Firepower Threat Defense API v6.2 (FTD v7.2)
Latest
- Overview
- Error Codes
- Resources
- Model Index
- AAASetting
- ASPathList
- AccessPolicy
- ActiveDirectoryRealm
- ActiveUserSessions
- AnyConnectClientProfile
- AnyConnectPackageFile
- ApiVersions
- Application
- ArchivedBackup
- AuditEntityChange
- AuditEvent
- BGP
- BGPGeneralSettings
- BackupImmediate
- BackupScheduled
- BreakHAStatus
- CertFileUploadStatus
- Certificate
- addExternalCACertificate
- addExternalCACertificateGroup
- addExternalCertificate
- addInternalCACertificate
- addInternalCertificate
- deleteExternalCACertificate
- deleteExternalCACertificateGroup
- deleteExternalCertificate
- deleteInternalCACertificate
- deleteInternalCertificate
- editExternalCACertificate
- editExternalCACertificateGroup
- editExternalCertificate
- editInternalCACertificate
- editInternalCertificate
- getExternalCACertificate
- getExternalCACertificateGroup
- getExternalCACertificateGroupList
- getExternalCACertificateList
- getExternalCertificate
- getExternalCertificateList
- getInternalCACertificate
- getInternalCACertificateList
- getInternalCertificate
- getInternalCertificateList
- CliDeploymentError
- CloudConfig
- CloudServices
- addCloudEnrollmentImmediate
- addCloudManagement
- addCloudUnenrollmentImmediate
- deleteCloudManagement
- editCloudCommunicationSettings
- editCloudEvents
- editCloudManagement
- editDefenseOrchestrator
- editSuccessNetwork
- getCloudCommunicationSettings
- getCloudCommunicationSettingsList
- getCloudEvents
- getCloudEventsList
- getCloudManagement
- getCloudManagementList
- getCloudRegion
- getCloudRegionList
- getCloudServicesInfo
- getDefenseOrchestrator
- getDefenseOrchestratorList
- getSuccessNetwork
- getSuccessNetworkList
- Command
- CommandAutoComplete
- ConfigIssue
- ConfigurationImportExport
- addScheduleConfigExport
- addScheduleConfigImport
- deleteConfigExportJobStatus
- deleteConfigImportExportFileInfo
- deleteConfigImportJobStatus
- downloadConfigFile
- getConfigExportJobStatus
- getConfigExportJobStatusList
- getConfigImportExportFileInfo
- getConfigImportExportFileInfoList
- getConfigImportJobStatus
- getConfigImportJobStatusList
- getScheduleConfigExportList
- getScheduleConfigImportList
- postuploadconfigfile
- ConnectTest
- Continent
- Country
- CustomLoggingList
- DAPXml
- DDNSService
- DHCPRelayService
- DHCPServerContainer
- DNS
- DataInterfaceManagementAccess
- Deployment
- DeploymentData
- DeviceHostname
- DeviceLogSettings
- DeviceMetrics
- addAwsCloudWatch
- addAzureApplicationInsights
- addDeviceMetricsIntegrations
- deleteAwsCloudWatch
- deleteAzureApplicationInsights
- deleteDeviceMetricsIntegrations
- editAwsCloudWatch
- editAzureApplicationInsights
- editDeviceMetricsIntegrations
- getAwsCloudWatch
- getAwsCloudWatchList
- getAzureApplicationInsights
- getAzureApplicationInsightsList
- getDeviceMetricData
- getDeviceMetricDataList
- getDeviceMetricNode
- getDeviceMetricNodeList
- getDeviceMetricsIntegrations
- getDeviceMetricsIntegrationsList
- DeviceMonitoring
- Download
- DuoLDAPIdentitySource
- ECMPZone
- EIGRP
- ExpandedCommunityList
- ExportConfigJobHistory
- ExtendedAccessList
- ExternalBrowserPackage
- FACRegistration
- FMCRegistration
- FeatureCapabilities
- FeatureInformation
- FileAndMalwarePolicy
- addFilePolicy
- addFileRule
- addScheduleStoredFileSHAList
- deleteCleanList
- deleteCustomDetectionList
- deleteFilePolicy
- deleteFileRule
- editAmpCloudConfig
- editAMPCloudConnection
- editFilePolicy
- editFilePolicyConfiguration
- editFileRule
- getAmpCloudConfig
- getAmpCloudConfigList
- getAMPCloudConnection
- getAMPCloudConnectionList
- getAMPCloudConnectionStatusList
- getAMPServer
- getAMPServerList
- getCleanList
- getCleanListList
- getCustomDetectionList
- getCustomDetectionListList
- getdownloadcleanhashlist
- getdownloadcustomdetectionhashlist
- getdownloadstoredfiles
- getdownloadstoredfileshalist
- getFilePolicy
- getFilePolicyConfiguration
- getFilePolicyConfigurationList
- getFilePolicyList
- getFileRule
- getFileRuleList
- getFileType
- getFileTypeCategory
- getFileTypeCategoryList
- getFileTypeList
- getMalwareUpdateConnectionStatusList
- getScheduleStoredFileSHAListJobHistoryList
- getScheduleStoredFileSHAListList
- postuploadcleanhashlist
- postuploadcustomdetectionhashlist
- FlexConfigObject
- FlexConfigPolicy
- GeoLocation
- GeoLocationFileUpload
- GeolocationUpdateImmediate
- GeolocationUpdateSchedule
- HAAction
- HAConfiguration
- HAFailoverConfiguration
- HAStatus
- HTTPAccessList
- HTTPProxy
- HardwareBypass
- HitCount
- HostScanPackageFile
- IPV4PrefixList
- IPV6PrefixList
- IdentityPolicy
- IdentityServicesEngine
- IkevOnePolicy
- IkevOneProposal
- IkevTwoPolicy
- IkevTwoProposal
- InitialProvision
- Interface
- addBridgeGroupInterface
- addEtherChannelInterface
- addEtherChannelSubInterface
- addInterfaceMigrationImmediate
- addSubInterface
- addVlanInterface
- breakoutinterface
- deleteBridgeGroupInterface
- deleteEtherChannelInterface
- deleteEtherChannelSubInterface
- deleteJobHistoryInterfaceMigration
- deleteSubInterface
- deleteVlanInterface
- editBridgeGroupInterface
- editEtherChannelInterface
- editEtherChannelSubInterface
- editNetworkInterfaceModule
- editPhysicalInterface
- editSubInterface
- editVlanInterface
- getBridgeGroupInterface
- getBridgeGroupInterfaceList
- getEtherChannelInterface
- getEtherChannelInterfaceList
- getEtherChannelSubInterface
- getEtherChannelSubInterfaceList
- getInterfaceData
- getInterfaceDataList
- getInterfaceMigrationImmediateList
- getJobHistoryInterfaceMigration
- getJobHistoryInterfaceMigrationList
- getNetworkInterfaceModule
- getNetworkInterfaceModuleDataList
- getNetworkInterfaceModuleList
- getPhysicalInterface
- getPhysicalInterfaceList
- getSubInterface
- getSubInterfaceList
- getVlanInterface
- getVlanInterfaceList
- joininterface
- InterfaceInfo
- InterfacePresenceChange
- IntrusionPolicy
- addIntrusionGroupRuleUpdate
- addIntrusionPolicy
- addToggleInspectionEngine
- createIntrusionRule
- createIntrusionRuleGroup
- deleteIntrusionPolicy
- deleteIntrusionRule
- deleteIntrusionRuleGroup
- deleteJobHistoryCustomRulesFileImport
- editIntrusionPolicy
- editIntrusionPolicyRuleUpdate
- editIntrusionRule
- editIntrusionRuleGroup
- editIntrusionSettings
- editPolicyIntrusionRule
- editPolicyIntrusionRuleGroup
- getcustomrulesfileimport
- getdownloadcustomrulesfileimporterror
- getIntrusionPolicy
- getIntrusionPolicyList
- getIntrusionRule
- getIntrusionRuleGroup
- getIntrusionRuleGroupList
- getIntrusionRuleList
- getIntrusionSettings
- getIntrusionSettingsList
- getJobHistoryCustomRulesFileImport
- getJobHistoryCustomRulesFileImportList
- getPolicyIntrusionRule
- getPolicyIntrusionRuleGroup
- getPolicyIntrusionRuleGroupList
- getPolicyIntrusionRuleList
- postcustomrulesfileimport
- Job
- deleteJobHistoryBackup
- deleteJobHistoryCloudManagement
- deleteJobHistoryDeployment
- deleteJobHistoryEntities
- deleteJobHistoryEntity
- deleteJobHistoryGeolocation
- deleteJobHistoryHaConfigSync
- deleteJobHistorySruUpdate
- deleteJobHistoryVDBUpdate
- deleteLicenseJobHistory
- getBootstrapJobHistory
- getBootstrapJobHistoryList
- getJobHistoryBackup
- getJobHistoryBackupList
- getJobHistoryCloudManagement
- getJobHistoryCloudManagementList
- getJobHistoryDeployment
- getJobHistoryDeploymentList
- getJobHistoryEntity
- getJobHistoryEntityList
- getJobHistoryGeolocation
- getJobHistoryGeolocationList
- getJobHistoryHaConfigSync
- getJobHistoryHaConfigSyncList
- getJobHistorySruUpdate
- getJobHistorySruUpdateList
- getJobHistoryVDBUpdate
- getJobHistoryVDBUpdateList
- getLicenseJobHistory
- getLicenseJobHistoryList
- JobHistoryUpgradeReadiness
- JoinHAStatus
- LdapAttributeMap
- ManagementIP
- NAT
- NTP
- NTPStatus
- NetworkAnalysisPolicy
- NetworkObject
- OSPF
- OSPFInterfaceSettings
- PTP
- PendingChanges
- PolicyList
- PortObject
- addICMPv4PortObject
- addICMPv6PortObject
- addPortObjectGroup
- addProtocolObject
- addTCPPortObject
- addUDPPortObject
- deleteICMPv4PortObject
- deleteICMPv6PortObject
- deletePortObjectGroup
- deleteProtocolObject
- deleteTCPPortObject
- deleteUDPPortObject
- editICMPv4PortObject
- editICMPv6PortObject
- editPortObjectGroup
- editProtocolObject
- editTCPPortObject
- editUDPPortObject
- getICMPv4PortObject
- getICMPv4PortObjectList
- getICMPv6PortObject
- getICMPv6PortObjectList
- getPortObjectGroup
- getPortObjectGroupList
- getProtocolObject
- getProtocolObjectList
- getTCPPortObject
- getTCPPortObjectList
- getUDPPortObject
- getUDPPortObjectList
- PostUpgradeFlags
- PullFile
- PullFileJob
- PullUpgradeImmediate
- PullUpgradeJob
- RaVpn
- RaVpnConnectionProfile
- RaVpnGroupPolicy
- RadiusIdentitySource
- RadiusIdentitySourceGroup
- RealmSequence
- RestoreImmediate
- RolePermission
- RouteMap
- Routing
- SAMLServer
- SGTDynamicObject
- SLAMonitor
- SNMP
- SRUFileUpload
- SRUUpdateImmediate
- SRUUpdateSchedule
- SSHAccessList
- SSLCipher
- SSLPolicy
- SToSConnectionProfile
- ScheduleExportConfig
- ScheduleTroubleshoot
- Secret
- SecurityGroupTag
- SecurityIntelligence
- addDomainNameFeed
- addSecurityIntelligenceUpdateFeedsImmediate
- addSecurityIntelligenceUpdateFeedsSchedule
- deleteDomainNameFeed
- deleteSecurityIntelligenceUpdateFeedsImmediate
- deleteSecurityIntelligenceUpdateFeedsSchedule
- editDomainNameFeed
- editDomainNameGroup
- editSecurityIntelligenceDNSPolicy
- editSecurityIntelligenceNetworkPolicy
- editSecurityIntelligencePolicy
- editSecurityIntelligenceUpdateFeedsImmediate
- editSecurityIntelligenceUpdateFeedsSchedule
- editSecurityIntelligenceURLPolicy
- editSystemFeedObject
- getDomainNameFeed
- getDomainNameFeedCategory
- getDomainNameFeedCategoryList
- getDomainNameFeedList
- getDomainNameGroup
- getDomainNameGroupList
- getNetworkFeedCategory
- getNetworkFeedCategoryList
- getSecurityIntelligenceDNSPolicy
- getSecurityIntelligenceDNSPolicyList
- getSecurityIntelligenceNetworkPolicy
- getSecurityIntelligenceNetworkPolicyList
- getSecurityIntelligencePolicy
- getSecurityIntelligencePolicyList
- getSecurityIntelligenceUpdateFeedsImmediate
- getSecurityIntelligenceUpdateFeedsImmediateList
- getSecurityIntelligenceUpdateFeedsSchedule
- getSecurityIntelligenceUpdateFeedsScheduleList
- getSecurityIntelligenceURLPolicy
- getSecurityIntelligenceURLPolicyList
- getSystemFeedObject
- getSystemFeedObjectList
- getURLFeedCategory
- getURLFeedCategoryList
- SecurityZone
- SmartLicensing
- addLicense
- addPLRAuthorizationCode
- addPLRReleaseCode
- addSmartAgentConnection
