformed Cannot find the time zone
Validation snmpUserPasswordsCannotContainSpaces SNMP User encryption and authentication password cannot contain spaces.
Validation cannotChangeUserRoleOfUser You cannot update the user role of a user.
Validation invalidFlexCliIncorrectSectionUsage Incorrect section usage found
Validation invalidOspfMissingArea Referenced Area ID {0} is not configured
Validation invalidHAFailoverPeerHoldTime Peer hold time must be between 800 and 999 milliseconds, or 1 and 15 seconds.
Validation BinderRuleMissingTypeField Binder Rule is missing "type" field.
Validation RaVpnConnectionProfileSAMLSourceNeedsSAMLType If the identity source is a SAML server, the authentication method must be SAML.
Validation communityEntriesNotUnique Community entries must be unique.
Validation dnsServerGroupMaxNoAllowedCheck Some DNS groups have more than the allowed number of configured servers ({0}). Number of DNS groups affected: {1}.
Validation inCompatiblePowerOverEthernet Power over ethernet is not supported on the {0} physical interface.
Validation manualNatTransSrcAndDestIpVersionMismatch The translated source and translated destination addresses must have the same IP version
Validation invalidHAFailoverInterfacePollTimeUnit Interface poll time unit must be MILLISECONDS or SECONDS
Validation webCertMissingInternalCert The Web Server Certificate must be assigned an Internal Certificate.
Validation acPolicyInvalidDefaultActionWithIps Invalid default action {0}; only Allow is allowed with intrusion inspection
Validation AnyConnACPrfOutsideIntfHasNoName The interface {0} added to AnyConnectProfile should have a logical name.
Validation invalidSmartCliEnumValue {0} value must be one of the allowed enum values {1}
Validation sruMaximumRuleUpdate Failed to update Intrusion Rule, only {0} may be updated in single transaction.
Validation certHashingNotSupported Certificate hashing is not supported, please use SHA256 or higher.
Validation RuleGroupContainsNames Cannot delete a custom rule group that contains custom rules. You must delete all contained rules prior to deleting this rule group.
Validation cannotTriggerAutoEnrollmentApiIfNotLicensed You must license the device before enrolling with the cloud using Auto Enrollment.
Validation objectNatDupRuleWithSameOrigNetwork There is another auto NAT rule with the same original network. Only one auto NAT rule is allowed per each original network
Validation cfgExpDuplicateExportJob You cannot start a new configuration export job because either an existing job is already running or an export job is scheduled to run
Validation ftdUpdateMgrError_189 Revert failed.
Validation useOfUnspecifiedIPAddressOnly {0} is known as an Unspecified Address. This address cannot be assigned to an interface.
Validation haIdenticalAddresses {0} has identical primary and secondary {1} addresses.
Validation invalidOspfInterfaceMD5NotEnabled Message digest has been chosen as the authentication type but message-digest-key is not configured
Validation upgradeCannotBeStartedWhenBaseIsMissing Upgrade cannot be started when 'BASE' license is missing
Validation invalidTarget Validation failed due to an invalid relationship target: "{0}"
Validation exceedLimitEnabledIkev2Policies The maximum number of IKEv2 policies enabled has already been reached ({0}). Please disable the unused policies.
Validation diskFileNameInvalid Disk file name cannot be null or empty or longer than 60 characters. It can start with an alphanumeric character or an underscore and contain the special characters +, ., _ and -
Validation sequenceNumberNotUnique Sequence number needs to be unique across all entries.
Validation vdbUpdateError_17 This version of VDB is already installed.
Validation s2sVTIRemoteNetworksNotAllowed You cannot configure the remote networks when using a static virtual tunnel interface for a site-to-site VPN connection.
Validation vtiIPv4Netmask You must provide an IPv4 address and netmask.
Validation CannotUpdateDefaultNapDescription You cannot update the description of the default Network Analysis Policy.
Validation moveToDeployDirFailed Unable to move the package to the deploy directory.
Validation acRuleNetworkObjectSubtypesNotSupported Access list contains network-object of un-supported sub-types.
Validation invalidEigrpALLONES 255.255.255.255 is not a valid Router ID.
Validation invalidSmartCliBranchRequired Incomplete configuration, at least one command must be enabled for the chosen value {0}
Validation scheduleInvalidTrigger Unable to schedule job {0}. Invalid start trigger.
Validation smartAgentManagerWasNotInitialized SmartAgentManager was not initialized
Validation ftdUpdateMgrError_132 Invalid command option.
Validation failedToDiscardPendingChanges You cannot discard pending changes. The system must complete a successful deployment before you can have the option to discard pending changes.
Validation bgpGracefulStalePathTimeWithoutGracefulRestart Graceful restart should be enabled before setting stale path time
Validation invalidSmartCliDuplicateConfiguration You have already configured the command with the same values
Validation invalidSmartCliInterfaceNameRequired Interface associated with {0} object of {1} (Smart CLI) should have a non-empty NAME.
Validation natNotSupportedNetworkObjects You cannot use FQDN or IP-Range network objects in this field of the NAT rule.
Validation cannotChangeNameOfDynamicDNSTrustedCAGroup You cannot change the name of Dynamic-DNS-Trusted-CA-Group.
Validation HTTPProxyAuthenticate Enter username and password for the http proxy server.
Validation globalBroadcastAddressNotAllowedAsFMCHost FMC Host of "{0}" cannot be a global broadcast address.
Validation registrationFailure The device is not registered.
Validation invalidDuplicateMetricsName Validation failed due to duplicate metric-name configured.
Validation AnyConnEmptyPackages No any-connect package file is included, please upload and select at least one
Validation RaVpnConnectionProfileSAMLSecondarySource The secondary authentication source cannot be a SAML server.
Validation invalidTimeoutSpecified Timeout value has to be in the range {0} and {1}
Validation ftdUpdateMgrError_186 Revert operation is not yet available. Try again after upgrade completes.
Validation s2sIkev2CertificateNotSpecifiedWhenAuthMethodCert An internal certificate for IKEv2 policy must be provided when authentication via certificate is selected
Validation manualNatDuplicateRule Another manual NAT rule is found to have identical address and port translation
Validation contextUpdateFailed Could not update device registration context. Please try again.
Validation scheduleInvalidType Unable to schedule job. Invalid type.
Validation invalidOspfInterfaceNeighborsDefined Operation cannot be performed. An OSPF neighbor is defined for the interface {0} in the object {1}
Validation acRuleOverlapCountryContinentDestNetworks The destination networks should not contain both country {0} and continent {1}
Validation RaVpnConnectionProfileSAMLTypeNeedsSAMLSource If the authentication method is SAML, the identity source must be a SAML Server.
Validation interfaceCannotHaveIpv6AddressOfBgpNeighbor An interface cannot have the same IPv6 address as a neighbor in BGP.
Validation portConflictWithIdentityPolicyPort Port value cannot be the same as the existing Identity Policy object's active authentication port value.
Validation objectNatTransNetIsNullAndIntfInTransNetIsFalse You must specify an address or interface for the translated address
Validation invalidInstrumentationKey Instrumentation Key field should be in the valid UUID format.
Validation appFilterInvalidTagName Invalid application filter tag name {0}.
Validation invalidNetworkSubtypeForDataInterface The management access rule for the data interfaces contains a network object of an unsupported type.
Validation acPolicyNapNotSupportedSnort2 Specifying the access policy's network analysis policy is not support in Snort 2.
Validation appFilterInvalidTagValue Invalid application filter tag value {0}.
Validation cannotNotFindValue Validation of depending objects could not be done successfully. The system failed to resolve the references of this entity for the depending objects.
Validation invalidOspfNsfIetfOnly NSF IETF requires Opaque LSA, IETF helper enabled and LLS capability, Cisco helper negated
Validation noUpgradeDetected There is no major upgrade operation in progress.
Validation cannotChangeNameOfUser You cannot change the username of a user
Validation FMCRegistrationSettingsInvalidCreation Cannot create more than one FMCRegistrationSettings object. Please delete the existing one before creating a new FMCRegistrationSettings object.
Validation zoneCannotBeDeletedIfECMPRouteExists You cannot delete "{0}". ECMP Traffic Zones cannot be deleted if equal-cost static routes exist across multiple interfaces from ECMP Traffic Zone. The following static routes need to be deleted first: [{1}]
Validation SecurityIntelligenceDNSPolicyMoreThanOne You cannot have more than one Security Intelligence DNS Policy.
Validation installOnStandbyNode The standby node of an HA pair may not install a new SRU package; upload only is authorized.
Validation sruUpdateError_17 Error downloading rule update, file is corrupt (Incorrectly Signed). Please contact technical support.
Validation unsupportedNetworkType {0} {1}
Validation invalidOspfAreaDupPrefixFilter Only one prefix list can be configured in either direction
Validation bgpDuplicateNetworksNotAllowed Duplicate networks are not allowed
Validation cannotAddSourceTunnelInterfaces Interface {0} is the source interface for a virtual tunnel interface (VTI). You cannot include it in an ECMP traffic zone.
Validation CannotUseApiDuringSnortToggle This API cannot be used during a Snort toggle job.
Validation appFilterDupCondition The application filter contains identical conditions.
Validation CannotImportRuleFileInSnort2 You cannot import a custom rule file in Snort 2 mode.
Validation DomainNameGroupIsNotEqualToGlobalWhiteOrGlobalBlackList Domain Name Group is not equal to global Block or Do Not Block list, it's allowed only to change domain names for Domain Name Group.
Validation invalidOspfDuplicateNetwork {0} has already been configured
Validation managementInterfaceCannotBeParent You cannot create a subinterface on the Management interface {0}
Validation cannotConfigureMacAddress You cannot configure MAC address on interface {0} when it is in {1} mode.
Validation memberInterfaceModeNotSupportedForEtherChannels You cannot add a switch port mode interface to an EtherChannel.
Validation ipsecNoEnabledIkev1PoliciesWithPreshareAuth Cannot disable or delete IKEv1 policy with pre-shared key authentication, need at least one policy active while a site-to-site connection profile using IKEv1 exists
Validation externalBrowserPackageInvalidName Invalid file name. The external browser package file name must end in .pkg.
Validation etherChannelSpeedMatchMemberInterfaceCommon EtherChannel speed must match common member interface speed capability: {0}.
Validation invalidFlexCliNoBlocks A group of blocks can be empty but not null
Validation invalidFlexCliLineSyntax Syntax error with Flex Config CLI line: {0}
Validation AnyConnPrefillUsernameFromCertificateNotEnabled Please enable PrefillUsernameFromCertificate to update DisablePrefilledUsernameEdit.
Validation objectNat46PrivateIpv4IsNotAllowedWithNat46WellKnownPrefix The private IPv4 address "{1}" in original address "{0}" is not allowed with the well known NAT64 prefix "64:ff9b::" in the translated address
Validation aceLogIntervalNull The log interval cannot be set to null when the logging option is enabled.
Validation sameIPGateway IP address and Gateway cannot be same
Validation SecurityIntelligenceNetworkPolicyMoreThanOne Cannot have more than one Security Intelligence Network Policy.
Validation invalidStateName Invalid State name
Validation realmSequenceIsEmpty Realm Sequence Object should contain at least one Identity Realm.
Validation vtiTunnelSourceNotNamed An interface used as a tunnel source interface for a virtual tunnel interface must be named.
Validation interfaceBreakOutJoinIntfUsed Interface {0} is being used in {1} with name {2}. Interface cannot be {3}.
Validation interfaceCannotMarkMissing An error occured while scanning the no longer available interface {0}
Validation deviceEnrollmentAlreadyInProgress The device enrollment with the Cisco cloud is already in progress.
Validation sruUpdateError_5 The system could not download the update file. Please try again later.
Validation InvalidBgpNeighborMigrationLocalAsBgpAsNumber Cannot have local-as number same as BGP AS number.
Validation InvalidSecurityLevelForRuleGroup Invalid security level for rule group: {0}.
Validation featureCapabilitiesNoHandlers No features capabilities handlers found in application context files
Validation ddnsUsernameShouldBeNull Username should be set to null for Custom URL Service Provider.
Validation multicastAddressNotAllowed The IP address cannot be a multicast address.
Validation interfaceInDHCPServerContainer The interface {0} is already configured as DHCP auto configuration. You must remove it before adding the interface to a bridge group
Validation bridgeGroupInterfaceMemberIsMgmtOnly Management interface {0} cannot be Bridge Group member interface
Validation RuleGroupChildNotAllowed Custom intrusion rule group must not include any child rule groups.
Validation identityRealmDuplicateAD There is already an AD configured with the Hostname {0} and Port {1}
Validation unsupportedSSPInterfaceFECType Unsupported SSP Interface FEC (Forward Error Correction) Type on SSP Platform: {0}
Validation cloudResponseReadFailed Snort 3 cloud update failed: Error reading response data from the update server.
Validation intfUsedInEtherChannel Interface {0} is being used in an EtherChannel.
Validation invalidLineConfiguration Line is not correctly configured. Please check the qualifiedPath and selfId values.
Validation invalidFxosVersion Current FXOS version is {0}. This upgrade is for FXOS versions greater than or equal to {1}.
Validation vlanInterfacesLimit You cannot create more than {0} VLAN interfaces on this device.
Validation newInstanceWithMetadata Validation failed, attempting to create an object with pre-populated metadata
Validation invalidMalwareLicense Malware license is not enabled
Validation timeZoneInvalidISOTime Invalid startTime or endTime. Use the format HH:MM, with time in 24-hour notation. The hour (HH) must be 0-23, and the minutes (MM) must be 0-59.
Validation HashCountLimitExceeded Hashcount limit has exceeded 10000 hashes
Validation ipsecExcessIkev2Policies The maximum number of IKEv2 policies enabled has already been reached ({0})
Validation s2sOverlapNetworks Site-to-Site profile {0} has overlapping local and remote network address space with profile {1}
Validation geoUpdateError_6 The latest GeoDB update is already installed
Validation vlan1CannotBeDeleted VLAN 1 is the default VLAN interface and cannot be deleted.
Validation CouldNotFindBasePolicy Could not find a base policy using the ID provided.
Validation s2sIkev2MaskedLocalKeyNotAllowed Masked value for IKEv2 pre-shared local key is not allowed with connection profile creation
Validation linaUnableToResolveHostname Unable to resolve the hostname {0} to an IP Address
Validation DHCPServerAutoConfigName This interface is being used for DHCP auto configuration. You cannot remove the interface name until you change the DHCP server auto configuration settings.
Validation cfgImpInvalidObjTypesInExcludeEntities Invalid entity types in exclude-entities matchers: {0}
Validation SecurityIntelligencePolicyEventLogOffWithSyslogOn You cannot enable syslog with event log disabled
Validation FMCConnectivityPortPerlError Failed to retrieve FMC Connectivity Port.
Validation missingRealmInAuthRule No realm found in an identity Rule that uses the Auth action.
Validation s2sVTINoNATExempt You cannot specify a NAT exempt interface when using a static virtual tunnel interface for a site-to-site VPN connection.
Validation customRulesFileImportSuccess Successfully imported rules.
Validation cannotBeMgmtInterface The interface is configured in {0} mode. You cannot configure it to be management interface.
Validation CannotImportEmptyFile You cannot import an empty file.
Validation cannotCreateFMCRegistrationSettingsInUPLRMode FMC registration is not supported when device is licensed in Universal PLR mode. Please unregister the device from Universal PLR before continuing with FMC registration.
Validation geoUpdateError_13 GeoDB update file is not valid.