- addSmartAgentSyncRequest
- deleteLicense
- deleteSmartAgentConnection
- editSmartAgentConnection
- getLicense
- getLicenseList
- getLicenseReservationList
- getPerformanceTier
- getPerformanceTierList
- getPLRRequestCode
- getPLRRequestCodeList
- getSmartAgentConnection
- getSmartAgentConnectionList
- getSmartAgentStatus
- getSmartAgentStatusList
- SpecialRealm
- StandardAccessList
- StandardCommunityList
- SyslogServer
- SystemInformation
- Telemetry
- TestDirectory
- TestIdentityServicesEngineConnectivity
- TestIdentitySource
- TimeRange
- TimeZoneObjects
- TimeZoneSettings
- TimeZones
- Token
- TrafficInterruptionReasons
- TrafficUser
- TrafficUserGroup
- TroubleshootJobHistory
- URLCategory
- URLObject
- URLReputation
- Upgrade
- UpgradeFile
- UpgradeReadinessCheck
- UpgradeReadinessCheckStatus
- Upload
- UrlCategoryInfo
- User
- VDBFileUpload
- VDBUpdateImmediate
- VDBUpdateSchedule
- VirtualTunnelInterface
- WebAnalyticsSetting
- WebUICertificate
- Models
- Model Index for FTD 7.2.0
- AAASetting
- AccessControlRuleDeployInfo
- AccessDefaultAction
- AccessEntryBase
- AccessPolicy
- AccessPolicyDeployInfo
- AccessRule
- AccessRuleInfo
- AccessSwitchPortConfig
- ActiveDirectoryRealm
- ActiveUserSessions
- AdministrativeDistance
- AdvancedOptions
- AdvancedSettings
- AFAggregateAddress
- AFAggregateAddressIPv4
- AFAggregateAddressIPv6
- AFBase
- AFBGPDistance
- AFInjectMap
- AFIPv4
- AFIPv4Network
- AFIPv6
- AFIPv6Network
- AFMaximumPaths
- AFNetworkBase
- AFTableMap
- AmpCloudConfig
- AMPCloudConnection
- AMPCloudConnectionStatus
- AmpConnectionStatesDeviceMetricValue
- AMPServer
- AmpThreatGridConnectionStatesDeviceMetricValue
- AnyConnectClientProfile
- AnyConnectGroupPolicy
- AnyConnectPackageFile
- AnyConnectPackages
- AnyConnectProfile
- AnyConnectVpnConnection
- AnyConnectVpnConnectionUncompressedModel
- ApiVersions
- Application
- ApplicationCategory
- ApplicationFilter
- ApplicationFilterCondition
- ApplicationTag
- ArchivedBackup
- Area
- AreaNetwork
- AreaRange
- AreaType
- ASPathEntry
- ASPathList
- AuditCustomFeedUpdateData
- AuditCustomFeedUpdateEvent
- AuditCustomRulesFileImportSummaryData
- AuditCustomRulesFileImportSummaryEvent
- AuditDeploymentData
- AuditDeploymentEvent
- AuditDiscardPendingChangesEvent
- AuditEntityChange
- AuditEntityCreateEvent
- AuditEntityDeleteEvent
- AuditEntityUpdateEvent
- AuditEvent
- AuditFailedLoginEvent
- AuditHAActionData
- AuditHaActionEvent
- AuditHAConfigSyncData
- AuditHAConfigSyncEvent
- AuditInterfacePresenceChangeEvent
- AuditJobExecutionData
- AuditJobExecutionEvent
- AuditLoginEvent
- AuditLogoutEvent
- AuditOutOfBandChangeEvent
- AuditRulesUpdateData
- AuditRulesUpdateEvent
- AuthenticationBase
- AwsCloudWatch
- AzureApplicationInsights
- BackupFile
- BackupImmediate
- BackupPeer
- BackupScheduled
- BaseDiff
- BaseEntityDiff
- BGP
- BGPBestPath
- BGPGeneralSettings
- BGPGracefulRestart
- BGPTimers
- BootstrapEvent
- BootstrapImmediate
- BootstrapJobHistory
- BreakHAStatus
- BreakoutInterface
- BridgeGroupInterface
- BridgeGroupInterfaceIdInfo
- BufferedLogging
- CancelUpgrade
- CapturedFile
- CertFileUploadStatus
- CertificateStatus
- CertificateUserNameSettings
- ChangePasswordStatus
- ChassisStatsStatusDeviceMetricValue
- CleanList
- CliDeploymentError
- Clipboard
- CloudCommunicationSettings
- CloudConfig
- CloudEnrollment
- CloudEnrollmentImmediate
- CloudEnrollmentJobHistory
- CloudEvents
- CloudManagement
- CloudRegion
- CloudServicesInfo
- CloudUnenrollmentImmediate
- CloudUnenrollmentJobHistory
- Command
- CommandAutoComplete
- CommunityEntryBase
- ConfigExportJobStatus
- ConfigImportExportFileInfo
- ConfigImportJobStatus
- ConfigIssue
- ConfigIssueMessage
- ConnectivitySetting
- ConnectTest
- ConsoleLogFilter
- Continent
- Country
- CriticalProcessStatusDeviceMetricValue
- CustomDetectionList
- CustomLoggingList
- CustomLoggingListLogLevel
- CustomLoggingListMessage
- CustomRulesFileImportImmediate
- DapAuthorizationAttributes
- DAPXml
- DatabaseInfo
- DataDNSSettings
- DataInterfaceHttpsPort
- DataInterfaceManagementAccess
- DataSSLCipherSetting
- DataSyslogServerLogging
- DayLightSavingDateRange
- DayLightSavingDayRecurrence
- DDNSInterfaceSettings
- DDNSService
- DefaultIdentityRule
- DefaultInformationOriginate
- DefenseOrchestrator
- DefenseOrchestratorEnablingImmediate
- DefenseOrchestratorEnablingJobHistory
- DependentEntity
- DeployedConfigChecksum
- DeploymentData
- DeploymentImmediate
- DeploymentInfo
- DeploymentSchedule
- DeploymentStatus
- DeploymentStatusMessage
- Device
- DeviceDNSSettings
- DeviceHostname
- DeviceLogFilterBase
- DeviceLogSettings
- DeviceMetricContainer
- DeviceMetricData
- DeviceMetricNode
- DeviceMetricsIntegrations
- DeviceMetricValue
- DHCPRelayAgent
- DHCPRelayServer
- DHCPRelayService
- DHCPServer
- DHCPServerContainer
- DirectoryConfiguration
- DirectoryUserDownloadImmediate
- DirectoryUserImportImmediate
- DiskFileObject
- DiskUsage
- DistinguishedName
- DistinguishedNameGroup
- DistributeList
- DNSRule
- DNSServer
- DNSServerGroup
- DomainNameFeed
- DomainNameFeedCategory
- DomainNameGroup
- DuoLDAPIdentitySource
- EasySetupBase
- EasySetupStatus
- ECMPZone
- EIGRP
- EigrpActiveInterfaces
- EigrpAdministrativeDistance
- EigrpDistributeList
- EigrpIncomingRouteFilter
- EigrpNeighbor
- EigrpOutgoingRouteFilter
- EigrpPassiveInterfaces
- EigrpProcessConfiguration
- EigrpRedistrbuteBGP
- EigrpRedistrbuteConnected
- EigrpRedistributeISIS
- EigrpRedistributeOSPF
- EigrpRedistributeProtocol
- EigrpRedistributeRIP
- EigrpRedistributeStatic
- EigrpRouteMetric
- EigrpRoutingInterfaces
- EigrpStubOptions
- EigrpStubOthers
- EigrpStubReceiveOnly
- EmbeddedAppFilter
- EmbeddedAppFilterBase
- EmbeddedURLFilter
- EntityCreate
- EntityDelete
- EntityDiffAnalyserResult
- EntityUpdate
- EpsReportItem
- ErrorResponse
- EtherChannelInterface
- ExpandedCommunityEntry
- ExpandedCommunityList
- ExportConfigFile
- ExportConfigJobHistory
- ExtendedAccessEntry
- ExtendedAccessList
- ExternalBrowserPackage
- ExternalCACertificate
- ExternalCACertificateGroup
- ExternalCertificate
- FeatureCapabilities
- FeatureCapabilities$Feature
- FeatureCapabilitiesResource
- FeatureInformation
- FeatureInformation$Feature
- FileChunkContent
- FileChunksInfo
- FileEntity
- FileList
- FileMalwareSyslogServerLogging
- FilePolicy
- FilePolicyConfiguration
- FilePolicySnortRestartCounter
- FileRule
- FileType
- FileTypeCategory
- FileUploadStatus
- FirepowerAnalyticsCenter
- FirepowerAnalyticsServer
- FlexConfigObject
- FlexConfigPolicy
- FlexVariable
- FlowBit
- FlowBitRuleRelation
- FMCRegistrationImmediate
- FMCRegistrationSettings
- FQDNId
- GeoLocation
- GeoLocationFileUpload
- GeolocationUpdateImmediate
- GeoLocationUpdateManual
- GeolocationUpdateSchedule
- GeolocationVersion
- GlobalTimeZone
- HaBreakCleanupImmediate
- HaConfigSyncImmediate
- HAConfiguration
- HAFailoverConfiguration
- HAIPv4Address
- HAIPv6Address
- HAJoinStatus
- HardwareBypass
- HaResumeImmediate
- HAStatus
- HitCount
- HostScanPackageFile
- HotFixInfo
- HTTPAccessList
- HTTPProxy
- ICMPv4PortObject
- ICMPv6PortObject
- IdEntity
- IdentityPolicy
- IdentityRule
- IdentityServicesEngine
- IdentitySourceBase
- IkePolicyBase$CliTokenIf
- IkevOnePolicy
- IkevOneProposal
- IkevTwoPolicy
- IkevTwoProposal
- IncomingRouteFilter
- InetAddressBase
- InitialProvision
- InspectorConfig
- InspectorOverrideConfig
- InstallUpgrade
- InterfaceData
- InterfaceInfo
- InterfaceInfoEntry
- InterfaceIPv4
- InterfaceIPv6
- InterfaceMigrationImmediate
- InterfacePresenceChange
- InterfaceStatusDeviceMetricValue
- InterfaceUsages
- InternalCACertificate
- InternalCertificate
- IntrusionGroupRuleUpdate
- IntrusionPolicy
- IntrusionPolicyRuleUpdate
- IntrusionRule
- IntrusionRuleConfig
- IntrusionRuleGroup
- IntrusionRuleGroupConfig
- IntrusionRuleInfo
- IntrusionRuleMetaData
- IntrusionRuleRelation
- IntrusionRuleUuidInfo
- IntrusionSettings
- IpIcmpEcho
- IPPrefixEntry
- IPSRuleClassification
- IPSVariableNetworkGroup
- IPSVariablePortGroup
- IPv4Address
- IPV4PrefixList
- IPV4PrefixListFilter
- IPv6Address
- IPv6Prefix
- IPV6PrefixList
- IPV6PrefixListFilter
- ISEObject
- ISESession
- JobHistoryBackup
- JobHistoryCloudManagement
- JobHistoryCustomRulesFileImport
- JobHistoryCustomRulesFileImport$RuleImportSummaryEntry
- JobHistoryDeployment
- JobHistoryDirectoryUserDownload
- JobHistoryDirectoryUserImport
- JobHistoryEntity
- JobHistoryFMCRegistration
- JobHistoryGeolocation
- JobHistoryHaBreakCleanup
- JobHistoryHaConfigSync
- JobHistoryHaResume
- JobHistoryInterfaceMigration
- JobHistoryRestore
- JobHistorySecurityIntelligenceFeedDownload
- JobHistorySruUpdate
- JobHistoryUpgrade
- JobHistoryUpgradeReadiness
- JobHistoryVDBUpdate
- JobLinks
- JoinHAStatus
- JoinInterface
- LdapAttributeMap
- LdapAttributeMapping
- LdapAttributeToGroupPolicyMapping
- LDAPRealm
- LdapToCiscoValueMapping
- LdapToGroupPolicyValueMapping
- License
- LicenseDeregistrationJobHistory
- LicenseJobHistory
- LicenseRegistrationJobHistory
- LicenseReservation
- Links
- LinksReference
- ListAttributeCapability
- LocalIdentitySource
- LogAdjacencyChanges
- LsaThrottleTimer
- MalwareUpdateConnectionStatus
- ManagementIP
- ManualNatRule
- ManualNatRuleContainer
- ManualNatRuleContainerDeployInfo
- MapUpdate
- MD5Authentication
- MetricSettings
- ModelClassDependency
- NapLinks
- NapSchema
- Neighbor
- NeighborAdvanced
- NeighborAdvertiseMap
- NeighborBase
- NeighborDefaultOriginate
- NeighborDistributeList
- NeighborEBGPMultiHop
- NeighborFallOverBFD
- NeighborFilterList
- NeighborGeneral
- NeighborHAMode
- NeighborHops
- NeighborIPv4
- NeighborIPv6
- NeighborLocalAs
- NeighborMaximumPrefix
- NeighborRouteMap
- NeighborRoutes
- NeighborTimers
- NeighborTransportPathMTUDiscovery
- NeighborTTLSecurityHop
- NestedAttributeCapability
- NestedEntity
- NetworkAnalysisPolicy
- NetworkFeed
- NetworkFeedCategory
- NetworkInterfaceModule
- NetworkInterfaceModuleData
- NetworkObject
- NetworkObjectGroup
- NGFWErrorMessage
- NsfGracefulRestart
- Nssa
- NTP
- NTPStatus
- NumericDeviceMetricValue
- OAuthTokenInfo
- OAuthTokenInfo$TokenInfoEntry
- ObjectNatRule
- ObjectNatRuleContainer
- ObjectUsages
- OpenAPISchema
- OpenAPIServerObject
- OpenSSLCipherInfo
- OSPF
- OSPFDeadIntervalMechanism
- OSPFHelloMultiplierMechanism
- OSPFInterfaceSettings
- OSPFLostNeighborDetectionMechanism
- OSPFProtocolConfiguration
- OutgoingRouteFilter
- Paging
- PasswordAuthentication
- PatOptions
- PercentUsageReportItem
- PerformanceTier
- PerformanceTierUpdateImmediate
- PerformanceTierUpdateJobHistory
- Permission
- PhysicalInterface
- PlatformApplicabilityAttributeCapability
- PlatformApplicabilityAttributeCapability$CapabilityValue
- PLRAuthorizationCode
- PLRCode
- PLRReleaseCode
- PLRRequestCode
- PolicyList
- PolicyRuleIdInfo
- PolicyRuleIdMapDbCache
- PortObjectGroup
- PostUpgradeFlags
- PowerOverEthernet
- PPPOverEthernet
- PrefixFilter
- PrefixListFilter
- ProcessConfiguration
- ProductivityCondition
- ProtocolObject
- PTP
- PullFile
- PullFileJob
- PullUpgradeImmediate
- PullUpgradeJob
- RadiusIdentitySource
- RadiusIdentitySourceGroup
- RangeAttributeCapability
- RangeAttributeCapability$CapabilityValue
- RaVpn
- RaVpnConnectionProfile
- RaVpnGroupPolicy
- RBACResource
- RBACResourceGroup
- RealmIdInfo
- RealmSequence
- Recurrence
- RedistributeBGP
- RedistributeConnected
- RedistributeEIGRP
- RedistributeISIS
- RedistributeISISIPv6
- RedistributeOSPF
- RedistributeOSPFv3
- RedistributeProtocol
- RedistributeRIP
- RedistributeStatic
- ReferenceModel
- ReferenceUpdate
- ReportItem
- ReportItemAttribute
- ResourcePermission
- ResponseStatus
- RestoreImmediate
- RetryUpgrade
- RevertUpgrade
- RiskCondition
- RolePermission
- RouteMap
- RouteMapEntry
- RouteMetric
- RuleImportMeta
- SAMLServer
- ScheduleConfigExport
- ScheduleConfigImport
- ScheduleExportConfig
- ScheduleStoredFileSHAList
- ScheduleStoredFileSHAListJobHistory
- ScheduleTroubleshoot
- SearchCondition
- SecondaryAuthenticationSettings
- Secret
- SecurityGroupTag
- SecurityGroupTagEntry
- SecurityIntelligenceDNSPolicy
- SecurityIntelligenceFeedsInfo
- SecurityIntelligenceNetworkPolicy
- SecurityIntelligencePolicy
- SecurityIntelligenceUpdateFeedsImmediate
- SecurityIntelligenceUpdateFeedsSchedule
- SecurityIntelligenceURLPolicy
- SecurityZone
- SerializationKey
- SerialNumber
- ServerHostAndPort
- SGTDynamicObject
- SHAList
- SignatureAlgorithm
- SLAMonitor
- SLAMonitorStatus
- SLAOperation
- SmartAgentConnection
- SmartAgentStatus
- SmartAgentSyncRequest
- SNMPHost
- SNMPSecurityConfiguration
- SNMPServer
- SNMPUser
- SNMPUserGroup
- SNMPv1SecurityConfiguration
- SNMPv2cSecurityConfiguration
- SNMPv3SecurityConfiguration
- SnortVersion
- SpecialRealm
- SpfThrottleTimer
- SQLiteBackedIntrusionGroup
- SQLiteBackedIntrusionRule
- SRUFileUpload
- SRUIntrusionPolicy
- SRUUpdateImmediate
- SRUUpdateManual
- SRUUpdateSchedule
- SRUVersion
- SseConnectorStatesDeviceMetricValue
- SSHAccessList
- SSLCipher
- SSLPolicy
- SSLPolicyDefaultAction
- SSLRule
- SSLUndecryptableActions
- StandardAccessEntry
- StandardAccessList
- StandardCommunityEntry
- StandardCommunityList
- StaticRouteEntry
- StaticRouteEntryContainer
- StoredSHAListFile
- SToSConnectionProfile
- Stub
- SubInterface
- SuccessNetwork
- SuccessNetworkEnablingImmediate
- SuccessNetworkEnablingJobHistory
- SummaryAddress
- SwitchConfiguration
- SwitchPortConfig
- SwitchPortSecurity
- SwitchPortStaticMacAddress
- SyncedObject
- SyslogServer
- SyslogServerLogFilter
- SystemFeedObject
- SystemInformation
- TargetLinks
- TCPPortObject
- Telemetry
- TelemetryJobHistory
- TelemetrySchedule
- TenantState
- TestDirectory
- TestIdentityServicesEngineConnectivity
- TestIdentitySource
- ThroughputReportItem
- Time
- TimeRangeObject
- Timers
- TimeZoneObject
- TimeZones
- TimeZoneSetting
- ToggleInspectionEngine
- TokenPayloadUnion
- TokenResponseUnion
- TokenStatus
- TrafficEntry
- TrafficGroupEntry
- TrafficInterruptionReasons
- TrafficUser
- TrafficUserBase
- TrafficUserEntry
- TrafficUserGroup
- TrendingReport
- TroubleshootFile
- TroubleshootJobHistory
- TrunkSwitchPortConfig
- TSAgentSession
- TunnelPolicy
- TunnelPolicyDeployInfo
- TunnelRule
- TunnelZone
- TypeCondition
- UDPPortObject
- UpgradeFile
- UpgradeReadinessCheck
- UpgradeReadinessCheckStatus
- UpgradeReadinessStatusDetailedFailureMessage
- UpgradeRevertInfo
- UpgradeStatus
- UpgradeStatusCumulativeMessage
- UpgradeStatusMessage
- UploadBackupStatus
- URLCategory
- UrlCategoryInfo
- URLCategoryMatcher
- URLFeed
- URLFeedCategory
- UrlHandlerPair
- URLObject
- URLObjectGroup
- URLReputation
- User
- UserBase
- UserPreferences
- UserRole
- UserSession
- ValueAdd
- ValueAttributeCapability
- ValueDelete
- ValueUpdate
- VariableBase
- VDBFileUpload
- VDBUpdateImmediate
- VDBUpdateManual
- VDBUpdateSchedule
- VDBVersion
- VirtualLink
- VirtualRouter
- VirtualTunnelInterface
- VlanInterface
- VlanTag
- VlanTagGroup
- VpnGatewaySettings
- VPNSession
- WebAnalyticsSetting
- WebUICertificate
Category | Code | Message | ||||||
---|---|---|---|---|---|---|---|---|
Validation | unableToDeletePLRReservation | Unable to remove the Permanent Licensing reservation. In order to remove PLR, Permanent Licensing deregistration must be in-progress. | ||||||
Validation | specifyFqdnRedirectHostname | You must specify an FQDN network object for Redirect to Hostname. | ||||||
Validation | pppoeNotSupportedOnHANode | PPPoE is not supported on a node in HA mode. | ||||||
Validation | keyTypeEmpty | Certificate encryption type is empty. You must specify a type. | ||||||
Validation | linaAAAServerTestConnectionInternalError | Internal error occured while testing aaa-server connection with data-plane. Please check backend logs. | ||||||
Validation | contextCreationFailed | Could not create device registration context. Please try again later. | ||||||
Validation | invalidUserRoleName | The user role name was not provided in the request or the name is invalid. | ||||||
Validation | missingFilterProcessor | Query processing failed due to a missing filter processor for class : "{0}" | ||||||
Validation | ipv4OrIpv6Required | You must select either an Ipv4 or Ipv6 network. | ||||||
Validation | appFilterInvalidNumericValueHigh | The numeric input for {0} is too high. The maximum value {1}. | ||||||
Validation | vtiCannotBeAddedToBridgeGroupInterface | A Virtual Tunnel interface cannot be used in BGI | ||||||
Validation | missingValidator | Validation failed due to a missing validator: "{0}" | ||||||
Validation | externalBrowserPackageMustBeUsedWithSamlAuthentication | You can use an external browser package only if you configure SAML authentication to use the default OS browser. | ||||||
Validation | invalidInput | Validation failed. Invalid input: "{0}" | ||||||
Validation | invalidOspfInterfaceConflictingMechanism | Conflicting lost neighbor detection mechanism. Either hello-multiplier or dead-interval and hello-interval must be used but not both | ||||||
Validation | ipsecExcessIkev1Policies | The maximum number of IKEv1 policies enabled has already been reached ({0}) | ||||||
Validation | selfSignedInvalidEndDateFormat | The self-signed certificate validity end date format is incorrect. The correct format is MMM dd HH:mm:ss yyyy z. | ||||||
Validation | objectNatSubnetNotAllowedInDynamicRuleTransNet | The dynamic auto NAT rule cannot have subnet objects for the translated address: {0} | ||||||
Validation | RaVpnGroupPolicyAnyConnectClientProfileTypeExists | The RAVPN Group Policy already has a profile for this type of AnyConnect Module | ||||||
Validation | ipv6PoolMissingPrefixLength | Missing prefix length in IPV6 address pool | ||||||
Validation | DHCPServerNoInterfaceIpAddress | The interface must have an IP address because it is used as a DHCP Server | ||||||
Validation | DHCPServerAutoConfigInterfaceInDHCPRelay | DHCP Server default interface, {0}, is used by an enabled DHCP Relay Agent. | ||||||
Validation | SecurityIntelligenceDNSPolicyGlobalBlacklistCanNotBeChanged | DNS policy global Block list can not be changed | ||||||
Validation | manualNatSubnetNotAllowedInDynamicRuleTransSrc | The dynamic manual NAT rule cannot have subnet objects for the translated source: {0} | ||||||
Validation | geoUpdateError_11 | Unable to update the Geolocation database, please retry the update | ||||||
Validation | dnsServersipv6management | You cannot use an IPv6 address for the DNS server because IPv6 is disabled on the management interface. | ||||||
Validation | onlyHttpLikeUrlsAreValid | The URL must be either HTTP or HTTPS. No other protocols are allowed. | ||||||
Validation | ftdUpdateMgrError_233 | Missing upgrade package. Cannot retry. | ||||||
Validation | cannotDeleteBaseLicense | The base license cannot be removed | ||||||
Validation | nullBgpNeighborFilteringMaximumPrefixLimitRestartInterval | Restart Interval can not be null. | ||||||
Validation | invalidBGPAddressFamilyMoreThanTwo | Cannot have more than two address families. | ||||||
Validation | snmpFruInsertTrapNotSupportedOnVirtualPlatform | SNMP FRU Insert Trap not supported on Virtual Platform. | ||||||
Validation | unexpectedPLRUnsuccessfulInstallation | Unable to install Universal Permanent Licensing. Inputted code may be incorrect. | ||||||
Validation | contextActivationFailed | Could not activate context. Please try again. | ||||||
Validation | s2sIkev1PolicyNotEnabledForAuthType | Authentication Type in IKEv1 has been set to "{0}" but none of the IKE Policies has a matching authentication type. | ||||||
Validation | accessListEntriesNotUnique | Access List entries must be unique. | ||||||
Validation | aaaInvalidUseLocalConfig | {0} AAA setting using "{1}" type for the "{2}" field must set the "useLocal" field to {3} | ||||||
Validation | filterNotSupported | Filter property not supported | ||||||
Validation | vdbBootstrap | Adding VDB updates to database | ||||||
Validation | diskFileNameIsEmpty | Disk file name cannot be null or empty string | ||||||
Validation | duplicateMetricsName | Cannot configure same metric-name across metric-groups. | ||||||
Validation | unableToCreatePTP | Unable to create PTP. | ||||||
Validation | ftdUpdateMgrError_160 | Too late to cancel upgrade. Use the 'upgrade retry' API to retry. | ||||||
Validation | manualNatOrigSrcAndDestIpVersionMismatch | The original source and original destination addresses must have the same IP version | ||||||
Validation | staticRouteDupIdentifier | Static routes must be identifiable by a unique combination of interface, network, and gateway values | ||||||
Validation | objectNat66OrigAddrPrefixShorterThanTransAddrPrefix | The IPv6 prefix of the original address subnet "{0}" must be greater than or equal to the IPv6 prefix of the translated address subnet "{1}" | ||||||
Validation | networkObjectIsADhcpRelayServer | This NetworkObject is used by the DHCP Relay Service which only supports the HOST type. | ||||||