Validation cryptoNonCompliantIkev1Policy The IKEv1 policies are using DES encryption which is disallowed when the Smart License Account has export-controlled features enabled: {0}.
Validation invalidBgpNeighborInterface BGP Neighbor cannot have the same IP address as that of a device interface
Validation invalidOspfAreaIdLeadingZero Numeric Area ID should be an unsigned integer without leading zeros
Validation invalidEigrpVRF You can configure EIGRP in the global virtual router only.
Validation invalidBgpNetworkManagementInterfaceConfigured BGP is not supported on management-only interface
Validation errorWhenRunningCLI Cannot retrieve hardware bypass information
Validation invalidTopLevelDomainName The top-level domain must start with an alphabetic character.
Validation snort2ForceInstallingInProgress Snort 2 Package Installation in progress.
Validation invalidTrackId Track ID value must be between 1 and 500.
Validation invalidBaseLicense Base license is not enabled
Validation SSLSettingProtocolVersionsNotOrdered You cannot skip a protocol version between start and end range. Missing protocol versions are {0}.
Validation unexpectedPLRUnsuccessfulGetReleaseCode Unable to attain Release Code for Universal Permanent Licensing. Inputted authorization code may be incorrect or was not installed.
Validation invalidMalwareLicenseForFilePolicy Missing Malware License. The associated file policy or rule requires this license.
Validation removeExistingIPFromHAInterface Interface {0} is configured with IP addresses. You must remove the IP address configuration to use this interface for the failover or stateful failover interface.
Validation invalidObjectForSupportedNetworkObjectAnnotation Invalid object type for SupportedNetworkObject annotation.
Validation ipPoolStartEndIpNotInSameSubnet Start and end IP address are not in the same sub-net with given sub-net prefix
Validation ruleRevisionMustBeLarger The updated rule must have a higher revision number compares to the original.
Validation RaVpnAddressPoolOverlapVal IP Address Pool {0} with range {1} has overlapping addresses with Address Pool {2} with range {3}.
Validation invalidDupInRouteFilter Duplicate configuration found for incoming route filter
Validation s2sIkev1ProposalsTooMany Too many IKEv1 proposals. Number of assigned IKEv1 proposals cannot exceed {0}
Validation invalidSmartCliStringValuePattern {0} value does not match the pattern it uses
Validation staticRouteInterfaceModePassive The selected interface {0} used in static route cannot be in passive mode.
Validation vrfIdNotFound Virtual Router is not found.
Validation genericException Error: {0}
Validation manualNatTransSrcHasIpv6AndIpv4Addresses The translated source network should not contain both IPv4 and IPv6 addresses
Validation invalidBGPNeighborPasswordLength Passwords used for BGP Neighbor authentication cannot contain spaces and must be between 1 and 25 characters
Validation invalidNumericObjectName The name "{0}" is invalid. The name must be an unsigned numeric value
Validation sruImportError Failed to import Rule Update package
Validation sruUpdateError_9 The latest Rulepack update is already installed
Validation sruUpdateError_12 Unable to copy installed files
Validation invalidURL Must be a valid URL
Validation acPolicyInvalidIdentityWIthNoSSL You cannot configure identity policy without enabling SSL policy
Validation NeedAtLeastOneRuleGroup You need to provide at least one rule group name to create the custom intrusion rule.
Validation interfaceHasSubInterfaces You cannot configure {0} with an interface that has subinterfaces. Please edit the interface and remove subinterfaces, or select a different interface.
Validation bgpHaNotConfigured High availability has not been configured.
Validation smartAgentNotReady Smart Agent is not ready.
Validation attemptToChangeNonEditEtherChannelId Validation failed, attempt to change a non-editable EtherChannel ID.
Validation fileNotFound File not Found
Validation RaVpnMaxNumberAddressPoolVal A maximum of 6 Address Pools are allowed.
Validation invalidOspfInterfaceConflictingInterval Hello interval({0}) must be set to a value less than Dead interval({1})
Validation lockTimeout Unable to acquire the read-lock due to timeout
Validation cannotCreateHardwareBypassPairs Cannot create hardware bypass Pair.
Validation objectNatDestIntfIsNullWithIntfInTransNetwork Destination interface cannot be "any" if you select Interface for translated network
Validation SslRulesWithDeletedCategories Some of the SSL decryption rules refer to deleted URL Categories. Number of SSL decryption rules affected: {0}.
Validation noSpaceAllowOnName The logical name cannot contain any spaces
Validation s2sInvalidNetworks Profile cannot have strictly {0} local networks and {1} remote networks
Validation cannotDeleteDynamicDNSTrustedCAGroup You cannot delete Dynamic-DNS-Trusted-CA-Group.
Validation snort2DownloadInProgress Snort 2 Package Downloading in progress.
Validation invalidThreatLicense Threat license is not enabled
Validation PullDiskSpaceNotAvailable Disk space is not available
Validation IntrusionPolicySnort2CreateNotAllowed You cannot create an Intrusion Policy in Snort 2 mode.
Validation memberInterfaceCannotBeNamed An interface with a logical name cannot be a member of an EtherChannel.
Validation registrationKeyBlankValue Registration Key cannot be blank.
Validation ipsecCombinedModeNullIntegrity Combined mode encryption must be used with solely null integrity type because combined modes internally set integrity type
Validation s2sConnTypeNotNull The connection type for a Policy-based site-to-site VPN connection profile must be null.
Validation upgradeFileAndDeviceVersionSame This upgrade is for the same version as the current device version. You cannot upgrade to the same version.
Validation cloudUpdateFailed Snort 3 cloud update failed: {0}.
Validation snort3RuleParsingInProgress Snort 3 rule parsing in progress.
Validation cannotContainPPPOEIpv4Config The interface is configured in {0} mode. It cannot contain any PPPOE Configuration or IPV4 address.
Validation invalidLicenseForObject Missing license for object: {0} requires the {1} license
Validation epmInterfaceNotDeployedCannotBeAdded Network Module Interface {0} is not deployed yet. Perform deployment, and then you can add to an EtherChannel.
Validation BinderRuleInstanceNotFound Instance {0} not found.
Validation unsupportedIkevTwoProposal MD5 Hash is not supported in IKEv2 Policies.
Validation stringOutOfRange The string length should be no less than {0} and no more than {1}
Validation entityNotFoundWithUuid Failed to find DB entity of type {0} with UUID {1}
Validation invalidCountryCode Invalid Country code
Validation standbyIPWithoutActiveIPAddress Standby IP Address cannot be specified without an active IP Address.
Validation interfaceReferencedInOspfNeighbor Interface cannot be updated when referenced in OSPF neighbor. You must remove the neighbor before updating the interface.
Validation DapXmlDfltPriorityInvalid Cannot provide priority for default DAP record
Validation InvalidRuleGroupsString Invalid value provided for ruleGroups, please specify a comma-separated list of IDs.
Validation invalidWebUrlPattern Invalid DDNS Web URL.
Validation s2sIkev1ProposalsEmpty IKEv1 proposals cannot be null or empty
Validation s2sMoreThanOneDynamicPeer Only one Site-to-site profile can have a dynamic peer.
Validation invalidNetworkType The NetworkObject {0} is invalid. NetworkObject must be of type Host.
Validation AnyconnInvalidClientPackage AnyConnect client file uploaded is invalid {0}
Validation interfaceHasSubIntfBreakOutJoinFail Interface {0} has {1} subinterface. Interface cannot be {2} until subinterfaces are deleted.
Validation interfaceWithDHCPAddress HA cannot be enabled when interface {0} has a DHCP address.
Validation invalidSmartCliCommunityListValue {0} entity value must be an existing Standard or Expanded Community List Object
Validation invalidEigrpRedistDuplicateConf Multiple configurations found for the protocol {0}.
Validation s2sNoDynamicRRI Dynamic reverse route injection cannot be configured on site-to-site VPN when Dynamic Crypto Map or IKEv1 policy are enabled
Validation RaVpnSecAuthNotValidOnCertOnly Secondary Authentication not valid on selected Authentication method.
Validation objectUsageInvalidUuidParam Uuid parameter used in object usages search for type "{0}" is invalid.
Validation currentAndNewPasswordCannotBeTheSame Current and new password cannot be the same
Validation s2sOutsideIntfIsNullOrEmpty Site-to-Site VPN outside-interfaces cannot be null or empty
Validation AnyConnDnsExcess There can only be a maximum of two servers for {0}
Validation DHCPServerIPPoolRange The interface DHCP server address pool {0} is not on the same subnet as the interface IP address, {1}. The pool must be on the same subnet and it cannot contain the interface IP address. If you are changing the interface IP address, you must first delete the DHCP server.
Validation InvalidBgpNeighborDupRouteMapFilter Only one route map can be configured in either direction
Validation vdbUpdateError_14 VDB successfully updated but skipping deployment as this is a STANDBY device.
Validation manualNatSrc46PrivateIpv4IsNotAllowedWithNat46WellKnownPrefix The private IPv4 address "{1}" in original source "{0}" is not allowed with the well known NAT64 prefix "64:ff9b::" in the translated source
Validation invalidDefaultLoggingValues When the logging option is set to default, the log level and log interval must be null.
Validation incompatibleTypes ICMP Code and Type are not compatible.
Validation ipsecPolicyNeedGroup Policy must have at least one DH group
Validation interfaceBreakOutJoinIntfUsedNoName Interface {0} is being used in {1}. Interface cannot be {2}.
Validation passwordTooShort Password is too short. The password needs to be at least 8 characters long
Validation invalidEigrpRedistBgpIdentifier Identifier value {0} does not match the BGP autonomous system number in use.
Validation sameOperationInprogress Another user or the system might be performing the same operation, please try again later.
Validation exceededNumCerts Number of external certificates must not exceed 10.
Validation interfaceWithPassiveMode You cannot use an interface in passive mode for HA configuration.
Validation s2sCryptoEnabledIkev1Proposals S2S VPN uses IKEv1 proposals with DES encryption. DES is not supported when strong encryption is enabled.
Validation interfaceBreakoutOrJoinIntfHAMonitoringEnabled Interface {0} is named, enabled and has HA Monitoring enabled. Interface {1} cannot be {2}.
Validation invalidSpeedDuplexPair You cannot select 1000 or 10000 Mbps when Duplex is "Half"
Validation acRuleDestTcpProtocolNotAllowedWithTcpDestPort You cannot add a destination TCP protocol object with destination TCP ports: {0}
Validation PullFileSizeCheckFailed File upload failed - Invalid file size.
Validation upgradeFileNotFoundOnDisk Upgrade file not found on disk.
Validation snmpInvalidEncryptionPasswordLength Encryption password should be an encrypted string with length 8 - 257 characters.
Validation unknownHostName Could not determine device hostname.
Validation opensslCertificates Failed to verify the certificate chain
Validation uncommitedChanges You must deploy all uncommited changes before starting a system upgrade.
Validation ftdUpdateMgrError_181 Syntax error: Revert-to version not provided. Use 'show upgrade revert-info' API to determine available revert versions.
Validation noBaseLicense Cannot add a license when the base license is not present
Validation unexpectedPLRUnsuccessfulGetRequestCode Unable to attain Request Code for Universal Permanent Licensing.
Validation manualNatStaticTransSrcNotNullAndIntfInTransSrcIsTrue You cannot select both a translated address and interface for the translated address in static NAT
Validation invalidSmartCliStandardAccessListValue {0} entity value must be an existing Standard Access List Object
Validation interfaceFecModeUnsupportedPlatform Forward Error Correction is not supported on this platform.
Validation ipsecNoEnabledIkev2Policies Cannot disable or delete IKEv2 policy, need at least one policy active while a site-to-site connection profile using IKEv2 exists
Validation objectNatOrigNetworkIsNull You must specify an original address in an auto NAT rule
Validation snmpUnsupportedSecurityConfiguration The specified security configuration is not supported. Supported versions are v1, v2c and v3.
Validation HTTPInvalidPassword Password must be 8 to 16 characters long.
Validation staticRouteNoNetworks Static route should have at least one network
Validation manualNatSrc64AnyIpv6NotValid The network corresponding to the full range of IPv6 addresses, i.e. ::/0, cannot be used in the source of an IPv6 to IPv4 manual NAT rule
Validation interfaceFecCanBeSetOnlyForPhysicalInterface Interface {0} isn't a physical interface; you cannot set the FEC mode.
Validation invalidVlanId Default VLAN is not correctly set on the device.
Validation interfaceDuplexWithSFPPorts Interface {0} is of SFP type and must have Duplex set to FULL.
Validation ddnsUsernameRequired Username is required.
Validation ftdUpdateMgrError_161 No upgrade in progress.
Validation smartAgentUninitialized Smart Agent was not initialized.
Validation haMonitoredNamedInterfaceCannotBeAdded Cannot add a deployed, named and HA monitored {0} interface to this EtherChannel. Please remove interface monitoring or name, perform deploy and then try adding the interface as the member.
Validation PullValidationStarted Upgrade installer file download is complete. Now validating the downloaded file.
Validation s2sOutsideIntfCannotBeBviMember Outside interface cannot be a bridge-group member: {0}
Validation invalidTrafficThrottleState Can not enable traffic throttle if device was in compliance at least once
Validation invalidConnectionEventTypes You cannot select two different connection event types to send to the cloud.
Validation invalidUmbrellaDnsServerGroup You cannot change the name or DNS server IP addresses in the system-defined CiscoUmbrellaDNSServerGroup object.
Validation InvalidBgpNeighborDupAccessListFilter Only one access list can be configured in either direction
Validation ftdUpdateMgrError_245 Upgrade failed and the system restarted. Cannot retry.
Validation IntrusionPolicySnort2UpdateRuleNotAllowed You cannot update an Intrusion Rule for a specific Intrusion Policy in Snort 2 mode.
Validation facReadPerlGeneralError An unexpected error occurred while retrieving Firepower Analytics Server entity(ies)
Validation aaaUpdatingName Updating the name for a rule is not supported
Validation acRuleLogEndNotAllowedWithDeny You cannot log at the end of connection only if the access rule action is Block.
Validation DHCPServerInvalidPlatformSupport DHCP server is not supported on the following platforms: Virtual FTD, Firepower 4100, Firepower 9300.
Validation invalidV6EndMapped IPv4-mapped IPv6 as end address is not supported.
Validation AnyConnInsideCannotBePassive The interface {0} added to AnyConnectProfile is invalid, the inside interface cannot be in passive mode
Validation natIdLengthOutOfRange NAT ID of "{0}" should be no less than {1} and no more than {2}.
Validation FMCRegistrationDeploymentInProgress Cannot start FMC registration while deployment is in progress.
Validation invalidInterfaceForRouteMapEntry A route map cannot include passive interfaces or bridge group member interfaces or an interface which is part of the high availability configuration.
Validation invalidOspfInterfaceEnabled Selected Interface is enabled.
Validation s2sIkev1InvalidKey Invalid IKEv1 pre-shared key. It must contain 1 to 128 ASCII printable characters, no whitespace, no single or double quotation marks, no question marks and cannot be a single digit
Validation vpnConnProfileNameIsIpAddress VPN connection profile name must not be an IP-V4 or IP-V6 address value
Validation invalidManagementInterfaceInDdns Management interface "{0}" is not allowed in DDNS Service.
Validation invalidNetworkSubtypeForPolicy Policy contains network-object of un-supported sub-types.
Validation appFilterDupProductivity Duplicated business relevance selected: {0}
Validation nullAuthToken The registration key is mandatory.