Validation | cannotEnableCTSFlag | The interface cannot be configured in {0} mode and have CTS enabled. | ||||||
Validation | exceededEtherChannelObjectLimit | You have exceeded the limit of 48 EtherChannel objects allowed on this system. | ||||||
Validation | invalidFlexCliInterfaceValue | {0} value must be an existing PhysicalInterface, SubInterface, or a BridgeGroupInterface Object | ||||||
Validation | pppoeIpv4AddressIsDynamic | The pppoe IPv4 IPAddress is set to be dynamically provided by the PPPOE server. No ip address or mask should be provided. | ||||||
Validation | invalidHAFailoverPeerPollTimeUnit | Peer Poll time unit must be MILLISECONDS or SECONDS | ||||||
Validation | vtiHardwareNameNonEditable | Hardware name for the Virtual Tunnel Interface is a non-editable field, and must be null. | ||||||
Validation | UnsupportedBgpAFIPv6Vrf | IPv6 address is not supported for user defined virtual router. | ||||||
Validation | haConfigurationDoesNotExist | High Availability is not configured, so the attempted HA join failed. Please reconfigure HA and re-try joining HA. | ||||||
Validation | otherRunningJobCannotTriggerUpgrade | Another job {0} is in progress, cannot trigger upgrade now. Please retry once the other job is completed. | ||||||
Validation | s2sVTIIkeV1V2BothEnabled | You cannot enable both IKEv1 and IKEv2 for route-based site-to-site VPN connection profiles. | ||||||
Validation | DHCPServerPrimaryWINSHost | DHCP server primary WINS server must be host type: {0} | ||||||
Validation | DHCPServerIPPoolSize | DHCP server IP address range must not exceed 256 entries: {0} | ||||||
Validation | invalidEigrpInterfaceNoIP | Cannot configure neighbor on interfaces without IP address. Assign an IPv4 address to the interface. | ||||||
Validation | connectorMsgSendError | Connector failed to send the message. | ||||||
Validation | invalidOspfDuplicateDefaultArea | 0.0.0.0/0.0.0.0 is already used, only one area can be set as a default area | ||||||
Validation | invalidLicenseCount | This is an invalid number of license requests. Please specify the count as 1 | ||||||
Validation | mgmtInterface | The Management interface {0} cannot be configured for DHCP Relay. | ||||||
Validation | invalidHoldTime | Hold time must be 0 or greater than 2 seconds. | ||||||
Validation | invalidTemplateInstance | Instance does not match with the template it uses. Found mismatch in the properties "{0}" of SmartCLI instance with name "{1}". | ||||||
Validation | cannotRetrieveHAStatus | Failed to retrieve current device's HA configuration status | ||||||
Validation | invalidEigrpBVINetwork | Bridge group interface falls on the same network. EIGRP can not be configured on BVI interface. | ||||||
Validation | unsupportedOperation | This operation is not supported in the specified API version | ||||||
Validation | unExpectedExitCodeFromScript | The script returned an unexpected exit code, {0}. | ||||||
Validation | ddnsWebURLShouldBeNull | Web URL should be set to null. | ||||||
Validation | ddnsRunTimesRequired | run times should not be null. | ||||||
Validation | missingPerformanceTier | Performance Tier attribute is required | ||||||
Validation | PullUpgradeInitiationFailed | Pull upgrade job initiation failed | ||||||
Validation | expiredCertificateUpload | The uploaded certificate has already expired. Please upload an unexpired certificate. | ||||||
Validation | manualNatDest46AnyIpv6NotValid | The network corresponding to the full range of IPv6 addresses, i.e. ::/0, cannot be used in the destination of an IPv6 to IPv4 manual NAT rule | ||||||
Validation | RulesImportSystemDefinedGroup | You cannot select system defined rule groups. {0} is a system defined rule group. | ||||||
Validation | invalidIpAddress | Invalid IP address | ||||||
Validation | invalidCronString | Invalid cron string for updates. | ||||||
Validation | PullSignValidationFailed | Image signature verification failed | ||||||
Validation | invalidEigrpProcessUpdated | Cannot change Autonomous System when editing EIGRP process. | ||||||
Validation | objectNat46Ipv6PrefixTooLong | The translated address IPv6 network prefix length must be less than or equal to 96 in an IPv4 to IPv6 auto NAT rule: {0}({1}) | ||||||
Validation | DNInvalidCN | CN is invalid, should be in format CN= |
||||||
Validation | pppoeInvalidUserName | Invalid PPPoE user name. User name can not contain a question mark, space, or a semicolon. | ||||||
Validation | geoUpdateError_2 | No valid support contract found. Contact sales or support for more information | ||||||
Validation | invalidEigrpNeighborIPSubnet | Specified neighbor IP address should be on the same subnet to the interface. | ||||||
Validation | invalidSmartCliIPValue | {0} value must be a valid IPv4 or IPv6 address | ||||||
Validation | invalidFlexCliNegateLineSyntax | Syntax error with Flex Config CLI negate line: {0} | ||||||
Validation | geoUpdateError_15 | A newer version of GeoDB is already installed. | ||||||
Validation | aceSourceEmptyDestinationIsNot | The source network list cannot be empty when the destination network list has entries. | ||||||
Validation | intfUsedInVTI | Interface {0} is the source for a virtual tunnel interface. | ||||||
Validation | objectNat64Ipv6HostCountTooHigh | The IPv6 host count {0} in the original address exceeds the maximum allowed {1} in an IPv6 to IPv4 auto NAT rule | ||||||
Validation | invalidFMCConnectivityInterfaceManagementOnly | Management-only interface "{0}" cannot be assigned to Connectivity Interface. | ||||||
Validation | unknownCertKeyType | Only '.der,.pem,.crt,.cer,.cert,.key' files are allowed for upload | ||||||
Validation | cannotContainDHCPIpv4Address | The interface is configured in {0} mode. It cannot contain a DHCP IPV4 address. | ||||||
Validation | DHCPServerWithDefaultPassiveInterface | You cannot use a passive mode interface for the DHCP server default interface. | ||||||
Validation | incompatibleBackupFile | Backup file is incompatible with this Hardware and/or the SW version. | ||||||
Validation | ftdUpdateMgrError_231 | Missing upgrade script. Cannot retry. | ||||||
Validation | sruUpdateError_15 | Internal error occurred while updating Rule Update. Please contact technical support | ||||||
Validation | nextHopInvalidSettingCombination | Cannot provide Specific IP(s) when Next Hop uses peer address. | ||||||
Validation | diagIntfMgmtIntfIpv4 | You cannot configure the same IPv4 address for the management interface and the diagnostic physical interface. | ||||||
Validation | duplicateName | Validation failed due to a duplicate name: "{0}" | ||||||
Validation | invalidOspfAreaIdValue | Area ID must be an integer between 0 and 4294967295 or an IPv4 address | ||||||
Validation | memberInterfaceCannotBeUpdated | An interface that is a member interface of either a VLAN or Port Channel cannot be associated with {0} object. | ||||||
Validation | deviceAlreadyEnrolled | The device is already enrolled with Cisco cloud. | ||||||
Validation | BasePolicyMustBeSystemDefined | The base policy must be defined by the system. | ||||||
Validation | minPrefixLessThanMaxPrefix | The minimum prefix length should be less than the maximum prefix length. | ||||||
Validation | apihostnameFormatInvalid | API Hostname must start with 'api-' and end with '.duosecurity.com' | ||||||
Validation | ftdCertNotFound | FTD Certificate not found. | ||||||
Validation | VrfNameChange | You cannot change the virtual router name. | ||||||
Validation | invalidEigrpNetworkObject | EIGRP does not support Network Object with address 0.0.0.0/0.0.0.0. | ||||||
Validation | invalidSmartCliNegateLineSyntax | Syntax error with Smart CLI negate line: {0} | ||||||
Validation | invalidObjectNameSpaceAllowed | The name "{0}" is invalid. The name can start with an alphanumeric character or an underscore. It can contain spaces and the special characters +, ., _, and -. However, the name cannot include a leading or trailing space. | ||||||
Validation | ipv6OptionsCannotBeTrue | The interface {0} is configured in {0} mode. You cannot turn on IPV6 options: ipv6-enabled, auto-config, suppress-RA or enable DHCP for IPv6 address and non-address configuration. | ||||||
Validation | acRuleDestinationZonePassive | You cannot use a passive mode security zone as a destination zone in rule {0}. | ||||||
Validation | natRuleImpactWithVRFConfig | The source and destination interfaces belong to different virtual routers. Please ensure you have configured appropriate routes across the virtual routers for this rule to function correctly. | ||||||
Validation | invalidSyslogPort | Invalid port for Syslog Server. Either use the default ports, which are 514 for UDP or 1470 for TCP, or specify a port in the 1025-65535 range. | ||||||
Validation | invalidInterfaceSelectedInDdns | Invalid type of interface selected, the only types allowed are PhysicalInterface and SubInterface. | ||||||
Validation | MultipleGroupsReplace | You can only specify a single rule group if using the REPLACE option. | ||||||
Validation | createFTSIndexFailed | Failed to create indices for objects and rules. Full Text Search will not work. | ||||||
Validation | invalidEigrpExceededLimit | Only one EIGRP process allowed per device. | ||||||
Validation | networkWithoutNetmask | The type Network requires a netmask. To specify a single host, either use the type Host, or use {0}/255.255.255.255. | ||||||
Validation | invalidLowercaseObjectName | The name "{0}" is invalid. The name can start with an alphanumeric lowercase character or an underscore. The name cannot contain uppercase characters. It can contain the special characters +, ., _ and -. The name cannot contain spaces. | ||||||
Validation | s2sVTINoTunnelSource | You must assign the tunnel source for the virtual tunnel interface if you want to use it for a site-to-site VPN connection. | ||||||
Validation | timeZoneInvalidDSTDateRange | The dstDateRange section is incomplete. To configure a dstDateRange, you must specify the startDateTime and the endDateTime. | ||||||
Validation | timeRangeInvalidDate | Invalid effective start or end date time. The start time must be prior to the end time. Use the format YYYY-MM-DDTHH:MM, with time in 24-hour notation. | ||||||
Validation | invalidRoleARN | RoleARN field should be of the format [arn:partition:service::account-id:resource-type/resource-id]. | ||||||
Validation | invalidOspfNetwork | {0} is not a legal network | ||||||