Validation RaVpnConnProfOnlyRadiusSupported Only RADIUS Identity source is supported.
Validation invalidNetworkSubtypeForSecIntelligencePolicyBlackList The Security Intelligence Block list contains a network object of an unsupported type.
Validation vdbUpdateError_18 VDB update file is not valid.
Validation InvalidOutsideInterface Invalid outside interface selected. Default outside interface cannot be changed.
Validation evalExpired Cannot set evaluation mode as it has expired or been interrupted
Validation invalidInterfaceModeInDdns Interface "{0}" cannot be added to DDNS Service. Only interfaces with ROUTED mode are allowed.
Validation invalidOspfNeighborInterfaceNonBroadcast Interface {0} network type must be point-to-point non-broadcast
Validation missingVrfId Virtual Router is not specified.
Validation aaaInvalidUsernameLength Username is too long. The username must be less than 128 characters long
Validation AnyConnDuplicateFileObj Cannot create another AnyConnectPackageFile object for platform {0}
Validation licensingJobInProgress Licensing task is in progress - {0}. Please try after some time
Validation invalidHAFailoverInterfacePollTime Interface poll time must be between 500 and 999 milliseconds, or 1 and 15 seconds.
Validation ipv6SubnetOverlap The prefix of IP address {0} overlaps with the prefix of the reserved range {1}, please use a higher prefix value or change the address.
Validation natDynamicRuleNotSupportNoProxyArp Dynamic NAT does not support the Do Not Proxy ARP option
Validation geoUpdateError_9 GeoDB installation failure
Validation staticRouteWrongGateway Gateway is not supported when it's a route leak.
Validation vtiSourceCannotBeUsedByBVI Interface {0} is being used as a source interface for VTI {1}. You cannot select it as a bridge group member.
Validation vdbUpdateError_9 VDB Installation Failure
Validation invalidInterface Management interface {0} is not allowed in security zones
Validation etherChannelCannotBeAddedToBridgeGroupInterface EtherChannel Interface cannot be added to a Bridge Group Interface.
Validation pppoeObjectIsRequired The pppoe object is required when the interface type is PPPoE.
Validation IntfModeInvalid Physical interface {0} is not in ROUTED mode. Only ROUTED mode Physical interfaces can be part of a virtual router.
Validation intfMigrationNotSupportedInputTypes Migration is not supported on the provided input. Only Interface types can be migrated.
Validation manualNatTransSrcIsNullAndIntfInTransSrcIsFalse You must specify an address or interface for the translated address
Validation notCryptoCompliant Current license settings do not allow use of strong cryptography for VPN
Validation newInstanceWithInitializedId Validation failed, attempting to create a new object with initialized ID
Validation lspPackageNotExist Can not find an appropriate LSP package for Snort 3.
Validation emptyKeyString Key String cannot be empty.
Validation internalCertValidationError There was an error validating the Internal Certificate.
Validation acRuleFilePolicyInvalidAction The selected access rule action is invalid. You must select the Allow action for a rule that uses a file or intrusion policy
Validation acRuleCannotUseSystemDefinedPolicy The selected intrusion policy is defined by the system. You must select a custom policy.
Validation s2sNoIkev1LocalAnyNetwork For IKEv1 connections, a local network spanning the entire IP address space with specific remote networks is not allowed
Validation FMCRegistrationJobStillQueued FMC Registration job is still queued.
Validation invalidSlaFrequency The frequency value has to be between 1000 and 604800000 seconds (7 days).
Validation snort3DownloadInProgress Snort 3 Package Downloading in progress.
Validation DNGroupDupDN Group contains duplicate distinguished name objects
Validation InvalidParentNameForIOC Parent Name for Inspector Override Config is not valid.
Validation updateEasysetupStatusWithoutEula The End User License Agreement has not been accepted, unable to update easy setup status
Validation SSLSettingInvalidDHGroup Invalid Diffie Hellman Group assigned. Valid values are GROUP_2, GROUP_5, GROUP_14 and GROUP_24.
Validation deviceNotEnrolled The device is not enrolled with Cisco cloud.
Validation etherChannelSpeedMatchMemberInterfaceSpeedCapability EtherChannel speed must match member interface speed capability.
Validation vtiMustBeInRoutedMode Virtual Tunnel Interface must be in ROUTED mode.
Validation initialDeploymentNotPerformed You must deploy changes at least once before you can upgrade the system software.
Validation ddnsWebURLRequired Web URL is required.
Validation featureCapabilitiesGeneralException Unable to build feature capabilities platform file
Validation invalidOSPFAreaNetworkVlanInterface VLAN interface falls in the same network as Area network. OSPF can not be configured on VLAN interface.
Validation markAsSystemDefined You cannot mark custom object as the system defined.
Validation passiveInterfaceCannotBeUsed DHCP Relay Service cannot use the Passive interface {0}.
Validation invalidNetworkSubtypeForSecIntelligencePolicyWhiteList The Security Intelligence Do Not Block list contains a network object of an unsupported type.
Validation invalidOspfVirtualLinkRouterId Multiple peer router id values specified for the same virtual link
Validation invalidSmartCliStringValueChar {0} value cannot contain spaces or reserved characters
Validation ErrorParsingRulesFile Encountered an error when parsing the rules file. Showing {0} of {1} lines parsed from error file: {2}.
Validation adiCliTestCannotReachMQ The connection test failed because ADI is not reachable.
Validation invalidDeviceMetrics At least one device metrics should be configured.
Validation entityNotFoundWithName Failed to find DB entity of type {0} with name {1}
Validation appFilterInvalidCatName Invalid application filter category name {0}.
Validation s2sOutsideIntfIsPassive You cannot use a passive mode interface for the outside interface of a site-to-site VPN connection.
Validation manualNatOrigDestNotNullAndIntfInOrigDestIsTrue You cannot select both an address and interface for the original destination
Validation invalidMtuMIO Invalid MTU for Firepower 4100/9300 device. You can set the MTU up to 9184 for this platform.
Validation invalidSpeedCapability The interface does not support this speed
Validation bridgeGroupCannotHaveVlanAndOtherInterfaces Bridge group member interfaces can either be all VLAN interfaces or physical/subinterfaces, but not both.
Validation snort3ToggleSuccess Successfully switched to Snort version 3.
Validation cryptoCompliantSSLCipher The Data SSL Cipher Setting is using SSL ciphers with strong encryption which is not allowed by your licensing setting, please de-reference them.
Validation geoUpdateError_1 Unable to connect to update server
Validation queryParameterValueNotValid Query parameter "{0}" is not valid because it contains semicolon or parenthesis.
Validation invalidHoldTimeKeepAliveTime The keep alive time and hold time values must either both be zero, or both non-zero. You cannot have zero for one and non-zero for the other.
Validation invalidAccessKey Access Key field should contain only Alpha-Numeric characters with length equals 20.
Validation contextDeletionSucceed Device has been unregistered.
Validation pppoeNotSupportedOnBridgeGroupnterface PPPoE is not supported on a Bridge Group Interface.
Validation deployPackageNotFound You must first deploy the configuration before you can restore a backup
Validation s2sVTIDynPeerNotAllowed You cannot use a dynamic remote peer when using a static virtual tunnel interface for the site-to-site VPN connection.
Validation invalidSmartCliNumericMaxValue {0} value cannot be greater than {1}
Validation MustSpecifyBaseNapPolicy You must choose a base Network Analysis Policy.
Validation featureCapabilitiesMissingHandler Feature capabilities handler {0} can not be found in context
Validation parentInterfaceIsSwitchport You cannot create a subinterface on the Switchport interface {0}
Validation snort2ToggleSuccessWithUpdate Successfully switched to Snort version 2 with rule package updated.
Validation cannotEditIPOfBridgeGroupInterfaceMember Interface {0} is a member of BridgeGroup Interface {1}. You cannot edit ip address for Interface {0}
Validation snmpBothTrapAndPollCannotBeDisabled Both Trap and Poll cannot be disabled. You must enable at least one.
Validation acRuleSrcTcpPortWithOtherDestPort When you specify source TCP ports, the destination ports should either be empty or contain at least one TCP port
Validation PullFileChecksumFailed File upload failed due to checksum failure
Validation cannotUseIntfInRavpn Port conflict. This interface is being used for remote access VPN on port {0}. You must either change the RA VPN port, or configure a different port number for HTTPS management access.
Validation invalidOspfInterface An interface with OSPF configuration must be enabled and cannot be in passive mode, or be a bridge group, or be a VLAN interface, or a member of a bridge group, or be part of the high availability configuration.
Validation modeMisMatch The mode for interface {0} does not match the mode of the security zone {1}.
Validation s2sLifetimeKB Site to Site profile Lifetime Range should be between 10 and 2147483647 kilobytes
Validation basePolicyNotFound Base Policy {0} not found in incoming LSP package. Please delete all Custom Intrusion Policies using this base policy and retry.
Validation manualNatDest64Ipv6PrefixTooLong The original destination IPv6 network prefix length must be less than or equal to 96 in an IPv6 to IPv4 manual NAT destination translation rule: {0}({1})
Validation cryptoNonCompliantIkev2PolicyForIntegrityType The upgraded IKEv2 policies use MD5 as Integrity which is not supported on this FTD version: {0}.
Validation RaVpnConnProfUserNameSettingsNotSupported Username Settings are not supported for this Authentication Type of AAA only
Validation switchPortConfigurationNotNull Interface {0} cannot have a switch port configuration when it is in {0} mode.
Validation AnyConnRealmEncryptionTypeNotSupported Realm server encryption type not supported by AnyConnect.
Validation acRuleUnnamedInterfaceInSourceZone Source security zone {0} contains an un-named interface that cannot be used in an access rule
Validation SSLPolicyAppFilterAppsMustHaveSSL SSL rule cannot contain application filter with applications that do not use SSL
Validation invalidLineInstance Instance does not match with the template it uses. Found mismatch in the properties "{0}" of Line having selfQualifier "{1}".
Validation routeMetricIsOutOfRange The Route Metric must be between 1 and 255
Validation invalidSHA512Checksum The checksum is not valid.
Validation diagIntfMgmtIntfIpv6 You cannot configure the same IPv6 address for the management interface and the diagnostic physical interface.
Validation DHCPServerAutoConfigInterface DHCP server auto config requires a default interface
Validation invalidServerSecretKeyLength The server secret key exceeds the length limit, which is 64 characters.
Validation RaVpnConnectionProfileSAMLDuplicate The SAML Server {0} is already in use in a connection profile.
Validation numberofinterfacesDoNotMatch The number of interfaces in Lina do not match with the number in SSP
Validation staticRouteManagementOnlyInterface There are static routes configured for this interface. You must delete the static routes before changing the interface to management-only.
Validation invalidMaskedPasswordString Password cannot be the reserved masking string: "{0}"
Validation timeZoneInvalidTimeZoneId Invalid TimeZone Id. A valid UTC TimeZone ID must be provided for TimeZoneObject configuration.
Validation memberInterfacesNotAtLeastOneCommonSpeedCapability The selected member interfaces do not share a common speed capacity; you can only include interfaces that can operate at the same speed.
Validation invalidWebUpdateType Web Update Type "{0}" is not supported for Google Service Provider.
Validation SSLPolicyNoKeysForKnownKey You must identify at least one internal certificate to configure decrypt known-key rules in the SSL decryption policy
Validation sruUpdateError_10 3D version mismatch, unable to proceed with installation
Validation invalidBgpNetworkBridgeGroupInterface A Bridge group interface was configured for the same network. BGP cannot be configured on BVI interfaces.
Validation snort3NoPlatformSupport Snort 3 does not support the current platform.
Validation cannotUseDataInterfaceInVirtualPlatform Data interface cannot be assigned to Connectivity Interface in virtual platform.
Validation encProtocolCannotBeNullWithCert A certificate has been provided but no encryption protocol has not been provided
Validation easySetupCompletionFailed The device setup wizard was not completed.
Validation invalidV6Mapped IPv4-mapped IPv6 addresses are not supported.
Validation natDestinationModePassive Destination interface {0} is in passive mode. You cannot a use passive mode interface in NAT rules : {1}
Validation timeZoneInvalidISODate Invalid startDateTime or endDateTime. Use the ISO format YYYY-MM-DDTHH:MM, with time in 24-hour notation. The hour (HH) must be 0-23, and the minutes (MM) must be 0-59.
Validation conflictingFlexConfigPolicy There are FlexConfig objects in the FlexConfig policy that include prohibited commands. You must either remove the prohibited commands from the objects, or remove the objects from the FlexConfig policy.
Validation blacklistedCli You are not allowed to use the following commands in the object:
Validation acRuleInvalidRiskReputation You must specify a valid reputation
Validation ftdUpdateMgrError_162 Upgrade or cancel upgrade already in progress. Cannot cancel.
Validation switchModeNotSupported Switch mode is not supported on this platform.
Validation interfaceMigrateSourceAndDestinationMustBeInterfaces Source and destination IDs must belong to interfaces.
Validation nestedNetworkGroupMaxNestingLevel This network group has more than 10 levels of nested objects, which is the maximum allowed nesting level.
Validation snmpHostInterfaceNameNull Interface associated with an SNMP Host must have a valid name.
Validation AnyConnAddressPoolTooBig {0} address pool is too large, {1} contains more than 16384 addresses
Validation ntdDbCreationFailed Snort 3 rule package installation failed: Unable to create ntd.db.
Validation invalidFMCConnectivityInterfaceManagementIntfNotRoutedToDataIntf Connectivity Interface cannot be a data interface when management interface has a gateway address or not routed to a data interface.
Validation ipsecPolicyNeedIntegrity Policy must have at least one integrity checking method
Validation cfgExpEmptyEncryptionKey You must specify an encryption key to encrypt the zip archive generated by the configuration export job
Validation cfgImpEmptyConfigInput No configuration data is specified for the import job. Please specify either a config-file ID or input entities
Validation cannotCreateOrEditLDAPRealm Cannot create or edit LDAP Realm
Validation objectNatStaticTransNetNotNullAndIntfInTransNetIsTrue You cannot select both a translated address and interface for the translated address in static NAT
Validation invalidGatewayForInternalRouting You cannot specify a gateway when you are routing management traffic through the data interfaces.
Validation AnyConnOverlapNetworks Address pool {0} has address space overlap with the selected inside networks
Validation cliCommandSpaceBeforeAndAfterPipe Space not present before/after pipe symbol.
Validation ftdUpdateMgrError_182 No revert version available. Cannot revert.
Validation vtiCannotModifyTunnelId Cannot modify the tunnel ID of the Virtual Tunnel Interface as it is being used by another object. If this object is already deployed, you will need to remove the reference to the VTI in the object and redeploy.
Validation cannotCreateBaseLicense The base license cannot be created
Validation portNotExpected The protocol type selected does not require a port.
Validation fileMalwareSyslogServerRequired File malware syslog server is required.
Validation invalidLoggingListInvalidOPtions Please provide either message ID or class.
Validation attemptToChangeNoneditHardwareName Validation failed, attempt to change a non-editable name
Validation invalidSmartCliStringValuePatternAnnotation {0} value does not match the pattern it uses
Validation invalidRAVPNUsernameLength Invalid username length. Username length should be between {0} to {1} characters
Validation emptySSHAAASettingServerSecretKey AAASetting for SSH access cannot reference a {0} that has a {1} with an empty server secret key; "{2}" contains an empty server secret key
Validation addressDoesNotMatchPrefixLength The IP Address {0} does not match with the prefix length {1}. To specify a network use {2}/{3}. To specify a host use {4}.