Validation | dnsServerGroupNameCannotBeDefault | DefaultDNS is a reserved name. Please enter a different name. | ||||||
Validation | appFilterApp | The application filter must have valid application parameter values. {0}. | ||||||
Validation | reservedAddressForInternalUsageNotAllowedAsFMCHost | FMC Host of "{0}" is reserved for internal usage. | ||||||
Validation | invalidOspfSummaryAddress | OSPF does not support summary address 0.0.0.0/0.0.0.0 | ||||||
Validation | atleastOneSyslogServerRequired | Atleast one Syslog Server Configuration is required to enable Syslog filter. | ||||||
Validation | objectNatRouteLookupAndIntfInTransNet | You cannot select the Perform Route Lookup option if you select interface for translated source | ||||||
Validation | invalidMinHoldTime | Minimum hold time must be 0 or greater than 2 seconds. | ||||||
Validation | onlyIPv6NetworkObjectsAllowed | Only IPV6 networks are allowed. | ||||||
Validation | moreThanOneFilterNotSupported | This object type does not support more than one filter parameter. | ||||||
Validation | interfaceHasDhcpRelayAgent | Interface {0} cannot be configured as type DHCP since it is currently configured as a DHCP Relay Agent. | ||||||
Validation | sruDownloadSuccess | Rulepack successfully downloaded | ||||||
Validation | invalidSmartCliNetworkObjectValue | {0} entity value must be an existing Network Object | ||||||
Validation | cannotModifyMemberInterfacesInEtherChannel | You cannot modify an interface that is a member interface in an EtherChannel. | ||||||
Validation | vdbUpdateError_3 | The update server did not have a file applicable to this device. Try again later. If the problem persists, contact Technical Support. | ||||||
Validation | invalidEigrpOutgoingRouting | Distribute List Out cannot be configured without Distribute List IN. | ||||||
Validation | invalidSmartCliInterfaceValue | {0} entity value must be an existing PhysicalInterface, SubInterface, or a BridgeGroupInterface Object | ||||||
Validation | certKeyTypeNotFound | Certificate digital signature is not supported. Supported types are: RSA, ECDSA, EdDSA. | ||||||
Validation | SslRulesWithDeletedCategoriesDisabledPolicy | Some of the SSL decryption rules refer to deleted URL Categories. Number of SSL decryption rules affected: {0}. Enable the SSL Decryption policy, remove deleted URL categories in the rules, or replace them with new ones. You can then disable the policy. | ||||||
Validation | vtiIPTypeMustBeStatic | The IP Type for VTI must be STATIC. | ||||||
Validation | RaVpnConnProfAuthentictaionServerNotSpecified | Authentication Identity source not specified. | ||||||
Validation | missingIdentityRuleWithAuth | Because there are no identity rules that require authentication, no users or groups defined in the directory can be matched. Configure at least one identity rule that requires authentication before configuring user-based access control rules. | ||||||
Validation | deploymentCannotBeStartedWhenBaseIsMissing | Deployment cannot be started when 'BASE' license is missing | ||||||
Validation | invalidOspfVirtualLinkMD5NotEnabled | The selected authentication type is message digest. You must also configure the message digest key | ||||||
Validation | cannotBlankIntfNameUsedInDIMA | Cannot blank out the name of interface when its used in management access rule. | ||||||
Validation | unknownSlaOperation | Unknown SLA Operation: {0} | ||||||
Validation | invalidFlexCliTemplateNull | Template cannot be null | ||||||
Validation | invalidAuthAction | Invalid authentication action in identity rule. You can select No Auth or Active Auth only. | ||||||
Validation | deleteObjWithRel | You cannot delete the object because it contains {0}. You must remove the object from all parts of the configuration before you can delete it. | ||||||
Validation | invalidDupOutRouteFilter | Duplicate configuration found for outgoing route filter | ||||||
Validation | uniqueEtherChannelIDNeeded | EtherChannel ID is already in use. You must specify a unique channel ID. | ||||||
Validation | invalidFlexCliTemplateIndexRef | Index reference is not supported | ||||||
Validation | interfaceMigrateSourceAndDestinationCannotBeMembersOfEtherChannelInterface | Source and destination IDs cannot belong to members of an EtherChannel Interface. | ||||||
Validation | duplicateVlanId | VLAN ID {0} is already used in {1} | ||||||
Validation | UnsupportedNetworkObjectTypeForVpn | Network Object is being used in RavpnConnectionProfile {0} , type can't be edited to FQDN or HOST | ||||||
Validation | invalidNetwork | The given network {0} cannot be found. | ||||||
Validation | s2sPfsGroupNotValidIkev1 | Only PFS groups 2,5,14 can be used with IKEv1 enabled | ||||||
Validation | InvalidBgpNeighborMigrationLocalAsRemoteAsNumber | Cannot have local-as number same as remote-as number. | ||||||
Validation | invalidLocalUserInRule | The local user selected in the rule is not valid. | ||||||
Validation | InvalidIOCForNap | Inspector Override Config for Network Analysis Policy {0} is not valid. | ||||||
Validation | natDestIntfNotNamed | The interface used for NAT rule destination interface must have a name | ||||||
Validation | invalidVersion | Validation failed due to an invalid version: "{0}" | ||||||
Validation | geoUpdateError_4 | Error downloading rule update, file is corrupt (MD5 does not match). Please contact Technical Support or try again later. | ||||||
Validation | InvalidRuleImportMode | Invalid rule import mode. | ||||||
Validation | cdoTokenTooLong | The authentication token length exceeds the limit of 32 | ||||||
Validation | cannotUseIntfWithPassiveMode | You cannot use an passive mode interface to configure data interface. | ||||||
Validation | cloudNoResponse | Snort 3 cloud update failed: No response from the update server or connection timeout. Please try again. | ||||||
Validation | ftdUpdateMgrError_242 | Retry is not allowed at this time. Use the 'upgrade cancel' API to cancel. | ||||||
Validation | manualNatDest46Ipv6PrefixTooShort | The translated destination IPv6 network prefix length must be greater than or equal to 64 in an IPv4 to IPv6 manual NAT destination translation: {0} | ||||||
Validation | acRuleNullRuleAction | You must specify an access rule action | ||||||
Validation | pppoeDoesNotRequireStandbyIP | A Standby IP address should not be provided for interfaces with PPPoE type. | ||||||
Validation | s2sNetworksMixedToStrict | Local networks contain both IPv4 and IPv6 but remote networks contain only {0} addresses | ||||||
Validation | invalidOspfAreaTypeConfiguration | Multiple area types defined for the same area | ||||||
Validation | scheduleExist | Unable to schedule job {0}. A schedule is pending. | ||||||
Validation | SecurityIntelligenceURLPolicyMoreThanOne | Cannot have more than one Security Intelligence URL Policy. | ||||||
Validation | cannotAddS2SVpnInterfaces | Interface {0} is used for a site-to-site VPN. You cannot include it in an ECMP traffic zone. | ||||||
Validation | AnyConnProxyServerPortTooLong | Proxy Server Host and Port should be within 100 characters | ||||||
Validation | invalidPerformanceTier | The format of the provided Performance Tier is invalid | ||||||
Validation | acRuleNullEventLogAction | You must specify an event logging action for the access rule | ||||||
Validation | RaVpnOutsideIntfAndPortDiffFromFDM | The selected outside interface ({0}) and port ({1}) combination is currently being used in a management access list to allow FDM connections. You cannot use this same combination for RA VPN. To use the same interface, please configure a different port number for the RA VPN connection. | ||||||
Validation | invalidASPathName | ASPath name must be a numeric value between 1 and 500 | ||||||
Validation | manualNatTransDestIsNull | You must specify a translated destination network | ||||||
Validation | invalidOspfv2IP | {0} must be an IPv4 address | ||||||
Validation | filterOperatorNotSupported | Operator not supported for "{0}" filter for this type of object. | ||||||
Validation | manualNatDest64Ipv4AnyIsNotAllowedWithNat46WellKnownPrefix | The translated destination cannot be IPv4 "any" with the well known NAT46 prefix "64:ff9b::" in the original destination | ||||||
Validation | ipWithoutPrefix | The IPv6 address requires a prefix. | ||||||
Validation | haActionDuringDeployment | HA action cannot be performed during an ongoing deployment process. | ||||||
Validation | manualNatOrigSrcHasIpv6AndIpv4Addresses | The original source network should not contain both IPv4 and IPv6 addresses | ||||||
Validation | deprecatedApplicationIsUsedInAccessRule | Deprecated applications found in the following Access Rule {0}, please remove them: {1}. | ||||||
Validation | pppoeNotSupportedBGI | Bridge Group interface member {0} cannot be set to PPPoE. | ||||||
Validation | invalidPort | Invalid port. Valid ports are from 1 to 65535. | ||||||
Validation | aceSourceDestinationNoMatchingIPV | IP version of source and destination network objects do not match. | ||||||
Validation | dnsDuplicate | DNS server {0} is specified more than once. Please remove duplicate servers. | ||||||
Validation | invalidOspfOutRouteFilterIdNotFound | No process found for the given protocol and identifier | ||||||
Validation | invalidFlexCliPortValue | {0} value must be an existing TCPPortObject or UDPPortObject | ||||||
Validation | storeFilesWithRuleAction | File Rule validations failed. Store Files can only be ALL for DETECT_FILES and BLOCK_FILES rule actions. | ||||||
Validation | invalidFlexCliDuplicateVariable | A variable with name {0} already exists in the configuration | ||||||
Validation | timeRangeInvalidDailyIntervalTime | Invalid dailyStartTime. The dailyStartTime must be prior to the dailyEndTime. | ||||||
Validation | unsupportedSSPInterfaceDuplex | Unsupported SSP Interface Duplex on NGFW | ||||||
Validation | invalidApplicationProtocolForDownload | File Rule validations failed. IMAP and POP3 application protocols support only DOWNLOAD direction of transfer. | ||||||
Validation | invalidSmartCliLineNotRepeatable | This command cannot be repeated but it appears more than once in the configuration. Please remove the repeated commands | ||||||
Validation | sysDefinedRuleCantChange | Cannot change or delete a system defined intrusion rule. | ||||||
Validation | invalidRavpnLicense | RA-VPN license is not enabled | ||||||
Validation | SecurityIntelligenceDNSPolicyGlobalWhitelistCanNotBeChanged | DNS policy global Do Not Block list can not be changed | ||||||
Validation | haBreakInterfaceOptionCannotBeEmpty | Interface Option cannot be null or empty. | ||||||
Validation | onlyIPv4NetworksAllowed | Only IPV4 networks are allowed - {0} | ||||||
Validation | netModSwitchRequireInterfaceScan | Some interfaces have been added to or removed from the device. Please perform an interface inventory scan before updating the network module. | ||||||
Validation | invalidOspfInterfaceSecretRequirements | Secret {0} does not meet the password requirements for {1} | ||||||
Validation | connectorResetError | Connector reset failed due to an internal error. | ||||||
Validation | invalidOutRouteFilterId | Process identifier is required for the chosen protocol | ||||||
Validation | snmpAuthAlgorithmShouldBeNull | Authentication Algorithm should not be provided for SNMP Users with NOAUTH security level. | ||||||
Validation | invalidFlexCliCharLimitExceeded | A cli command exceeded character limit | ||||||
Validation | pppoeObjectFieldsAreRequired | The pppoe object fields (vpdnGrpName, pppoeUser, pppoePassword) are required fields. | ||||||
Validation | duplicateNetwork | Found duplicate use of NetworkObject {0}. | ||||||
Validation | memberIntefaceCannotBeCtsEnabled | An interface with CTS enabled cannot be a member of an EtherChannel. | ||||||
Validation | CannotCreateNap | You cannot create a Network Analysis Policy. | ||||||
Validation | DHCPServerOverlapOutsideInterface | A DHCP server is already configured for {0}. You cannot use DHCP to obtain the IP address on an interface running DHCP server. Please select a different interface. | ||||||
Validation | geoDbBootstrap | Adding Geolocation updates to database | ||||||
Validation | pppoeStaticAddressMaskMustBe32 | The pppoe static ip address must have a mask of 32. | ||||||
Validation | iseNetworkFilterInvalid | You cannot use an FQDN or RANGE network object or an IPV6 Address in the Identity Services Engine configuration. | ||||||
Validation | evalNotUsed | Evaluation mode cannot be stopped as it is not currently in use | ||||||
Validation | primaryAndSecondaryIseConflict | Primary and Secondary ISE Server address cannot be the same | ||||||
Validation | invalidFlexCliTemplateEmpty | Template cannot be empty | ||||||
Validation | haBreakFromNegotiation | The units in this HA pair are in negotiation. You cannot execute {0} until negotiation is finished. | ||||||
Validation | AnyConnServerCertNeedsIssuerCommonName | The Server certificate {0} requires issuer common name | ||||||
Validation | invalidThreatLicenseForFileRule | Missing Threat License. Creating or updating the file rule requires this license. | ||||||
Validation | identityRealmNullDirectoryConfig | No directory configuration defined for the realm. | ||||||
Validation | invalidIPAddressRange | DHCP server IP address range is invalid | ||||||
Validation | acRuleDupUrlCat | More than one URL matcher is specified for URL category {0} | ||||||
Validation | haFullDeploymentNeeded | Before attempting {0}, all pending changes need to be deployed. | ||||||
Validation | staticRouteNetworkMatchesInterfacePrefix | There is already a route for {0}/{1} because of the implicit route for the interface {2}, {3}/{4}. Do not define routes for networks configured on an interface. If the interface has been disabled, deploy the changes before defining route. | ||||||
Validation | RaVpnPasswordManagementNotAvailable | Password Management is only available when AAA is selected. | ||||||
Validation | invalidBgpAggregateTimerVrf | The aggregate timer value should match the aggregate timer value in General Settings. | ||||||
Validation | backupDoesNotExist | Backup does not exist. | ||||||
Validation | cloudServiceInfoUnsupportedMethod | You cannot create, update, or delete cloud service info. | ||||||
Validation | invalidSpecialRealmId | Invalid Special Realm creation operation | ||||||
Validation | authTokenContainSpecialChar | The registration key is invalid. | ||||||
Validation | s2sNoIkev1RemoteAnyNetwork | For IKEv1 connections, specific local networks with a remote network spanning the entire IP address space is not allowed | ||||||
Validation | objectNatDestIntfIpv6DisabledWithIpv6InTransNetwork | Destination interface "{0}" is not IPv6 enabled. You cannot use IPv6 addresses in the translated network | ||||||
Validation | emptyPLRAuthorizationCode | Authorization code not given. In order to install Permanent Licensing reservation, you must input the authorization code. | ||||||
Validation | invalidSmartCliLineSyntax | Syntax error with Smart CLI line: {0} | ||||||
Validation | vdbUpdateError_16 | A newer version of VDB is already installed. | ||||||
Validation | invalidRetryInterval | Retry interval has to be in the range {0} and {1} | ||||||
Validation | mgmtIPandGatewayNotSameSubnet | The gateway {1} is not in the same subnet defined by the management address, {0}/{2}. The management and gateway addresses must be in the same subnet. | ||||||
Validation | DHCPServerSecondaryDNSOnly | DHCP server secondary DNS server cannot be specified unless a primary DNS server is also specified | ||||||
Validation | monitoredInterfaceCannotBeShutdown | Cannot disable HA monitored interface on this platform. Please remove interface monitoring, perform deploy and then disable the interface. | ||||||
Validation | invalidIpv4Address | Invalid IPv4 address | ||||||
Validation | AnyConnIdleTimeoutInvalid | AnyConnect idle timeout must be 1-35791394 minutes | ||||||
Validation | vdbUpdateError_5 | The system could not download the update file. Please try again later. | ||||||
Validation | invalidSmartCliAccessListValue | {0} entity value must be an existing Standard or Extended Access List Object | ||||||
Validation | RuleAreOverriddenUnderPolicy | Intrusion Rule(s) {0} are overridden under Intrusion Policy [{1}]; | ||||||
Validation | s2sAnyNetworkOneProfile | Only one Site-to-Site VPN profile can exist if local and remote networks are both unset in a profile | ||||||
Validation | noUpgradeStatusScript | The script file {0} is missing. | ||||||
Validation | invalidSmartCliNumericValue | {0} value is not a valid integer | ||||||
Validation | netModNotEnabled | The interface {0} cannot be {1} since the Network Module is disabled. Enable NetworkInterfaceModule{2} in order to perform the {3} operation. | ||||||
Validation | manualNatPortNotAllowedWithDnsEnabled | You cannot enable DNS reply with port translation in a manual NAT rule | ||||||
Validation | invalidFTSFilterValue | The search filter contains an unsupported character. Supported characters are [a-z A-Z 0-9 * . , _ -]. | ||||||
Validation | invalidPerAccessListLoggingValues | When the logging option is set to per access list, the log level and log interval may not be null. | ||||||
Validation | staticRouteInconsistentGatewayProtocol | Static route inconsistent protocol version for gateway: IPv4 vs IPv6 {0} | ||||||
Validation | invalidCustomWebURLParams | The following parameters in web URL are invalid: | ||||||
Validation | vpnIntfCannotBeMemberOfUserDefinedVrf | Interface {0} is assigned to a custom virtual router. You can configure VPN on interfaces that belong to the global virtual router only. | ||||||
Validation | cryptoNonCompliantIkev2ProposalForIntegrityType | The upgraded IKEv2 proposals use MD5 as Integrity which is not supported on this FTD version: {0}. | ||||||
Validation | invalidQualifierText | "{0}" is not a valid qualifier. Quailifier text can optionally begin with a forward slash followed by one or more alphabets, numbers, or underscore. | ||||||
Validation | ErrorParsingStderrFile | Encountered an error when reading the stderr file. | ||||||
Validation | InvalidRuleGroupName | Could not find a custom rule group with the name of {0}. | ||||||
Validation | vlanIdBeingUsedByVlanInterface | VLAN ID {0} is being used by VLAN interface "{1}" and cannot be assigned to a subinterface's vlan id. | ||||||
Validation | InvalidCountryContinentSelection | Validation failed. You cannot include country "{0}" because continent "{1}" is already included. | ||||||
Validation | acRuleCannotHaveMultipleModes | You cannot use security zone of different modes in a rule. | ||||||
Validation | invalidOspfLsaTimers | Incorrect LSA timer configuration, expected initial-delay <= min-delay <= max-delay | ||||||
Validation | bridgeGroupInterfaceIsOutsideInterfaceInAnyConnectProfile | The interface {0} selected as outside interface in AnyConnectProfile {1} | ||||||
Validation | manualNatDest66HostInOrigDestNotAllowedWithSubnetInTransDest | The IPv6 host object "{1}" in the original destination is not allowed with an IPv6 subnet object "{0}" in the translated destination | ||||||
Validation | invalidOspfNeighborIPAddress | Specified neighbor IP address belongs to one of the interfaces on the device | ||||||
Validation | vdbUpdateError_11 | Version mismatch, unable to proceed | ||||||
Validation | invalidActiveAuthPort | Invalid port for Active Auth. Port must be either 855 or in the 1025-65535 range | ||||||
Validation | mismatchedVersion | Another user or the system updated this object while you were editing it. Please refresh the browser page and redo your changes. | ||||||
Validation | notInRange | The value has to be between {0} and {1} | ||||||
Validation | noUpgradeInitiated | No upgrade action has been initiated. | ||||||
Validation | invalidOspfInterfaceNoConfiguration | Configuration is not specified for the selected interface | ||||||
Validation | manualNatRouteLookupAndIntfInOrigDest | You cannot select the Perform Route Lookup option if you select interface for original destination | ||||||
Validation | thresholdExceedsTimeout | The threshold value should not exceed the timeout value | ||||||
Validation | invalidEigrpNeighborIPAddress | Specified neighbor IP address belongs to one of the interfaces on the device. | ||||||
Validation | cloudServiceCannotBeEnabledIfNotEnrolled | A cloud service cannot be enabled if the device is not enrolled in the cloud. | ||||||
Validation | acRuleSyslogOnWithEventLogOff | You cannot enable syslog with event logging disabled | ||||||
Validation | bridgeGroupIsNotSupportedAsTargetInterface | A bridge group member interface is not supported as the target interface. | ||||||
Validation | bridgeGroupMemberModeOnInvalidInterface | You cannot set the interface mode type to BRIDGEGROUPMEMBER. | ||||||