Validation PullFileSuccess File upload was successful
Validation sseGetTokenAndRegionFailed Error in connecting to SSE Registration server to get token and domain.
Validation invalidConnectionType The Connection Type entered for Smart Licensing is invalid, please give either "Eval" for Evaluation Mode, "Register" with a token to register to the cloud or "UNIVERSAL_PLR" to enable Universal Permanent Licensing.
Validation failedToExportConfig You cannot export the configuration at this time. The system must complete an initial successful deployment before you can export the configuration.
Validation invalidSmartCliASPathValue {0} entity value must be an existing ASPath Object
Validation deleteObjWithContained Cannot delete object because it contains {0}. You must delete the contained objects prior to deleting this object.
Validation invalidObjectName The name "{0}" is invalid. The name can start with an alphanumeric character or an underscore. It can contain the special characters +, ., _ and -
Validation invalidFlexCliTemplate Template could not be resolved. {0}
Validation s2sDupRemotePeerIpAddr Duplicate remote-peer IP-address is found, remote-peer IP address must be unique across all S2S VPN connection profiles
Validation sequenceNumberInAscending IP prefix entries should be arranged in the ascending order of sequence number of an entry.
Validation SecurityIntelligencePolicyMoreThanOne Cannot have more than one Security Intelligence Policy.
Validation ipsecDupIkev2Prf Cannot have duplicate pseudorandom functions
Validation snmpUnsupportedSecurityLevel The specified SNMP user security level is not supported.
Validation unsupportedIkevTwoIpsecEncryptionsStrong The following encryption algorithms are not supported in IKEv2 IPsec proposals when strong encryption is enabled: DES.
Validation ftdUpdateMgrError_157 Cancel upgrade failed.
Validation bridgeGroupInterfaceUsedUnsupportedOptions {0} contains unsupported options.
Validation invalidSubinterfaceHardwareName Subinterface hardware name "{0}" does not match parent interface's hardware name "{1}" and Subinterface ID "{2}"
Validation unknownBooleanInput The Input for a Boolean type should be TRUE or FALSE
Validation sruUpdateError_13 Unable to install package
Validation natOrigMappedPortsAreNotBothSpecified The original and translated ports should be either both specified or both empty
Validation invalidOspfInterfaceNetworkType Network type must be point-to-point non-broadcast when OSPF neighbors are defined on this interface
Validation invalidInterfacesForBypassPair Invalid interfaces for bypass pair
Validation snort3ToggleFailed Failed to switch to Snort version 3: {0}
Validation userPreferenceNotFound Cannot find User Preferences.
Validation s2sVTIDynRRINotAllowed You cannot enable dynamic reverse route injection when using a static virtual tunnel interface for a site-to-site VPN connection.
Validation upgradeIncorrectTypeInvocation Upgrade could not be performed because of a system error, please contact the support.
Validation cannotCreateFMCRegistrationSettingsWithBackupInProgress Cannot create an FMCRegistrationSettings object while backup job "{0}" is in progress.
Validation invalidNodeId Validation failed due to invalid node ID: {0}
Validation performanceTierUnsupportedMethod The following method is not supported for tired licensing API.
Validation s2sIkev2InvalidRemoteKey Invalid IKEv2 pre-shared remote key. It must contain 1 to 128 ASCII printable characters, no whitespace, no single or double quotation marks,no question marks and cannot be a single digit
Validation interfaceMigrateSourceAndDestinationCannotBeUsedInHa Source and destination IDs cannot belong to interfaces used in HA.
Validation ddnsPasswordShouldBeNull Password should be set to null for Custom URL Service Provider.
Validation fileMalwareSeverityLevelRequired File malware severity log level is required.
Validation DHCPServerNoInterfaceNetMask The interface must have a netmask
Validation DHCPServerInterfaceModePassive You cannot use a passive mode interface for the DHCP server default interface.
Validation portSecurityInTrunkMode You cannot enable port security on a trunk port.
Validation IntrusionRuleUpdateNotAllowed You cannot change the state of a rule whose default state is Disabled
Validation unableToUpgradeToDestinationVersion The upgrade versions are invalid for source version {0} and destinationVersion {1}. This means that either the source version is greater than the destination version or the minimum required version to update to the destination version is higher than the current source version.
Validation invalidFlexCliLineNull A cli command cannot be null
Validation cannotTurnOffNetmodForHaMonitoredNamedInterfaces You cannot disable the Network Module on the active unit in a High Availability pair while an interface is being monitored for HA; this limitation does not apply to the standby unit. Interface {0} is currently being monitored. You must disable monitoring for this interface, deploy the configuration, and then disable the Network Module. Alternatively, you can make this unit the standby unit without altering the monitoring configuration.
Validation modeNotSupportedForEtherChannels Switch port mode is not supported for EtherChannels.
Validation invalidInterfaceInAAA Only routed mode interface is allowed in RADIUS server "{0}".
Validation aceDestinationEmptySourceIsNot The destination network list cannot be empty when the source network list has entries.
Validation cfgExpEmptyEntityIds You must specify at least one valid entity identity matcher for field entity IDs for a partial export job. Each matcher can either just be a UUID value or have a matcher pattern like 'id=', 'type=' or 'name='
Validation SSLRuleNullCertStatus Certificate Status cannot be null
Validation configDependentOnMissingInterface This configuration relates to an interface that is no longer on the system. You cannot modify this configuration, you must delete it. This configuration will not be deployed.
Validation invalidOspfInterfaceDuplicateConfiguration Interface {0} has already been configured for the protocol {1} in the object {2}
Validation haDeploymentAutoRecovered Successfully auto-recovered {0} deployment.
Validation ISETagDeleted Tag is deleted: {0}
Validation showPostUpgradeDialogCannotBeTrue The showPostUpgradeDialog value in PostUpgradeFlags cannot be set to true.
Validation passwordNoUplower Password does not contain an upper and a lower case character
Validation invalidFlexCliNetworkValue {0} value must be an existing NetworkObject or NetworkObjectGroup
Validation containedEntityNotFoundInContainer The contained entity to be updated is not found in the specified container
Validation RaVpnPriSecUsernameSame Primary and Secondary username fields cannot be the same.
Validation invalidFlexCliNumericValue {0} value is not a valid integer
Validation invalidSmartCliObjectNameValue {0} value must be same as the Smart CLI object name
Validation adiCliTestFailed The connection test failed.
Validation bridgeGroupInterfaceReferencedInSmartCli The following interfaces are referenced by Smart CLI: {0}. This feature is not compatible with a bridge group member interface. You must remove them before you can add the interfaces to a bridge group.
Validation AnyConnInvalidXMLFile {0} is a Invalid XML file.
Validation featureCapabilitiesIOReadException IO Exception thrown while trying to read Feature Capabilities from file {0}
Validation bridgeGroupInterfaceReferencedInDdnsService The following interfaces are referenced by DDNS Service: {0}. This feature is not compatible with a bridge group member interface. You must remove the interfaces from the configuration before you can add them to the bridge group.
Validation invalidFlexCliStringValue {0} value cannot be null or blank
Validation BannerHasQuestionMarkChar Banner display string cannot contain question mark character
Validation nullBgpNeighborRoutesAdvertisementInterval Advertisement Interval can not be null.
Validation cannotHaveRealmOnTheMemberOfBVI This interface is a member of a bridge group. You cannot use it in an identity realm configuration.
Validation s2sVTILocalNetworksNotAllowed You cannot configure the list of local networks when using a static virtual tunnel interface for a site-to-site VPN connection.
Validation packageFileShouldBePresentWhenEnableExternalBrowserIsTrue You must specify an external browser package when you select to use the default OS browser for SAML authentication.
Validation AnyConnACPrfInsideIntfHasNoName The interface {0} added to AnyConnectProfile should have a logical name.
Validation certKeyTypeAndSizeWeak Certificate digital signature key size is {0}, which is not supported. Supported key sizes for {1} signatures are: {2}
Validation unableToGetMaxDestinationVersio Unable to find the maximum destination version for the current source version.
Validation snmpConfigChangeTrapNotSupportedOnVirtualPlatform SNMP Config Change Trap not supported on Virtual Platform.
Validation IntfIsUsedInBvi Interface {0} is used in a bridge group interface.
Validation interfaceWithSpeedSFPDetect Interface {0} has speed type set on Detect SFP, FEC mode should be AUTO, auto negotiation should be enabled and duplex type should be set to FULL.
Validation bridgeGroupInterfaceReferencedInMgmtAccess The following Interfaces are used in management access configuration: {0}. This feature is not compatible with a bridge group member interface. You must remove the interfaces from the configuration before you can add them to the bridge group.
Validation monitoredAddressInvalidNetworkType The SLA Monitored address network object contains unsupported type.
Validation interfaceMissingName Interfaces used in DHCP Relay Service are required to have a name assigned. Interface with UUID {0} is missing a name.
Validation queryParameterNotValid Query parameter "{0}" is not valid because it contains forbidden characters.
Validation objectNatNoInterfaceSelectedWithRouteLookup Please specify both source and destination interfaces to enable route lookup
Validation bridgeGroupInterfaceMemberHasIpv6Address Bridge Group interface member {0} cannot contain IPV6 address
Validation msexeFileTypeShouldBeAddedForSperoAnalysis File Rule validations failed. You must add MSEXE file type to the selected list to use Spero Analysis.
Validation fileTypeAndFileTypeCategoryCannotBeNullAtOnce File Rule validations failed. At least one file type or file type category should be present.
Validation sruUpdateError_4 Error downloading rule update, file is corrupt (MD5 does not match). Please contact technical support or try again later.
Validation timeNotInRange The time value has to be between {0} and {1} {2}.
Validation featureInfoIOException IO Exception thrown while trying to read Feature Information
Validation invalidSmartCliUnsupportedVariableType {0} is not a supported variable type
Validation cloudAutoEnrollmentNotSupported This platform does not support Cloud Auto Enrollment. Supported device types are the Firepower 1100 and 2100 series.
Validation objectNat46DynamicNotAllowed Dynamic NAT is not allowed in an auto NAT rule for IPv4 to IPv6 address translation
Validation invalidSmartCliExpandedCommunityListValue {0} entity value must be an existing Expanded Community List Object
Validation searchDomainNameTooLong The domain search name in the DNS group is longer than 63 characters. The name must be shorter than 63 characters to use the group for data interfaces.
Validation performanceTierUpdateNotAllowedForUnregistered Performance Tier update operation is not allowed when device is unregistered.
Validation portConflictWithRAVPN The RA VPN outside interface is already using {0} as the HTTPS port. You must select a different value for the data interface's HTTPS port, or first change the RA VPN port number.
Validation SSLRuleNullRuleAction You must specify an SSL rule action
Validation existingConnection The device is currently operating in Evaluation, Registered or Universal PLR mode. If you would like to change the mode, you must update the existing connection object.
Validation invalidPasswordCombination You must enter both the new and old password
Validation s2sBackupPeerIkev2InvalidRemoteKey Invalid IKEv2 pre-shared remote key. It must contain 1-128 ASCII printable characters, no whitespace, no single or double quotation marks, no question marks and cannot be a single digit
Validation manualNatNoDestNatWithSrcNat64 Missing destination translation with IPv6 to IPv4 translation on source addresses
Validation unExpectedExitCode The script returned an unexpected exit code, {0}.
Validation invalidObjectForNotECMPZoneInterfaceAnnotation Validation could not be performed successfully due to a server issue. Please contact Cisco Technical Support.
Validation s2sNoRemotePeerIpAddr Remote-peer IP-address can not be null in case of static peers.
Validation unableToCancelPLRReservation Unable to cancel the Permanent Licensing reservation. In order to cancel PLR, Permanent Licensing deregistration must be in-progress.
Validation PullUpgradeSuccess Pull is completed successfully
Validation mandateVlanOnNamedInterface Interface cannot have a logical name if it has no VLAN assigned to it
Validation communityNumberNotInRange Community number {0} should be between 1 and 4294967295 or in the format aa:nn where aa and nn are 2-byte numbers. A number from 1 to 65535 can be entered for each 2-byte number.
Validation duplicateInterfaceInList There is already a management access list rule for this interface. Edit the existing rule.
Validation invalidDupOutAclRouteFilter Only one access list is allowed per protocol process
Validation SslRuleCannotHavePassiveZone You cannot use a passive security zone in an SSL rule.
Validation dynamicObjectGeneral An error has occurred.
Validation autoNegHasToBeNull AutoNeg field has to be set to null on this Platform.
Validation invalidEigrpDuplicateProcess Identifier value {0} does not match the EIGRP autonomous system number in use.
Validation cryptoNonCompliantIkev2PolicyForEncryptionType The upgraded IKEv2 policies use 3DES or NULL Encryption which is not supported on this FTD version: {0}.
Validation cannotConfigureIPAddress The interface is configured in {0} mode. You cannot configure an IP address on a {0} interface.
Validation licenseAlreadyExists This device already has a license of this type. You cannot have multiple licenses of the same type
Validation identityRealmNullEncryptionCert No encryption certificate defined for the realm
Validation interfaceNotPresentWithConfig The configuration includes references to a missing interface. Any elements that are dependent on the missing interface will not be deployed. Please re-evaluate the configuration, and if necessary, re-create the undeployable parts of the configuration for a valid interface.
Validation AnyConnNotSupportedNestedNetworkGroup You cannot use Nested network group {0} in the AnyConnectProfile {1}
Validation contextRetrieveFailed Could not retrieve device registration context. Please try again later.
Validation canNotUpdateTokenOnRegisterConnection Cannot update token on existing SmartAgentConnection object if it already has token and connection type is REGISTER.
Validation EmptySSLCipherSecurityLevel You must specify one of the open SSL security level
Validation geoUpdateError_10 Error running GeoDB Update
Validation invalidAuthorizationCode The Reservation Authorization code entered is invalid. The Reservation Authorization Code must follow the format XXXXXX-XXXXXX-XXXXXX-XXXXXX-XXXXXX-XXXX where X is any alphanumeric character.
Validation certTypeEmpty Certificate Type is empty. You must specify a type.
Validation invalidOspfInerfaceIsPassive Interface {0} cannot be passive
Validation cliCommandNotSupported This command is not supported or not recognized. Command abbreviations are not allowed.
Validation s2sIkev1NoEnabledPolicyWithAuth Cannot enable site-to-site IKEv1 without enabling any IKEv1 policy with authentication type {0}
Validation invalidSlaDataSize The size of the data payload value has to be between 0 and 16384 bytes.
Validation intrusionSettingsTooManySyslogServers This version does not support multiple syslog servers.
Validation cliCommandCommandNotAllowedAfterPipe Command {0} is not valid after pipe symbol. Only include, grep, exclude or begin allowed after pipe symbol.
Validation invalidRuleActionWithMalwareAnalysis File Rule validations failed. Malware analysis options are valid only for MALWARE_BLOCK and MALWARE_CLOUD_LOOKUP rule actions.
Validation AnyConnSplitTunnelNoInsideNet Split tunnel functionality requires at least one inside network
Validation standbyIPSameAsActiveIPAddress Standby IP Address cannot be the same as an active IP Address.
Validation sruUpdateUnknownError Unknown error occurred while updating Rule Update
Validation objectNatPortNotAllowedWithDynamicRule Port translation is not allowed with dynamic auto NAT
Validation bridgeGroupInterfaceCannotHaveIpv6AddressOfBgpNeighbor This IPv6 address is part of a neighbor that is being used in the BGP configuration. You cannot assign the same IPv6 address to a bridge group interface.