Validation | InvalidSSPFactoryServiceClass | Error while getting service class for a give model type {0} | ||||||
Validation | multicastMacAddress | Invalid MAC address. MAC address must not have the multicast bit set (The second hexadecimal digit from the left cannot be an odd number.) | ||||||
Validation | externalBrowserPackageNotPresentWhenEnableExternalBrowserIsTrue | You must select an external browser package when you configure SAML authentication to use the default OS browser. | ||||||
Validation | natSrcModePassive | Source interface {0} is in passive mode. You cannot use a passive mode interface in NAT rules : {1} | ||||||
Validation | SystemDefinedRule | You cannot modify system defined rules. {0} is a system defined rule. | ||||||
Validation | CustomInstanceName | Instance name cannot end with "_custom". | ||||||
Validation | bridgeGroupInterfaceReferencedInS2SVPN | The following Interfaces are used in S2S VPN configuration: {0}. This feature is not compatible with a bridge group member interface. You must remove the interfaces from the configuration before you can add them to the bridge group. | ||||||
Validation | invalidSmartCliActionDependency | Operation cannot be performed due to a dependency in the object {0} | ||||||
Validation | CannotFindIOCByUuid | Inspector Override Config specified by uuid {0} could not be found. Use "default" for uuid. | ||||||
Validation | switchModeNotAllowedInSecurityZone | Switch mode is not allowed in a security zone. | ||||||
Validation | MustSpecifySecurityLevelForRuleGroup | You must specify a security level for the rule group. | ||||||
Validation | intfMigrationExportNothingToExport | Nothing to migrate. | ||||||
Validation | SyslogServerInterfaceInBridgeGroup | The interface {0} is already a member of the bridge group interface {1} and hence cannot be configured as a Syslog server | ||||||
Validation | DHCPServerClient | You cannot configure DHCP server on a interface that obtains its IP address using a DHCP client | ||||||
Validation | vdbUpdateError_8 | Unspecified error when doing remote update. VDB download failed | ||||||
Validation | invalidInterfaceJoin | The interface provided cannot be used for the join operation. Valid interfaces are interfaces with type PhysicalInterface. | ||||||
Validation | upgradeScriptNotFound | The script file {0} is missing. | ||||||
Validation | appFilterMissingUuid | The application filter should have a UUID {0}. | ||||||
Validation | dataInterfaceHttpsPortOutOfRange | Invalid Custom Data Interface HTTPS Port range. Port range must be between 1 to 65535. | ||||||
Validation | invalidSmartCliBranchUsage | Branch commands are not in accordance with branching usage | ||||||
Validation | invalidOspfInterfaceManagementOnly | You cannot enable OSPF on management-only interfaces | ||||||
Validation | ftdUpdateMgrError_159 | Cancel upgrade failed. Use the 'upgrade status' API for details. | ||||||
Validation | interfaceMigrateSourceAndDestinationCannotBeMembersOfBridgeGroupInterface | Source and destination IDs cannot belong to members of a Bridge Group Interface. | ||||||
Validation | manualNatSrcIntfIsNullWithIntfInOrigDest | Source interface cannot be any if you select interface in original destination | ||||||
Validation | addressDoesNotMatchNetmask | The IP Address {0} does not match with netmask {1}. To specify a network use {2}/{3}. To specify a host use {4}/255.255.255.255. | ||||||
Validation | bridgeGroupInterfaceMemberIpv6UnsupportedOptions | Bridge Group member interface {0} cannot turn on IPV6 options: ipv6-enabled, auto-config, suppress-RA or enable DHCP for IPv6 address and non-address configuration | ||||||
Validation | snmpNullAuthenticationAlgorithm | Authentication algorithm can not be null for SNMP users with security level AUTH and PRIV. | ||||||
Validation | cannotCreateWithMask | Unable to create object using a secret mask containing asterisks (*). | ||||||
Validation | smartAgentInitializationError | Unable to initialize Smart Agent, which communicates with the Smart Licensing server. Please reboot the system and try enabling/disabling licenses again. If the problem persists, please contact Cisco Technical Support. | ||||||
Validation | RuleMsgEmpty | Msg field is missing for intrusion rule: {0}. | ||||||
Validation | snort3LatestRuleExists | The latest Snort3 rulepack is already installed | ||||||
Validation | expiredLicenseGracePeriod | The grace period for the base license has expired. You cannot deploy changes until you apply a new license. | ||||||
Validation | BinderRuleMissingWhenField | Binder Rule is missing "when" field. | ||||||
Validation | lspFilePermission | Failed to obtain read/write permission for file: {0}. | ||||||
Validation | maxECMPStaticRouteLimitReached | You cannot have more than 8 equal-cost static routes. | ||||||
Validation | invalidUserTypeInRule | The users in the rule should be of type TrafficUserEntry or TrafficGroupEntry | ||||||
Validation | unableToRetrieveTiers | Unable to retrieve tiers. | ||||||
Validation | invalidNetworkSubtypeForIdentityRuleDestination | The identity rule destination criteria contains a network object of an unsupported type. | ||||||
Validation | ErrorParsingRulesData | Encountered an error when parsing the rules data: {0} | ||||||
Validation | performanceTierUpdateNotAllowedForPLR | Performance Tier update operation is not allowed for PLR mode. To change the tier deregister device and register in with new tier. | ||||||
Validation | invalidFlexCliBlockNotFound | Referenced block {0} is not found | ||||||
Validation | identitySourceIDIsNullOrEmpty | The identity source ID cannot be null or empty | ||||||
Validation | invalidServerSecretKey | The server secret key is invalid. It can contain the special characters: $, &, -, _, ., +, @ but should not contain spaces. | ||||||
Validation | invalidOrMissingUserRole | No user role could be obtained from identity source response for external user. | ||||||
Validation | manualNatSrc46DynamicNotAllowed | Dynamic NAT is not allowed in a manual NAT rule for IPv4 to IPv6 source address translation | ||||||
Validation | provisionUnsupportedMethod | The update and delete methods are not supported for the Provision API. | ||||||
Validation | fqdnIdAssignmentFailure | Unable to assign the FQDN ID to the FQDN network object. | ||||||
Validation | featureCapabilitiesParseException | Exception thrown while parsing application context files for Feature Capabilities | ||||||
Validation | cannotRestoreInHAMode | You cannot restore a backup while the device is part of a high availability group. Please break HA and then perform the restore operation. | ||||||
Validation | staticRouteDupNetworkValue | Static route duplicate network value: {0} | ||||||
Validation | intfMigrationExportValidationFailed | Please fix validation errors and resubmit. {0} | ||||||
Validation | multipleDHCPRelayEntities | Multiple DHCPRelay entities found. | ||||||
Validation | invalidEigrpDuplicateRouting | {0} routing interface already configured. | ||||||
Validation | cannotEditDeleteSpecialRealm | Cannot edit the Special Realm | ||||||
Validation | memberInterface | This interface is a member interface of either a VLAN or Port Channel. You cannot update its properties or refer to it from other policies or objects. | ||||||
Validation | snmpBothTrapAndPollCannotBeEnabled | Both Trap and Poll cannot be enabled for SNMP Host with Host Group type. | ||||||
Validation | invalidLinkLocalIPAddress | The IP address "{0}" is not a link-local address | ||||||
Validation | ipv6OverlappingSubnet | This IPv6 address exists in the subnet of the {0} interface. | ||||||
Validation | invalidDHCPClientInternalRouting | You must specify a static address for the management IP when you route management traffic through the data interfaces. Using DHCP client to obtain an address is not allowed. | ||||||
Validation | ftdUpdateMgrError_239 | Upgrade in progress. Cannot retry. | ||||||
Validation | invalidOspfRouteMapInterfaceVrf | Interface {0} used in route map should belong to the virtual router {1}. | ||||||
Validation | invalidPlatform | Tiered licensing is only support on virtual platforms. | ||||||
Validation | nameMustBeNull | The interface is configured in {0} mode. You cannot name this interface. | ||||||
Validation | vlanNotAssociatedWithPortMode | VLAN {0} is not associated with switch port mode of the interface | ||||||
Validation | invalidOspfRedistOspfIdentifier | Identifier value {0} does not match any OSPF processes in use | ||||||
Validation | invalidV6StartCompatible | IPv4-compatible IPv6 as start address is not supported. | ||||||
Validation | s2sMaxBackupPeer | The number of backup peers exceeds the maximum count of 9. | ||||||
Validation | invalidOspfDuplicateProcess | An OSPF process already exists with the given Process ID | ||||||
Validation | geoUpdateError_5 | The system could not download the update file. Please try again later. | ||||||
Validation | invalidAction | Invalid Action {0} | ||||||
Validation | invalidUpdateFile | The uploaded file is not valid. | ||||||
Validation | adiCliTestTimedout | The connection test timed out. | ||||||
Validation | emptySGTTags | There must be at least one SGT tag. | ||||||
Validation | smartCliUpgradeFailed | SmartCLI upgrade failed due to a system error, please contact the support. | ||||||
Validation | PullFileCertificateError | File upload failed - Https Certificate Issue - | ||||||
Validation | InvalidPeerHoldTime | You cannot enter a hold time value that is less than 3 times the peer poll time | ||||||
Validation | s2sOverlapChosenNetworks | Site-to-site profile has {0} network objects that have overlapping address space: {1}, {2} | ||||||
Validation | unsupportedIkevOneEncryption | The following encryption algorithms are not supported for IKEv1 policies: 3DES. | ||||||
Validation | ftdUpdateMgrError_244 | Upgrade not in failed state. Cannot retry. | ||||||
Validation | invalidFileName | The filename is invalid | ||||||
Validation | acPolicySyslogOnWithEventLogOff | You cannot specify a syslog server because connection logging is disabled. | ||||||
Validation | unsupportedIkevOneHash | MD5 Hash is not supported in IKEv1 Policies. | ||||||
Validation | ipsecPolicyNeedEncryption | Policy must have at least one encryption method | ||||||
Validation | invalidPublicKey | Public key is not valid | ||||||
Validation | subIntfReuseDupVlanId | VLAN ID {0} is already deployed on sub-interface {1} which is being deleted or modified. Please deploy current changes before re-using this VLAN ID. | ||||||