Validation MaxCountReached FDM can support a maximum of {0} VRFs.
Validation acRuleMixedIpv4v6AddressInSrcDestNetworks Source and destination networks contain a mix of IPv4 and IPv6 addresses
Validation scheduleDoesNotExist Unable to modify a scheduled job. No pending schedule.
Validation invalidOspfRouterId 0.0.0.0 is not a valid Router ID
Validation manualNatPortsNotAllTcpOrAllUdp Manual NAT rule port references should be either all TCP ports or all UDP ports
Validation interfaceCannotCreate An error occured while scanning the newly added interface {0}
Validation invalidEtherChannelId EtherChannel ID must be an integer between 1 and 48.
Validation vlanIdBeingUsedBySubInterface VLAN ID {0} is being used by subinterface "{1}" and cannot be assigned to a VLAN interface.
Validation PullUpgradeJobFailed Pull Upgrade job failed because stuck in progress
Validation invalidOspfInterfaceNotEnabled Interface {0} must be enabled to configure OSPF
Validation deprecatedApps An application filter cannot contain deprecated applications.
Validation RaVpnGroupPolicyAnyConnectClientProfileModuleNotAllowed ANY_CONNECT_CLIENT_PROFILE is not allowed as a module name
Validation invalidOspfNsfMechanismRequired You must specify the NSF mechanism to configure graceful restart
Validation PullFileFailed File upload failed.
Validation invalidCliObjectName The name "{0}" is invalid. The name can start with an alphanumeric character or an underscore. It can contain the special characters _ and -
Validation ipsecNormalModeNullIntegrity Normal encryption modes cannot be used with null integrity type, null integrity type is for combined modes
Validation invalidBGPExceededLimit Only one BGP protocol can be running in the system
Validation invalidNetworkSubtypeForManagementInterface The management access rule for the management interface contains a network object of an unsupported type.
Validation unsupportedIkevOneIpsecEncryption The following encryption algorithms are not supported in IKEv1 IPsec proposals: ESP-3DES.
Validation aceLogLevelNull The log level cannot be set to null when the logging option is enabled.
Validation redundantRegionForEnrollmentViaAutoEnrollment You should not specify the region when enrolling with the cloud using Auto Enrollment.
Validation trunkAllowedVlansLimit In trunk mode, the allowed VLANs must be from 1 to 20.
Validation invalidStaticMacAddress MAC address {0} is invalid. The allowed format is H.H.H, where H is a 16-bit hexadecimal digit.
Validation cannotUseDiagnosticInterface Diagnostic interface cannot be assigned to Connectivity Interface.
Validation InspectorSharedStateInvalid The following inspectors must always be enabled or disabled together: ({0}).
Validation adiCliTestSucceeded The connection test succeeded.
Validation ToggleToSnort3WithTimeBasedACLNotSupported Switching to Snort 3 is not allowed because you have Time Based ACL. Remove timeRange configuration and re-try.
Validation redundantTokenForEnrollmentViaAutoEnrollment You should not specify the token when enrolling with the cloud using Auto Enrollment.
Validation cannotTurnOffNetmodWhenNetmodInterfaceIsFailoverInterface You cannot disable the Network Module on the active unit in a High Availability pair while an interface {0} is being used as a failover or stateful failover link; this limitation does not apply to the standby unit.
Validation CannotDeleteOverriddenRule Cannot delete intrusion rule {0} as it is currently overridden in policies: {1}.
Validation DHCPServerIPPoolNetwork DHCP server IP address range {0} must not include the network address: {1}
Validation RaVpnConProfileIntfAddrOverLap Interface cannot be in the address pool range {0} used in RAVPN connection profile {1}
Validation exceedsMemberInterfacesLimitKPWM EtherChannel cannot contain more than 8 active physical interfaces on this platform.
Validation interfaceNotBrokenout Cannot perform join on an interface that is not broken out {0}
Validation unexpectedPLRUnsuccessfulGetAuthorizationCode Unable to attain the Authorization Code for Universal Permanent Licensing.
Validation SecurityIntelligenceExceededMaxNetworkListSize The combined number of entries in the network Block and Do Not Block lists cannot exceed 255.
Validation invalidAAARadiusIdentitySourceGroupSize RADIUS identity sources in a RADIUS identity source group must not exceed 16 entries
Validation invalidInterfaceBreakout The interface provided cannot be used for the breakout operation. Valid interfaces are interfaces with type PhysicalInterface.
Validation RuleGroupSnort2NotAllowed Custom rule groups are not supported with Snort 2.
Validation staticRouteWrongGatewayType Wrong gateway type for static route: {0}
Validation managementInterfaceCannotBeCreated You cannot create a new management interface.
Validation staticRouteInconsistentInterfaceProtocol Static route inconsistent protocol version for interface: IPv4 vs IPv6 {0}
Validation accountTypeNotPresent You should specify the account type you want to use for enrollment.
Validation invalidBackupFile Backup file is invalid. It does not have the manifest file.
Validation integrationkeyinvalid The Integration Key should be 20 characters containing only the characters A-Z, 0-9.
Validation nullObject Input object is null
Validation memberInterfaceShouldBeAutoNegCapable All member interfaces should have AutoNeg capability.
Validation objectNat66OrigAddrIpv6PrefixTooShort The original address IPv6 prefix must be greater than or equal to 64 in an IPv6 to IPv6 auto NAT rule: {0}
Validation updateTimedOut Update failed. Installation timed out.
Validation invalidGroupPolicy Invalid group policy configured for LDAP attribute value {0} in LDAP attribute map {1}.
Validation s2sIkev1CertificateNotSpecifiedWhenAuthMethodCert An internal certificate for IKEv1 policy must be provided when authentication via certificate is selected
Validation SSLSettingNoTLSV1_2ProtocolsAssigned Along with DTLSV1_2 protocol version, TLSV1_2 protocol version should be assigned.
Validation duplicateECMPZone Selected interface is already assigned to ECMP Traffic Zone "{0}".
Validation s2sBackupPeerIkev2LocalMaskedKeyNotAllowed Masked value for IKEv2 local pre-shared key is not allowed when creating a new backup peer or updating the IP address for an existing backup peer.
Validation invalidDuplexType Validaton Failed, This interface does not support {0} for duplex mode.
Validation ftdUpdateMgrError_183 Upgrade in progress. Cannot revert.
Validation ftdUpdateMgrError_184 Upgrade in progress. Cannot revert.
Validation manualNatRouteLookupSrcNetworkMismatch The Perform Route Lookup option is available for identity NAT only. The original and translated source networks must be identical to use the option.
Validation SystemDefinedCannotHaveBasePolicy A policy that is system defined cannot have a base policy.
Validation SSLRulesWithSnort3AndDetectionPolicy The access control policy is linked to a network analysis policy in detection mode with SSL decryption or TLS server identity configured. This feature combination is not supported. Change your network analysis policy to prevention mode or disable SSL decryption or TLS server identity and try again.
Validation cannotTriggerAutoEnrollmentApi Error in getting the token and domain from the Cisco Cloud Registration server. Refer to the Smart Agent logs for more details. Please retry and if the problem persists, contact Cisco TAC.
Validation useOfUnspecifiedIPAddressWithPrefix {0}/{1} is known as an Unspecified Address. This address cannot be assigned to an interface.
Validation troubleshootFailed Error generating troubleshooting file
Validation invalidFlexCliIPValue {0} value must be a valid IPv4 or IPv6 address
Validation s2sVTICannotBeUnnamed You must give an interface name to a virtual tunnel interface to use it in a site-to-site VPN connection.
Validation pppoeObjectIsOnlyRequiredWithPppoeType The pppoe object is only required when the PPPoE type is selected.
Validation downloaderNoResponse Snort 3 cloud update failed: The package downloader failed with no response.
Validation emptyMappings There are no mappings in the LDAP attribute map {0}. A map must contain at least one mapping of an LDAP attribute to a Cisco attribute name, or a group policy should be defined.
Validation upgradeDeviceNotRegistered You must register the device before starting a system upgrade.
Validation exceedLimitEnabledIkev1Policies The maximum number of IKEv1 policies enabled has already been reached ({0}). Please disable the unused policies.
Validation s2sNetworksStrictToMixed Local networks contain only {0} addresses but remote networks contain both IPv4 and IPv6
Validation invalidLoggingListMessageId Message ID should be in between {0} and {1}.
Validation invalidOspfNsfBoth NSF Cisco and IETF requires all LLS capability, Cisco helper, Opaque LSA, and IETF helper be enabled
Validation bridgeGroupInterfaceIdNotAvailable All bridge group interface IDs have been assigned between {0} and {1}
Validation selfSignedStartDateAfterEndDate The self-signed certificate validity end date cannot be in the past.
Validation FMCConnectivityInterfaceCannotBeMemberOfUserDefinedVrf The data management interface can only belong to the global virtual router.
Validation bgpAsDotNotationEnabled You must disable AS dot notation if you do not use the X.Y number format.
Validation unexpectedPLRUnsuccessfulDisable Unable to disable Universal Permanent Licensing.
Validation vtiTunnelSourceAllowedTypes Invalid type of tunnel source interface, the only types allowed are PhysicalInterface, SubInterface and EtherChannelInterface.
Validation noRetryAvailable No upgrade to retry at this stage.
Validation SecurityIntelligenceDNSPolicyGlobalBlacklistShouldBeFirstElement The DNS policy global Block rules should be in the first position in the Block list.
Validation s2sIntfForNatIsPassive You cannot use a passive mode interface for the NAT exempt interface of a site-to-site VPN connection.
Validation invalidMtuVirtual Invalid MTU for virtual device. You can set the MTU up to 9000 for virtual devices.
Validation snmpInvalidSnmpUserNameLength The SNMP user name cannot be longer than 33 characters, and it cannot be empty.
Validation valueNotInRange {0} value must be between {1} and {2}.
Validation monitoredInterfaceCannotBeDeleted You cannot delete an HA-monitored named interface on this platform. Please remove the interface from the HA monitoring list, perform deployment, and then you can delete the interface.
Validation SSLSettingInvalidECDHGroup Invalid Elliptical Curve Diffie Hellman Group assigned. Valid values are GROUP_19, GROUP_20 and GROUP_21.
Validation interfaceIsMemberOfEtherChannel Interface {0} cannot be a member of an EtherChannel interface and be used by DHCP Relay Service at the same time.
Validation noLogFileCorrupted Upgrade status JSON and log files maybe corrupted.
Validation nextHopNullSpecificIPNotNull Next Hop setting cannot be null when Specific IP is provided.
Validation unsupportedSpeedType Specified EtherChannel Speed type is not supported.
Validation AnyConnInvalidNetworkObjectType Network object type is not valid for address pool
Validation DHCPServerIntInIPPool Interface address {0} must not be in the IP address range: {1}
Validation AnyConnACPkgMissing AnyConnect client package {0} is missing
Validation invalidEigrpBVIInterface Cannot configure EIGRP on BVI Interface.
Validation IntfAddrOverLap Interface {0} cannot be in the address pool range {1}
Validation unsupportedRedistribution Unsupported redistribution protocol selected
Validation natPortRangeNotSupported Port range is not supported in auto NAT rules
Validation invalidOspfDuplicateNeighborInterface An OSPF neighbor is already defined on the interface {0}. Only one neighbor is allowed on point-to-point interfaces
Validation invalidEigrpDuplicateNetwork {0} has already been configured.
Validation invalidPrefix The Prefix entered is invalid
Validation emptyGroupPolicyForLdap There is no group policy mapping for LDAP attribute value {0} in the LDAP attribute map {1}.
Validation invalidObjectNameSpaceCommaAllowed The name "{0}" is invalid. The name can start with an alphanumeric character or an underscore. It can contain spaces and the special characters +, ., _, -, and ,. However, the name cannot include a leading or trailing space.
Validation CustomRuleGidInvalidValue The gid value for a custom rule must be {0}.
Validation AnyConnACPrfOutsideIntfCannotBeMgmt The interface {0} added to AnyConnectProfile is invalid, the outside interface cannot be for management only
Validation acRuleMoreThanOneEmbeddedAppFilter An access rule should not have more than one embedded application filter
Validation failedToExportHugePendingChangesToClipboard Pending Changes size exceeds the limit for copying to clipboard. Please download pending changes as a file.
Validation handlerError Internal error during feature toggle
Validation cryptoNonCompliantS2SIkev2Proposal The S2S VPN connection profile {0} is using IKEv2 proposals {1} having DES encryption which is disallowed when the Smart License Account has export-controlled features enabled.
Validation invalidObjectType The type is invalid.
Validation invalidHostName The fully-qualified domain name (FQDN) or IP address is not valid.
Validation unsupportedIkevOneEncryptionStrong The following encryption algorithms are not supported for IKEv1 policies when strong encryption is enabled: DES.
Validation AnyConnExcessProfile Can have only one Any-Connect connection profile
Validation SecurityIntelligenceExceededMaxURLListSize The combined number of entries in the URL Block and Do Not Block lists cannot exceed 32767.
Validation cannotDiscardDuringDeploy You cannot discard pending changes while a deployment is in progress. Please wait for the current deployment to finish.
Validation pppoeNotSupportedOnManagementInterface PPPoE is not supported on Management Interface.
Validation taskStatusNotAvailable Status not available
Validation SSLSettingNoTLSVProtocolsAssigned Along with DTLSV protocol family version at least one TLSV protocol family version should be assigned.
Validation haBreakFromSingle The device does not have HA configured, {0} cannot be executed.
Validation methodException Validation failed due to an exception: {0}
Validation snort2ToggleFailed Failed to switch to Snort version 2: {0}
Validation invalidCertificate Certificate is not valid
Validation acPolicyInvalidIPS The selected intrusion policy cannot be used in an access rule.
Validation userServiceTypesIsNullOrEmpty The user service types cannot be null or empty
Validation s2sCryptoRestrictedIkev1Proposals S2S VPN uses IKEv1 IPsec proposals with strong encryption, which is not allowed by your licensing setting. Please use DES only
Validation invalidOspfAreaCost Area cost is not applicable for backbone area
Validation invalidFlexCliBooleanValue {0} value must be set to either true or false
Validation autoSpeedMustHaveAutoDuplex Interface with speedType and duplexType must match if either is set to AUTO.
Validation invalidAgentStatus Invalid Smart agent status
Validation externalBrowserPackageFileIsMissing The following external browser package is missing: {0}
Validation invalidLocalUserType The local user selected must be of type "trafficuserentry"
Validation DapXmlDuplicateRecords There are one or more duplicate records : {0}
Validation invalidNetworkObjectType Type has been set to an invalid value {0}
Validation minIpv6MtuIs1280 To configure IPv6, the minimum MTU is 1280.
Validation missingBuildNumber Snort 3 rule package installation failed: Unable to obtain package build number.
Validation cannotFindDiagnosticInterface Cannot find diagnostic interface for convergence in the database.
Validation unsupportedIkevOneIpsecAuth The following ESP hash algorithm is not supported in IKEv1 IPsec proposals: ESP-MD5-HMAC.
Validation s2sCryptoRestrictedIkev2Proposals S2S VPN uses IKEv2 IPsec proposals with strong encryption, which is not allowed by your licensing setting. Please use DES only
Validation ftdUpdateMgrError_156 Cancel operation is not available.
Validation interfaceMigrateCannotMigrateBetweenPassiveAndNonPassive You cannot migrate between passive and non-passive interfaces.
Validation invalidOspfVirtualLinkAuthKeyNotEnabled The selected authentication type is password authentication. You must also configure the authentication key
Validation featureCapabilitiesNoResource No feature capabilities resource found in application context files
Validation AnyConnInsideIntfAddrOverLap Cannot use an address pool with range {0} because it contains the address used on inside interface {1}
Validation switchPortConfigurationNull Interface {0} must define a switch port configuration when it is in switch mode.
Validation externalBrowserPackagesExceedsAllowedNumber You can upload a maximum of {0} external browser packages.
Validation blacklistedFlexConfigPolicy There are FlexConfig objects in the FlexConfig policy that include prohibited commands. You must either remove the prohibited commands from the objects, or remove the objects from the FlexConfig policy, before you can add new Smart CLI objects.
Validation s2sPfsNoGroup The S2S VPN connection profile {0} uses unsupported {1}. The following Diffie-Hellman groups can no longer be used for Perfect Forward Secrecy: 1, 2, 5, 24.
Validation invalidBgpNextHopTriggerEnable The Next hop trigger enable value should match the next hop trigger enable value in General Settings.
Validation bridgeGroupInterfaceEnableIpv6AutoConfig Bridge group interface do not support IPV6 option auto-config
Validation invalidFlexCliUnsupportedNumericValue {0} value cannot have signs or leading zeros
Validation configImpExpUnsupportedVersion Configuration Import Export feature is only supported on the latest version.
Validation noRollbackScript The script to cancel upgrade is not available at this stage.
Validation cannotCreateIdRuleWithoutCert Cannot create an identity rule if the Server Certificate for Active Authentication is not provided
Validation defaultActionNotPassiveOrNoAuth The default action in the identity policy should be Passive or No Authentication
Validation appFilterInvalidRiskValue Invalid application filter risk value {0}.
Validation AnyConnPrefillUsernameAndDisabledUsernameEditFromCertificateNotEnabled Please enable PrefillUsernameFromCertificate and DisablePrefilledUsernameEdit option to update password type.
Validation invalidDomainName The Domain name is invalid. It can contain only letters, digits and the characters '.' or '-'. It can consist of multiple sections, each separated by a '.'
Validation unsupportedIkevOneIpsecEncryptionStrong The following encryption algorithms are not supported in IKEv1 IPsec proposals when strong encryption is enabled: ESP-DES.
Validation invalidTemplateIdentifier Template identifier is not valid. {0}
Validation onlySupportsMajorUpgrade This API is only available for major upgrades.
Validation vdbUpdateError_7 Peer certificate cannot be authenticated with known CA certificates
Validation AnyConnNatNoInsideNet NAT exempt functionality requires at least one inside network
Validation s2sVTISVTINotEnabled You must enable static VTI to use a virtual tunnel interface for a site-to-site VPN connection.
Validation subIntfVlanIdNotNull VLAN ID must be null when sub-interface is in switchport mode.
Validation cryptoNonCompliantIkev2ProposalForEncryptionType The upgraded IKEv2 proposals use either 3DES or AES_GMAC or AES_GMAC192 or AES_GMAC256 Encryption which is not supported on this FTD version: {0}.
Validation invalidSmartCliPortValue {0} entity value must be an existing TCPPortObject or UDPPortObject
Validation unableToParseIseConfigTestOutput An error occurred trying to parse the response from ISE.
Validation interfaceJoinCreate An error occurred while joining Network Module interface {0}
Validation invalidEtherChannelIdWMDesktop EtherChannel ID must be an integer between 1 and 8.
Validation snmpUnsupportedManagementAddressType SNMP Hosts with Host Group type supports only Range and Network manager address types. SNMP Hosts of SNMP Host type supports only Host manager address.
Validation interfacePresentFieldReadOnly Presence of an interface is not user configurable.
Validation snort3LspTarDdVersionUnknown Unable to find a appropriate datasource that matches the installed Snort 3 Version.
Validation memberInterfaceCannotBeEmpty EtherChannel must have at least one physical interface member.
Validation timeZoneInvalidOffset Invalid DST Offset. A valid offSet must be provided for TimeZone Object custom configuration. Valid Offset must be between 1-1440.
Validation bgpNeighborFilterDistributedListSameFilterDirection Prefix list and Distribute list can not co-exist for same filter direction.
Validation staticRouteUsingInterface Interface {0} referenced in static route {1} can not be moved to a different VRF
Validation DHCPServerIPPoolBroadcast DHCP server IP address range {0} must not include the broadcast address: {1}
Validation appFilterAppNotFound Application filter application not found {0}.
Validation InvalidRuleGroupId Could not find a rule group with the ID of {0}.
Validation AnyConnMaxConnTimeoutInvalid Anyconnect maximum connection timeout cannot be greater than 4473924 minutes
Validation s2sNoBackupPeerIpAddr Backup peer IP address cannot be null or empty.
Validation vdbUpdateError_15 VDB update file not found.
Validation invalidDisabledLoggingValues When the logging option is set to disabled, the log level and log interval must be null.
Validation SSLSettingSameProtocolVersion You cannot refer to multiple SSL Cipher objects with overlapping Protocol versions in Data SSL Cipher Settings. Overlapping versions are {0} part of Cipher objects {1}.
Validation invalidSmartCliUnsupportedNumericValue {0} value cannot have signs or leading zeros
Validation AnyConnAuthMethodMustBeAAAAndClientCertificateToEnablePasswordType Auth method must be {0} for using Password Type on user login window
Validation TimeBasedACLNotSupportedWithSnort3 TimeRange is configured. This is not supported with Snort3. Remove timeRange configuration and re-try.
Validation appTagInvalidName Invalid application tag name {0}.
Validation subInterfaceNotAllowed The interface is configured in {0} mode. You cannot create subinterfaces on a {0} interface.
Validation RaVpnGroupPolicyInvalidNumberVal Invalid Value. Valid range is {0} to {1}.
Validation PullInvalidFilename Filename is invalid
Validation duplicateSubInterfaceId Subinterface ID {0} already exists for {1}
Validation cannotAssignDHCPWhenHAIsEnabled Interface {0} cannot be assigned a DHCP address when HA is enabled.
Validation RuleMustHaveValidRevision Rule must have a revision number greater than or equal to 1.
Validation disableSha256CantBeLesserThanMaxFileSize SHA 256 can be disabled only for a file which exceeds the maximum file size.
Validation IntrusionPolicySnort2DeleteNotAllowed You cannot delete an Intrusion Policy in Snort 2 mode.
Validation aaaSpecifiedAuthIdentitySourceNotSupported Specified authentication identity source is not supported
Validation invalidPortRange Invalid port range. Beginning port must be less than ending port.
Validation noImsConfFile The ims conf file cannot be found.
Validation ntpDuplicate NTP server {0} is specified more than once. Please remove duplicate servers.
Validation IntrusionPolicyNameOrDescriptionChangeNotAllowed You cannot change the name or description of an intrusion policy.
Validation invalidAsciiCharacterForLina The name and password can contain any printable ASCII alphanumeric or special character except spaces and question marks. Printable characters are ASCII codes 33-126.
Validation subInterfaceNotAllowedInSecurityZone SubInterfaces are not allowed in a security zone with mode passive.
Validation ftdUpdateMgrError_254 Retry upgrade failed. Use the 'upgrade cancel' API to cancel.
Validation hardwareNameCannotBeNull Hardware name cannot be null.
Validation invalidOspfInterfaceNoIP Cannot configure neighbor on interfaces without IP address. Assign an IPv4 address to the interface
Validation s2sFQDNNetwork Site-to-site profiles cannot have FQDN type network objects
Validation vdbUpdateError_10 The latest VDB update is already installed
Validation invalidOspfNsfConflictingConfiguration Conflicting NSF graceful restart configuration
Validation emptyConnectivityInterfaceNameNotAllowed Interface associated with ConnectTest should have a non-empty NAME.
Validation bridgeGroupInterfaceCannotHaveIpv6AddressOfBgpNetwork This IPv6 address is part of a network that is being used in the BGP configuration. You cannot assign an IPv6 address from this network to a bridge group interface.
Validation s2sBackupPeerSameAsPrimaryPeer IP address of one of the backup peers is the same as that of the primary peer.
Validation prefixNotAllowed Invalid range. Prefix/subnet mask is not allowed in range object.
Validation appTagInvalidDesc Invalid application tag description {0}.
Validation SslRulesWithDeprecatedCategories Some of the SSL decryption rules refer to deprecated URL Categories. Number of SSL decryption rules affected: {0}.
Validation CustomRuleGroupSnort2 Custom rule groups are not supported in Snort 2.
Validation invalidLicenseForDeployment Deployment is blocked. This device does not have a base license. You cannot deploy changes.
Validation threadError Error occurred during thread sleep.
Validation ipsecPolicyInvalidLifetime Lifetime value not in range: {0}
Validation AnyConnNoIpv4InsideNetwork With {0} as an IPv4 address pool, you must have at least one IPv4 inside network specified
Validation UpgradeReadinessJobFailed Upgrade Readiness job failed because stuck in progress
Validation AnyConnOutsideIntfAddrOverLap Cannot use an address pool with range {0} because it contains the address used on the selected outside interface {1}
Validation objectNat64AnyIpv6NotValid The network corresponding to the full range of IPv6 addresses, i.e. ::/0, cannot be used in an IPv6 to IPv4 object NAT rule
Validation invalidOperationOSPFNeighborDefined Operation cannot be performed when an OSPF neighbor is enabled for this network
Validation invalidNetworkSubtypeForFlexPolicy The FlexConfig policy contains a variable for a network object of an unsupported type.
Validation duplicateInterfaceSelected Selected interface is already assigned to DDNS Service "{0}".
Validation onlyIPv4NetworkObjectsAllowed Only IPV4 networks are allowed.
Validation authTokenNotEqual32 The registration key must be 32 characters.
Validation AnyConnNatNoInsideIntf NAT exempt functionality requires at least one inside interface
Validation manualNatNoInterfaceSelectedWithRouteLookup Please specify at least one interface to enable route lookup
Validation invalidIdentitySourceGroup "identitySourceGroup" field can only be of type {0}
Validation InvalidOverrideStateForRule Invalid security level for rule group: {0}.
Validation lspExtractingFailed Failed to extract package {0} during LSP package installation.
Validation vdbUpdateError_4 Error downloading rule update, file is corrupt (MD5 does not match). Please contact Technical Support or try again later.
Validation snmpInvalidAuthenticationPasswordLength Authentication password should be an encrypted string with length 8 - 257 characters.
Validation sruUpdateError_14 Error running Rule update
Validation invalidDuplexSpeedComboNotSupported Invalid duplex and speed combination.
Validation conflictingInterface All syslog servers should have same interface type. i.e either all servers should have management interface or all should have data interfaces.
Validation accountTypeNotSupported You cannot enroll in the cloud with the specified account type.
Validation unnamedInterfaceInSecurityZoneNotAllowed This interface is part of security zone: {0}. You must remove the interface from all zones before you can remove the interface name.
Validation updateSkipped The latest rule package is already installed.
Validation manualNatSrc46Ipv6RangeObjNotAllowedInTransSrc You cannot use an IPv6 range network object as the translated source in an IPv4 to IPv6 manual NAT source translation rule: {0}
Validation cryptoCompliantS2SIkev2Proposal The S2S VPN connection profile {0} is using IKEv2 proposals with strong encryption which is not allowed by your licensing setting, please de-reference them and use DES only: {1}
Validation cryptoNonCompliantS2SIkev1Proposal The S2S VPN connection profile {0} is using IKEv1 proposals {1} having DES encryption which is disallowed when the Smart License Account has export-controlled features enabled.
Validation managementInterfaceAttributeCannotBeUpdated You cannot change which interface acts as the management interface.
Validation failedToConvertJSON Failed to convert upgrade revert info JSON to java object.
Validation bgpAsDotNotationNotEnabled You must enable AS dot notation to use the X.Y number format.
Validation externalBrowserPackageCannotBeDeletedFromRavpnWhenUsedInProfiles You cannot delete the external browser package from RA VPN {0}, because it is being used in a connection profile.
Validation emptyInterfaceNameNotAllowed Interface associated with an ECMP Traffic Zone should have a non-empty NAME.
Validation DHCPServerIPPoolAsClient DHCP server IP address range is not valid if its already defined as a DHCP Client.
Validation geoUpdateError_3 The update server did not have a file applicable to this device. Try again later. If the problem persists, contact Technical Support.
Validation pppoeDuplicateVpdnGrpName The vpdnGrpName is the same as the PPPoE from interface {0}.
Validation ecmpZoneInterface This interface is being used in an ECMP Zone. You cannot use this interface for other purposes.
Validation checksumError Error in {0} checksum. The file is corrupt, obtain a new copy.
Validation cannotAddRaVPNInterface Interface {0} is used for remote access VPN. You cannot include it in an ECMP traffic zone.
Validation invalidNetworkSubtypeForIdentityRuleSource The identity rule source criteria contains a network object of an unsupported type.
Validation cfgExpInvalidObjTypesInEntityIds Invalid entity types for a partial export job: {0}
Validation updateJobExists A Manual Update Job of this type already exists.
Validation cannotDeleteReferredLocalUserInRule Cannot delete local user object because it is being used by an access or SSL rule.
Validation bgpInvalidMinHoldTime Minimum hold time should be less than hold time
Validation s2sIkev1Ikev2BothDisabled IKEv1 and IKEv2 cannot be both disabled. You must enable either one or both
Validation appFilterInvalidProductivityValue Invalid application filter business relevance value {0}.
Validation bgpInvalidGracefulRestartAndStalepathTimeDifference There should be at least 240 secs difference between the restart timeand the stale path time
Validation invalidSmartCliStandardCommunityListValue {0} entity value must be an existing Standard Community List Object
Validation illegalNumBitsForMask Invalid number of bits for mask - {0}. Mask cannot be greater than 128
Validation ECMPStaticRouteNotInECMPZone There is already a static route with the same networks on different interface. You must specify another metric or add interfaces to an ECMP Zone.
Validation errorInEnablingCDO Enabling Cisco Defense Orchestrator service failed.
Validation manualNatDest64AnyIpv6NotValid The network corresponding to the full range of IPv6 addresses, i.e. ::/0, cannot be used in the destination of an IPv4 to IPv6 manual NAT rule
Validation InvalidBgpNeighborRoutesRemovePrivateAs Private AS cannot be removed for IBGP peers. You cannot configure if BGP AS number is same as remote-as number.
Validation cryptoNonCompliantIkev2Policy The IKEv2 policies are using DES encryption which is disallowed when the Smart License Account has export-controlled features enabled: {0}.
Validation passiveModeNotSupported Passive mode is not supported on this interface.
Validation jobRunning The task you are requesting is already in progress or it is queued to start.
Validation s2sIkev2ProposalsTooMany Too many IKEv2 proposals. Number of assigned IKEv2 proposals cannot exceed {0}
Validation customRulesFileImportFailure Failed to import rules.
Validation aaaInvalidUsername Username cannot be empty or contain spaces
Validation invalidCacheTimeValue Refresh time (minutes) for the CRL cache is invalid.
Validation haActionOnInvalidState The current node state {0} does not allow HA {1} action.
Validation securityProtocolIsDeprecated Security protocol version {0} is deprecated. You cannot use it.
Validation InstanceMissingNameField Instance is missing name field.
Validation pppoeIpv4AddressIsStatic The pppoe IPv4 IPAddress is static and should be provided.
Validation MustProvideRuleGroupId You must provide at least one rule group ID.
Validation manualNatDestIntfIpv6DisabledWithIpv6InTransSrc Destination interface "{0}" is not IPv6 enabled. You cannot use IPv6 addresses in the translated source
Validation napConfigOverrideCheck Latest LSP update affected inspector overrides {0} under policy [{1}].
Validation invalidOspfRedistBgpIdentifier Identifier value {0} does not match the BGP autonomous system number in use
Validation invalidLengthFqdn The fully-qualified domain name cannot be more than 128 characters.
Validation unsupportedSSPInterfaceSpeed Unsupported SSP Interface Speed on NGFW: {0}
Validation overlappingSubnet The IP address, {0}/{1}, cannot overlap with the subnet of interface {2}
Validation cloudRegionWithRegionDoesNotExist The {0} cloud region does not exist.
Validation featureCapabilitiesNoHandler Found feature capability without a matching capabilities handler
Validation maxOneInterface Either Data interface or management interface can be selected.
Validation dupRealmInRealmSequence Realm Sequence Object should not contain duplicate realms.
Validation IntfAddedIsOutside The interface {0} is already added as an outside interface.
Validation snmpUserGroupContainAltLeastOneUser SNMP User Group has to contain at least one user.
Validation invalidOspfRedistEigrpIdentifier Identifier value {0} does not match the EIGRP autonomous system number in use
Validation reservedAddressNotAllowed The IP address cannot be a reserved address (240.x.x.x to 255.x.x.x).
Validation ipAddressIsBlocked The IP address {0} is reserved. You cannot assign it to the interface.
Validation powerOverEthernetConsumptionWattageShouldBeNull Consumption wattage cannot be set on PoE disabled physical interface.
Validation PullFileHTTPFailed File upload failed - Http(s) Transfer Error Status -
Validation XmlConfigNotWellFormed XML configuration must be a well formed XML
Validation SSLPolicyDefaultActionBlockorDND Default action for SSL policy can only be block or do-not-decrypt
Validation bgpInvalidAggregationToAnyIP Aggregating to default is not allowed
Validation bypassInterfacePairEmpty The hardware bypass pair contains no interfaces
Validation ftdUpdateMgrError_240 Retry operation is not available. Reboot to continue.
Validation geoUpdateError_12 GeoDB update file not found.
Validation ddnsRunTimesShouldBeNull run times should be set to null when UpdateInterval is On Change.
Validation invalidSmartCliStringValueBlank {0} value cannot be null or blank
Validation bridgeGroupInterfaceRederencedInBridgeGroup The following interfaces are referenced by another Bridge Group Interface: {0}. You must remove them before you can add the interfaces to a bridge group.
Validation invalidOspfInterfaceVrf Interface {0} should be a member of virtual router {1}.
Validation InvalidInspectionMode The inspection mode must be DETECTION or PREVENTION.
Validation DHCPServerInterfaceName This interface is being used as a DHCP server. You cannot remove the interface name until you change the DHCP server configuration.
Validation manualNatSrc46Ipv6PrefixTooLong The translated source IPv6 network prefix length must be less than or equal to 96 in an IPv4 to IPv6 manual NAT source translation rule: {0}({1})
Validation interfaceMigrateSourceAndDestinationCannotBeDiagnostic Source and destination IDs cannot belong to the management interface.
Validation ftdUpdateMgrError_185 Cancel upgrade in progress. Cannot revert.
Validation manualNatDest66TransDestIpv6PrefixTooShort The translated destination IPv6 prefix must be greater than or equal to 64 in an IPv6 to IPv6 manual NAT destination translation: {0}
Validation AnyConnAuthenticationIdentitySourceNotSupported Authentication identity source of type {0} is not supported.
Validation frequencyShouldBeMultipleOfThousand The frequency value should be a multiple of 1000.
Validation versionMismatch This upgrade is for software versions greater than or equal to {0} and less than {1}.
Validation DHCPServerInterfaceMgmt DHCP server cannot be configured on the management interface.
Validation appFilterInvalidRiskName Invalid application filter risk name {0}.
Validation snort2ToggleSuccess Successfully switched to Snort version 2.
Validation AnyConnInsideNetNoPool {0} address pool is required if {0} inside networks are specified
Validation DapXmlMustContainDfltRecord Provide only DfltAccessPolicy record config when the DAP XML is empty
Validation invalidManagementIP Cannot configure on managementip without IP address. Assign an IPv4 or IPv6 address to the Connectivity Interface.
Validation connectorIOError Connector failed to connect. Please check the connection.
Validation noRevertInfo No other version is available for Upgrade Revert.
Validation sslUnsupportedForCryptoCompliantAlgorithms The DES encryption algorithm is not supported when strong encryption is allowed by your license.
Validation manualNatTransDestHasIpv6AndIpv4Addresses The translated destination network should not contain both IPv4 and IPv6 addresses
Validation emptyAddressPoolForNatEnabled NAT Exempt cannot be enabled when there is no client address assignment pool configured on any RAVPN connection profile or any of the group policies.
Validation natOtherOptionsNotSupported The following options are not supported and should not be selected in NAT rules: {0}
Validation HTTPProxyCheckConfigAfterRestore HTTP proxy is enabled after restore, please check the proxy reachability.
Validation invalidECMPZoneInterfaceVrf Interface "{0}" should be a member of Virtual Router "{1}".
Validation invalidEtherChannelHardwareName EtherChannel Hardware must be null, empty, or in the correct format (correct format is: Port-channel appended with EtherChannelID)
Validation natRuleImpactWithInterfaceChangingVRFConfig One or more interfaces were moved from one virtual router to another. Any existing connections on moved interfaces will be dropped. One or more interfaces that were moved also have NAT rules configured. Please ensure you have configured appropriate routes across the virtual routers for those rules to function correctly.
Validation DapXmlMissingRecords DAP XML configuration is missing some records : {0}
Validation CustomRuleMinSidValue The sid of a custom rule must be {0} or higher.
Validation s2sNoRRIAndDynamicRRI Dynamic reverse route injection cannot be enabled without enabling reverse route injection in site-to-site VPN
Validation backupInvalidEncryptionKey Encryption key cannot be the reserved masking string: "{0}"
Validation prefixGreaterThanMask The {0} prefix length should be greater than the IP address subnet mask value.
Validation cannotChangeExternalUserPassword You cannot change the password for an externally authenticated user. Change the password in the external AAA server instead.
Validation bgpDuplicateInjectMapEntryNotAllowed Duplicate Inject Map Entries are not allowed.
Validation s2scaCertUsedAsInternalCertificate CA or self-signed certificate cannot be used as identity certificate for authentication between Site-to-Site VPN peers. Please provide a valid identity certificate for successful VPN establishment.
Validation cryptoNonCompliantIkev2PolicyForPrfType The upgraded IKEv2 policies use MD5 as Pseudo Random Function (PRF) Hash which is not supported on this FTD version: {0}.
Validation securityIntelligenceWhitelistPolicyUnsupportedNetwork The Security Intelligence Do Not Block list contains an unsupported network : {0}
Validation SAMLSystemDefinedCert System defined certificates are prohibited. Use a certificate provided by the SAML issuer.
Validation SSLCipherInvalidSecurityLevelForProtocolVersion Security level {0} not applicable for protocol versions {1}
Validation objectNat46AnyIpv6NotValid The network corresponding to the full range of IPv6 addresses, i.e. ::/0, cannot be used in an IPv4 to IPv6 object NAT rule
Validation cryptoCompliantIkev1Policy The IKEv1 policies are using strong encryption which is not allowed by your licensing setting, please disable them or use DES only: {0}
Validation invalidSlaTypeOfService The value defines the Type of Service (ToS) type has to be between 0 and 255.
Validation scheduleInvalidName Invalid schedule name
Validation invalidCharacters Cannot contain special characters {0}
Validation IntrusionRuleGroupNotFound Unable to find the IntrusionRuleGroup with ID:{0}.
Validation invalidPlatformLogSettings Platform log settings property cannot be accepted on this platform.
Validation missingIdentityPolicyinAccessPolicy You cannot disable the realm because an identity policy that uses it is associated with an access control policy.
Validation taskRunning The task is queued/in-progress. Task cannot be deleted.
Validation timeRangeInvalidRange The time range specification is incomplete. To configure a time range, you must specify the range's start day, end day, start time, and end time.
Deployment checksumTimeoutError The deployment process could not retrieve the checksum. Please run deployment again.
Deployment missingRequiredPackage A package file required for deployment, {0}, does not exist. The installation of a {1} update package may be required.
Deployment error Error during deployment
Deployment alreadyQueued There is already a deployment task pending. Wait until it completes before deploying changes again.
Deployment sruInfoLoadFail The rule installation is corrupted. Please run a rule update to fix the problem.
Deployment deltaCliError Internal error during delta CLI generation
Deployment nothingTodeploy Nothing to Deploy.
Deployment ASAConfigExportFailedMessage Deployment failed because exporting the Lina configuration failed.
Deployment failedUnknownReason Deployment failed for an unknown reason. Please try deploying changes again. If the problem persists, reboot the device and try again. If you continue to have problems, contact Technical Support.
Deployment invalidPeerState Failed to run {0} deployment because the peer is not ready to synchronize configuration. Peer state: {1}
Deployment noChassissSerialNumber Failed to retrieve the chassis serial number.
Deployment deployPendingChanges There are pending changes or mandatory deployment is required. Please deploy changes first.
Deployment missingHaConfiguration Failed to read Interfaces from HAConfiguration object.
Deployment mergedDbNotEqual Encountered an error when merging the databases for export.
Deployment generalIOError Deployment cannot be performed due to an internal server error
Deployment currenrPolicyBundleUpdateFailed Configuration is partially deployed and not completed. Please run deployment again.
Deployment failedEncryptionOnCertificateKey Failure in encrypting the certificate key.
Deployment archiveError Error creating deployment archive
Deployment generalError Internal error during deployment: {0}
Deployment deployInProgress You cannot start deployment with a deployment job already in progress
Deployment unfinished The previous deployment did not finish properly. Please redeploy the changes.
Deployment invalidNodeState Failed to run {0} deployment because the node is in {1} state.
Deployment pwdDecryptionError Server failed to decrypt password for user {0}. If the problem persists, please re-create the user instance.
Deployment sensorExportFailedMessage Deployment failed because exporting the Sensor configuration failed.
Deployment failedUnableToResolveHostname Unable to resolve the hostname {0} with exception {1}, failing the deployment
Deployment timeoutError The deployment process timed out. Please run deployment again.
Deployment requireNetModFixIntfSpeeds The inserted Network Module interfaces changed some of the interface speed capabilities. Before deploying, please fix the interface speeds for: {0}
Deployment requireInterfaceScan Some interfaces have been added to or removed from the device. Please perform an interface inventory scan before deploying the current configuration.
General fileTypeAndCategoryCsvFilesNotFound The required CSV files for File Type and Category Bootstrap not found.
General accessDeniedHaStandbyWriteProhibited This device is part of a high availability (HA) pair and is currently not in the active state. With few exceptions, you cannot edit the configuration for this device. To make any changes, please log into the active unit.
General invalidNeighborGeneralDescription Neighbor General description cannot contain spaces or question mark
General FailedStringToJsonConversion Failed to convert String to Json.
General FailedJsonToStringConversion Failed to convert Json to String.
General HitcountCliParseFailure Failed to parse output from FTD CLI
General smartLicenseDeregistrationJobInProgress Deregistration is in progress.
General tooManyFailedAttempts Too many failed attempts. You must wait before you can try again.
General ltpSudiConnectionError Failed to connect to the Cisco Cloud from the platform. Check network connectivity with the cloud and retry.
General exportCommittedConfig Committed state configuration. Cannot export if deployment is not performed.
General deviceAlreadyRegistered The device was already enrolled.
General couldNotFindStatus The requested deployment status id, {0}, does not exist.
General prefixNameContainsInvalidChar Prefix name cannot contain characters other than a-z, A-Z, 0-9, -, and _
General smartLicenseDeRegistrationJobCompleteSuccessfully Smart License successfully deregistered.
General ciscoSseRegistrationSuccessful Cisco cloud registration is successful
General failedToToggleCloudServiceState Failed to toggle Cloud Service state.
General ltpSudiToolNotFound Suditool script not found. Please retry. If the problem persists, contact Cisco TAC.
General addFMCManagerSuccess FMC manager was successfully added.
General CouldNotUpdateRule Failed to update rule with Uuid: {0}
General cloudUnregistrationInternalError Received internal server error from cloud service. Retry after some time. If problem persists, contact Cisco TAC.
General cloudEnrollmentDroppedConnection Cloud service dropped connection. Retry after some time.
General cleaningUpAfterCancellation Cleaning up after FMC registration job was canceled.
General cloudServiceEnablingNeedsCloudEnrollment Before enrolling in {0}, you must enroll the device in cloud.
General errorConnectingToRadiusIdentitySource Error connecting to RADIUS identity source
General cloudRegistrationConnectionUnauthorized Connection to cloud service unauthorized. Re-register with a new valid token.
General ampConnectionSuccess Successfully connected to cloud
General couldNotGetValidURLResources Failed to get the list of valid URL resource names for authorization enforcement
General cleaningUpAfterTimeOut Cleaning up after FMC registration job timed out.
General CliCommandFileParsingError Exception occurred while parsing the command file.
General ciscoSseRegistrationFailed Cisco cloud registration failed
General storedFileDownloadError Unable to download the stored file's hash list.
General FDMInReadOnlyModeFMCRegistrationInProgress Registration with FMC is in progress. Configuration changes are not allowed. You can only cancel FMC registration.
General storedFileSuccess Stored SHA list file successfully generated.
General registrationFailedDueToInvalidToken The Smart License registration can not be completed because the provided token is invalid
General FMCRegistrationJobFailedAndRemoveFMCManagerFail FMC registration job and clean up failed because FMC Manager cannot be removed.
General currentlyInDeadTime Failed to authenticate user against identity source group because it is currently in dead time
General cloudServicesMessagingConnectionFailed Failed to connect to a cloud service. Check network connectivity and retry.
General cloudEnrollmentInternalError Received internal server error from cloud service. Retry after some time. If problem persists, contact Cisco TAC.
General couldNotFindFile Failed to find Lina CLI file, {0}.
General cleanUpFMCRegistrationJobRemoveFMCManagerFail Clean Up failed to remove FMC Manager.
General errorOccurredWhileProcessingRadiusClient Error occurred while processing RADIUS client
General cliCommandExecutionFailed Command execution failed.
General FMCRegistrationJobCancelledAndRemoveFMCManagerFail FMC registration job was cancelled and clean up failed because FMC Manager cannot be removed.
General classNotFound Class not found: {0}
General cannotCancelFMCRegistrationJob Cannot start cancellation on FMC Registration job within {0} milliseconds.
General failedToSyncWebUiCertificateToDevice Failed to synchronize the Web UI Certificate to the device.
General smartLicensePerformanceTierUpdateJobInProgress Performance Tier update is in progress.
General cannotCompleteCancelFMCRegistrationJob Cannot finish cancellation on FMC Registration job within {0} milliseconds.
General versionMismatch Failed to import the configuration from the active peer. The software version of the peer, {0}, does not match the software version of this unit, {1}. Please install the same software version on each peer. Then, ensure that you make the currently active peer the active peer again, and deploy the configuration from the active unit.
General failedToConnect The device was unable to connect to the Smart Licensing server. This might indicate a gateway problem for the management interface. Please select Evaluation Mode for now. Then, after completing setup, go to Device > System Settings > Management Interface and verify the management address and gateway configuration. There must be a path from the management IP address to the Internet to complete Smart License registration. You can then go to Device > Smart License and try registering again.
General cloudRegistrationDroppedConnection Cloud service dropped connection. Retry after some time.
General errorOccurredUpdatingUser Error occurred when updating user information
General FMCRegistrationJobTimedOutAndRemoveFMCManagerFail FMC registration job timed out and clean up failed because FMC Manager cannot be removed.
General ampConnectionNormal Cloud connectivity functioning normally
General HitcountDBCreateFailure Failed to initialize hit count database tables
General changePasswordFailed Current password is not correct. You must enter the correct current password to change it.
General invalidFMCRegistrationObject Valid FMCRegistrationSettings object is required for FMC registration job.
General ciscoSseUnregistrationInProgress Unenrolling the device from the cloud.
General FMCRegistrationJobSuccess FMC configuration and communication were successful.
General smartLicenseRegistrationJobFailed Smart License registration job cannot be completed.
General smartLicenseRegistrationJobInProgress Registration is in progress.
General duplicatePathsWithConflicts Duplicate resource pointing to same path without correct overriding path. Resource Mappings process is incomplete.
General failedToAuthenticateUser Failed to authenticate user
General cliCommandExecutionTimeOut Command execution timed out. Please try again.
General ltpProxyAuthFailure Failed to connect to the Cisco Cloud due to a HTTP Proxy authentication error. Check the HTTP Proxy Authentication configuration and retry.
General ltpSerialNumberNotClaimed Claim the device in Cisco Defense Orchestrator using the serial number before starting the Cloud Auto Enrollment process.
General cloudRegionCertificateNotReceived The certificate was not received from the cloud regions domain.
General storedFileFailed Error generating stored SHA list file.
General cloudRegistrationInternalError Received internal server error from cloud service. Retry after some time. If problem persists, contact Cisco TAC.
General accessDeniedDueToUserRole You do not have access to edit this feature based on your User Role.
General cloudRegistrationRefreshFailed The registration refresh with the Cisco cloud failed.
General cleaningUpAfterFailure Cleaning up after FMC registration job failed.
General invalidSessionId User session id is not valid.
General ciscoSseUnregistrationRequestWasNotFulfilled Cisco cloud deregistration request was not fulfilled by the Cisco cloud server.
General fileTypeAndCategoryBootstrapFailure Failed at File Type and Category Bootstrap step.
General cloudRegistrationRefreshConnectionUnauthorized Connection to cloud service unauthorized. Re-register with a new valid token.
General smartLicenseDeRegistrationJobFailed Smart License deregistration job cannot be completed.
General duplicateRadiusServerInGroup Radius Identity Source Group cannot contain duplicates of the same server.
General FMCRegistrationJobTimedOut FMC registration job timed out.
General invalidPassword Invalid password: A blank or masked password is not allowed.
General HPMServerUnavailable System is unable to obtain the device metrics at this moment, please try again later.
General unknownHost Unknown Host: {0}
General unableParseFile Unable to parse file
General cloudUnregistrationFailedResolveFqdn Failed to resolve cloud service FQDN. Check network connectivity or DNS configuration and retry
General couldNotResolveAuthorization Failed to resolve authorization for current user
General cloudEnrollmentConnectionUnauthorized Connection to cloud service unauthorized. Re-register with a new valid token.
General cloudRegistrationRefreshDroppedConnection Cloud service dropped connection. Retry after some time.
General failedToGenerateTokenViaSmartLicense Failed to generate token to enroll with the Cisco cloud using Smart License.
General fdmIsStillStarting FDM is performing bootstrap initialization following an install or upgrade. Use the REST api '/api/fdm/latest/jobs/bootstrap' to check status.
General smartLicenseRegistrationJobCompleteSuccessfully Smart License successfully registered.
General cloudServicesReRegistrationDeactivateFailed Failed to re-register device to cloud: Unable to un-register the device from the default tenant. Check network connectivity with cloud and retry.
General noAuthorizationFoundForUser No external authorization cisco-av-pairs were found; unable to authorize user
General deviceEnrollmentRequiredForThisOperation The device is not enrolled, but enrollment is required for this operation.
General getparamsArgumentLength Argument length less than 1
General SecurityIntelligenceFeedsUpdateSucceeded Security Intelligence feeds download succeeded.
General interfaceNeedsToBeSpecified Interface to connect to radius server "{0}" needs to be specified.
General FMCRegistrationJobCancelled FMC registration job was cancelled.
General cloudRegistrationConnectionForbidden Connection to cloud service forbidden.
General performanceTierUpdateJobCompleteSuccessfullyReleaseFailed Performance Tier updated but some licenses for previous tier are failed to release. Please re-sync connection from the Smart Licensing page
General malwareUpdateSuccess Malware signature pack is up to date.
General smartLicensePerformanceTierUpdateJobFailedResync Performance Tier update job cannot be completed. Please re-sync connection from the Smart Licensing page
General FMCRegistrationJobFailure FMC registration job failed.
General fileTypeAndCategoryNotFound File Type or Category details with Id {0} not found
General smartAgentDelegateUnsupportedConnectionType Connection type {0} is not supported.
General failedToConnectDueToDnsIssue Unable to resolve IP by {0}. Please verify that the DNS server addresses are correct.
General cloudUnregistrationDroppedConnection Cloud service dropped connection. Retry after some time.
General waitingForSmartLicenseRegistration Waiting for the device being registered via Smart License.
General cancelFMCRegistrationJobFailUnknownReason Cancellation on FMC Registration job failed with unknown reason.
General invalidFile Invalid export file.
General failedToSendTelemetryData Could not send telemetry data: the device is not enrolled or there was a connection issue.
General malwareUpdateFailed Recent malware update attempt failed.
General createInstanceError Cannot create instance of class: {0}
General cryptoFtdKeyFailure Server failed to encrypt the FTD certificate key
General ampConnectionFailure Cannot connect to cloud
General cloudRegistrationRefreshFailedResolveFqdn Failed to resolve cloud service FQDN. Check network connectivity or DNS configuration and retry.
General cloudEnrollmentConnectorInternalError Connector internal error. Check network connectivity and retry. If problem persists, contact Cisco TAC.
General userNotFound User not found
General cloudRegistrationRefreshConnectorInternalError Connector internal error. Check network connectivity and retry. If problem persists, contact Cisco TAC.
General timeout The attempt to ping {0} timed out. Please verify that the interface is connected to a gateway that can reach the internet.
General injectionDetected Invalid input data
General cloudRegistrationRefreshConnectionFailed Failed to connect to a cloud service. Check network connectivity and retry.
General cloudRegistrationRefreshInternalError Received internal server error from cloud service. Retry after some time. If problem persists, contact Cisco TAC.
General cannotFindHTTPSAAASetting You cannot connect using HTTPS due to possible database corruption. If this device is the secondary device in a high-availability pair, synchronization might have failed; please try deploying from the primary again to trigger a sync to the secondary. Otherwise, please contact Cisco TAC.
General entityNotCompatibleWithDestinationInterface Entity is not compatible with the destination interface.
General importFail Unable to import database
General failedToAuthenticateAgainstLocal Failed to authenticate user against local identity source
General deviceEnrollmentInProgress The device enrollment with the Cisco cloud in progress.
General accessDeniedConfigImportInProgress The device is importing its configuration from the peer unit. After the import completes, you might need to log in again.
General cloudServiceEnablingFailure Could not complete enrollment in {0}.
General cloudRegistrationConnectorInternalError Connector internal error. Check network connectivity and retry. If problem persists, contact Cisco TAC.
General ProcessTimedOut Process timed out. Please try again later.
General exportMixedConfig Mixed state configuration. Cannot export if deployment is not performed.
General exportFail Unable to export database
General errorGettingPermissions Error occurred when getting the access rights for the user
General rsyncFail Failed to download file {0} via rsync for database import
General unsupportedImport Unsupported import type: {0}
General HitcountDBReadFailure Failed to read from hit count database tables
General SecurityIntelligenceScheduleDisableError Exception occurred while disabling default Security Intelligence feed download schedule.
General couldNotLogoutUser Could not terminate session. Please try again.
General configSkipped Config import skipped. Please upgrade both units in the HA pair to the same version, and perform a deployment from the active unit to synchronize the configuration.
General cloudUnregistrationConnectorInternalError Connector internal error. Check network connectivity and retry. If problem persists, contact Cisco TAC.
General cloudRegistrationConnectionFailed Failed to connect to a cloud service. Check network connectivity and retry.
General cloudEnrollmentConnectionForbidden Connection to cloud service forbidden.
General conflictingAuthorizationFoundFromProvider Conflicting authorization cisco-av-pairs were received from the AAA provider this user. Unable to resolve the authorization profile for this user
General addFMCManagerFail FMC manager cannot be added.
General cloudServiceEnablingSuccess Completed enrollment in {0}.
General performanceTierUpdateJobCompleteSuccessfully Performance Tier successfully updated.
General smartLicenseRegistrationRequired Smart License registration required to enroll with a Smart Virtual Account.
General ciscoSseUnregistrationSuccessful Cisco cloud deregistration is successful.
General unauthorizedUserCustomTokenCreation Unauthorized to create custom token. Custom Token can be created by local Admin users only.
General generalErrorMessageHandlingRequest Unable to handle request
General accessDeniedImportFromCfgFileInProgress The device is importing objects from a configuration file. After the import completes, you might need to log in again.
General failedToConnect Unable to ping {0}. Please verify that the interface is connected to a gateway that can reach the internet.
General cloudServiceEnablingJobWasCreated {0} enabling job was successfully created.
General HitcountDBUpdateFailure Failed to update hit count values in database tables
General connectorDataDirectoryNotFound The system failed to find the connector data directory path.
General cannotFindHTTPSAAASettingHA The server is busy. Please try again later.
General badCredentials Bad Credentials
General resourceMappingCyclicDependency Cyclical Resource dependency is detected. Resource Mappings process is incomplete.
General deviceRegistrationContextCreationInprogress Device registration context creation in progress.
General cloudServiceEnablingInProgress Enrollment in {0} in progress.
General incorrectUploadFileExtensionError You can upload supported files (extensions .pkg, xml, json, fsp, asp, isp, nvmsp, nsp, wsp, wso) only.
General cloudServicesReRegistrationActivateFailed Failed to re-register device to cloud: Unable to register the device to cloud tenant. Check network connectivity with cloud and retry.
General accessDeniedDeploymentConfigGenerationsInProgress The device is generating deployment data. After the generation completes, you might need to log in again.
General changePasswordInvalidBlank Invalid password: A blank password is not allowed.
General unknownError An unexpected error occurred.
General ltpSudiProxySupportNotAvailable Cloud Auto Enrollment is not supported with HTTP Proxy. To use the Cloud Auto Enrollment process, disable HTTP Proxy and try again.
General unableToResolveRadiusServerIdentitySource Could not resolve RADIUS identity source address
General deviceEnrollmentInitialized The device enrollment with the Cisco cloud initialized.
General cloudUnregistrationConnectionForbidden Connection to cloud service forbidden.
General cloudServicesReRegistrationParseFailed Failed to re-register the device to cloud due to a message parsing issue. Check network connectivity with cloud and retry. If problem persists, contact Cisco TAC.
General deviceSuccessfullyEnrolledInCloud The device was successfully enrolled with the Cisco cloud in region {0}.
General registrationFail The registration could not be completed. The system will automatically try registration again.
General cloudRegistrationRefreshConnectionForbidden Connection to cloud service forbidden.
General cloudEnrollmentConnectionFqdn Failed to resolve cloud service FQDN. Check network connectivity or DNS configuration and retry.
General smartAgentAlreadyEnabled Smart Licence Agent is already enabled.
General ampConnectionBadKeys Bad keys for cloud communication
General cloudUnregistrationConnectionFailed Failed to connect to a cloud service. Check network connectivity and retry.
General cloudEnrollmentDeleteIsStarted Cloud un-enrollment has started and will be finished as a result of the corresponding job.
General ciscoSseUnregistrationFailed Cisco cloud deregistration failed.
General cloudRegionCertificatePathNotFound The system failed to find the certificate for validating the cloud regions domain.
General cancellingFMCRegistrationJob Cancelling FMC registration job.
General cloudEnrollmentNotStartedDueToFailedSmartLicense The device enrollment with the Cisco cloud was not started due to Smart License registration failure.
General AdapterLoadingFailed Failed to load the encoder/decoder {0} for the model {1}
General AdapterTemplateMappingNotFound Smart CLI Template mapping not found for the model {0}
General ltpProxyConnectFailure Failed to connect to the Cisco Cloud due to a HTTP Proxy configuration. Check the HTTP Proxy configuration and retry.
General cloudRegistrationFailedDueToInvalidToken The device enrollment with the Cisco cloud failed because of invalid token. Retry with a new valid token.
General unableToResolveSourceIP Unable to resolve source IP of the incoming HTTP request
General externalSmartLicenseDeRegistrationJobCompleteSuccessfully Smart License successfully deregistered by CSSM.
General capturedFileDoesNotExist The requested file with SHA256 does not exist. It might have been deleted.
General exportConfigFailed Failed to export intrusion config.
General cloudRegionInvalidCertificate The certificate for the cloud regions domain is invalid.
General cloudServiceWasNotFoundInDatabase CloudService object {0} was not found in the database.
General ltpInvalidSudiSseRequest Registration request to Cisco Cloud failed due to invalid request from platform. Please retry and if the problem persists, contact Cisco TAC.
General SecurityIntelligenceFeedsUpdateFailed Security Intelligence feeds download failed.
General invalidDynamicAuthorizationPort Dynamic authorization port must be between 1024 and 65535
General SecurityIntelligenceFeedsUpdateInProgress Security Intelligence feeds is in progress.
General tokenExpiredUnAuthorizedAccess The access token has expired. You are no longer authorized. Please refresh the token or authenticate again.
General cloudEnrollmentConnectionFailed Failed to connect to a cloud service. Check network connectivity and retry.
General smartLicensePerformanceTierUpdateJobFailed Performance Tier update job cannot be completed.
General instanceExist An object of this type already exists. You have only one object of this type.
General timedOutConnectingToRadiusIdentitySource Timed out connecting to RADIUS identity source
General deviceFailedToEnrollInCloudService The device enrollment with the Cisco cloud failed.
General cannotFindAAASetting Unable to authenticate, please contact your system administrator.
General userRoleInvalid The user role is invalid. Please specify a valid user role.
General smartLicenseDeRegistrationNeslaFailure Failed to deregister Smart License in Cisco Smart Software Manager (CSSM). The device is now in an unregistered state, but you need to go to CSSM and deregister the device manually to complete the process.
General testConnectionSucceeded The connection test succeeded
General deviceContextActivationFailed Could not activate context. Please try again.
General ltpSudiBadRequestFailure Failed to connect to the Cisco Cloud due to a bad request from the platform. Please reboot and try again. If the problem persists, contact Cisco TAC.
General cloudUnregistrationConnectionUnauthorized Connection to cloud service unauthorized. Re-register with a new valid token.
General sseConfigurationNotFound Configuration for SSE has not been found.
General performanceTierUpdateFailedDueReboot Performance Tier update job has failed as a result of a reboot, please try again.
General ltpSudiToolException Exception occurred when connecting to cloud. Please retry and if the problem persists, contact Cisco TAC.
General exportDeploymentOngoing Deployment in progress. Cannot export: {0}.
General cloudRegistrationFailedResolveFqdn Failed to resolve cloud service FQDN. Check network connectivity or DNS configuration and retry.