Validation | licenseValidationFailed | License certificate validation failed. The Smart License servers might not have been available. Please try again. | ||||||
Validation | acRuleProtocolNotAllowedInSrcPorts | A protocol object is not allowed in the source ports field: {0} | ||||||
Validation | cannotAddSubInterfacesToEtherChannelMemberInterfaces | You cannot add subinterfaces to physical interfaces that are part of an EtherChannel. | ||||||
Validation | unableToGeneratePLRReleaseCode | Unable to generate PLR Release Code. In order to generate a release code, Permanent Licensing must be enabled or be in-progress to be enabled. | ||||||
Validation | RaVpnConnectionProfileSAMLNoFallbackOrSecondary | If the primary authentication source is SAML, you cannot specify a fallback or secondary authentication source. | ||||||
Validation | manualNatTranslatedDestCannotIncludeNetworkGroupWithFQDN | The translated destination cannot include a network group that contains an FQDN network object | ||||||
Validation | serverAllowedInterfaceTypes | Invalid type of DCHP Relay Server interface, the only types allowed are PhysicalInterface, SubInterface, VLAN, VTI, and EtherChannelInterface. | ||||||
Validation | upgradeInProgress | Upgrade process is still running. Cannot cancel current running upgrade. | ||||||
Validation | invalidSlaThreshold | The threshold value has to be between 0 and 2147483647 milliseconds. | ||||||
Validation | cannotUpdateNullKey | Missing existing encrypted string, The asterisk (*) is not an allowed character. | ||||||
Validation | snmpServerHostsManagerAddressDuplicates | The same address is repeated in the SNMP hosts list. You can specify a manager address only once. | ||||||
Validation | operationalSLAAPIUnsupportedMethod | The method is not supported. | ||||||
Validation | fqdnIdNotAvailable | All FQDN IDs have been assigned. | ||||||
Validation | minCantBeGreaterThanMax | Minimum File Size cannot be greater than maximum File Size. | ||||||
Validation | invalidAuthenticationPort | Authentication port has to be in the range {0} and {1} | ||||||
Validation | AnyConnOutsideCannotBePassive | The interface {0} added to AnyConnectProfile is invalid, the outside interface cannot be in passive mode | ||||||
Validation | RangeInvalidEnd | Invalid End Address | ||||||
Validation | emptyLdapName | You must specify an LDAP attribute name. | ||||||
Validation | InvalidUserVrfNameAsGlobal | 'Global' is a reserved keyword for Virtual Router. Please use other name for the virtual router. | ||||||
Validation | powerOverEthernetCannotBeNull | Power over ethernet cannot be set to null on the {0} physical interface. | ||||||
Validation | PullFileUnsupportedProtocol | Unsupported protocol used in downloadUrl. Only http or https can be used. | ||||||
Validation | invalidFlexCliUnsupportedVariableType | {0} is not a supported variable type | ||||||
Validation | targetInterfaceInvalidName | Interface used for SLA monitor must have a logical name | ||||||
Validation | cloudEventsCanNotBeToggled | Cannot toggle cloud event. | ||||||
Validation | invalidFMCConnectivityInterfacePPPoENotSupported | PPPoE is not supported on Connectivity Interface. | ||||||
Validation | HTTPNoProxyServer | proxyServer must not be null, Please enter the proxy server IP address. | ||||||
Validation | invalidVariableName | The name "{0}" is invalid. The name can start with an alphanumeric character or an underscore. It can contain the special characters +, _ and - | ||||||
Validation | PullUpgradeFailed | Pull Upgrade job failed | ||||||
Validation | pppoeCannotAddBridgeGroupInterfaceMember | Interface {0} is a member of BridgeGroup Interface {1}. You cannot enable PPPoE on it. | ||||||
Validation | ruleUrlCatStateDeleted | {0} rule must not contain an URL Category whose state is DELETED. | ||||||
Validation | InvalidRuleId | Could not find a rule with the ID of {0}. | ||||||
Validation | mismatchedOrdinal | Ordinal should remain same on update | ||||||
Validation | invalidSmartCliNumericMinValue | {0} value cannot be less than {1} | ||||||
Validation | AccessRulesWithDeprecatedCategories | Some of the access rules refer to deprecated URL Categories. Number of access rules affected: {0} | ||||||
Validation | performanceTiersNotChanged | Performance Tier is the same as currently applied. | ||||||
Validation | lspInstallerFailed | Snort 3 rule package installation failed: Package installer failed with a exception. | ||||||
Validation | acRuleDestTcpPortWithOtherSrcPort | When you specify destination TCP ports, the source ports should either be empty or contain at least one TCP port | ||||||
Validation | cryptoNonCompliantIkev1PolicyForGroup | The upgraded IKEv1 policies use either of DH groups 1 or 2 which is not supported on this FTD version: {0}. | ||||||
Validation | nestedReferenceCircle | A circular reference is found between nested entity {0} and {1} | ||||||
Validation | snmpHostMaxCount | Max count of SNMP Hosts is 4000. | ||||||
Validation | SSLPolicyNoDecryptCAForResign | You must identify an internal CA certificate to use for decrypt re-sign rules in the SSL decryption policy | ||||||
Validation | bridgeGroupInterfaceReferencedInSyslogServer | The following Interfaces are used in Syslog configuration: {0}. This feature is not compatible with a bridge group member interface. You must remove the interfaces from the configuration before you can add them to the bridge group. | ||||||
Validation | cannotChangeDescriptionOfDynamicDNSTrustedCAGroup | You cannot change the description of Dynamic-DNS-Trusted-CA-Group. | ||||||
Validation | ConfigErrors | There are some configuration errors. Please fix them, deploy the configuration, and proceed with the upgrade. Check the pending changes for items that might need attention. | ||||||
Validation | webCertAlreadyExists | A Web Server Certificate already exists. | ||||||
Validation | DuplicateInstanceName | Duplicate Instance name found. | ||||||
Validation | cannotHaveNullCertForPolicyWithActiveRule | Cannot have a null certificate for Identity Policy which has an active rule | ||||||
Validation | objectUsageInvalidNameParam | Name parameter used in object usages search for type "{0}" is invalid. | ||||||
Validation | hostBlank | Host must not be empty or blank. | ||||||
Validation | RuleGroupCustomIDNotAllowed | Custom rule groups do not support custom IDs. | ||||||
Validation | manualNatDnsNotAllowedWithDest | You cannot enable DNS reply translation when doing destination address translation | ||||||
Validation | cloudRegionUnsupportedMethod | You cannot create, update, or delete cloud regions. | ||||||
Validation | InvalidClassType | Un-supported class type found in rule: {0}. Supported class types for the installed LSP are [{1}]. | ||||||
Validation | sruUpdateError_11 | Not enough disk space on root/Volume | ||||||
Validation | useHostForSingleAddress | Use Host to specify a single address. | ||||||
Validation | manualNatSrc66HostInTransSrcNotAllowedWithSubnetInOrigSrc | The IPv6 host object "{1}" in the translated source is not allowed with an IPv6 subnet object "{0}" in the original source | ||||||
Validation | parentInterfaceIsPassive | You cannot create a subinterface on the Passive interface {0} | ||||||
Validation | adiCliTestUnknownFailure | The connection test failed with an unknown error. | ||||||
Validation | invalidKey | Invalid key. | ||||||
Validation | s2sCryptoRestrictedIkev2Policy | Your licensing setting does not allow to enable IKEv2 policy with strong encryption. Please use DES only | ||||||
Validation | appFilterInvalidCatValue | Invalid application filter category value {0}. | ||||||
Validation | linkLocalIPAddressNotAllowed | The IP address {0} cannot be a link-local address | ||||||
Validation | manualNatStaticRuleEmpty | No network or port translation is specified with static NAT rule | ||||||
Validation | invalidEigrpRouteMapInterfaceVrf | Interface {0} used in route map should belong to the virtual router {1}. | ||||||
Validation | aaaUsernameCannotContainSpaces | Username cannot contain spaces | ||||||
Validation | deleteDepStatusObj | Cannot delete on-going Deployment Status object: {0} | ||||||
Validation | cannotDisableRegenAfterFailure | You cannot disable regeneration deployment mode. There was a deployment failure, and the system must perform a successful full deployment (forceRefreshDeploymentData=true) before partial deployments are possible again. | ||||||
Validation | aaaUpdatingProtocolType | Updating the protocol type for a rule is not supported | ||||||
Validation | staticRouteWrongNetworkType | Wrong network type for static route: {0} | ||||||
Validation | passwordNoNumber | Password does not contain a number | ||||||
Validation | loopbackAddressNotAllowed | The IP address cannot be a loopback address. | ||||||
Validation | DeviceSetupAlreadyDone | The initial device setup is complete. You can now manage the device and change the configuration. | ||||||
Validation | autoNegNotALlowedWithSelectedInterfaceSpeed | AutoNeg cannot be set to True when interface speed is lower than 1g, or interface speed is set at 10g. | ||||||
Validation | AnyConnACPkgInvalid | AnyConnect client package {0} is invalid for the given platform | ||||||
Validation | vtiMaxLimit | You cannot create more than {0} Virtual Tunnel Interfaces. | ||||||
Validation | acRuleUrlCatRepBothNull | URL category and reputation are both any or null in one of the URL matchers | ||||||
Validation | invalidUuid | Validation failed due to an invalid UUID: "{0}" | ||||||
Validation | disabledEtherChannelHAInterface | EtherChannel {0} must be enabled. | ||||||
Validation | snmpInvalidEncryptionAlgorithm | Encryption algorithm can not be null for SNMP users with security level AUTH and PRIV. | ||||||
Validation | contextStatusFailed | Could not retrieve device registration context status. Please try again later. | ||||||
Validation | manualNatOrigDestHasIpv6AndIpv4Addresses | The original destination network should not contain both IPv4 and IPv6 addresses | ||||||
Validation | CannotUpdateSystemDefinedIntrusionPolicy | You cannot update an intrusion policy that is defined by the system. | ||||||
Validation | invalidMalwareLicenseForFileRule | Missing Malware License. A file rule that stores files, or that uses the MALWARE_BLOCK or MALWARE_CLOUD_LOOKUP actions, requires this license. | ||||||
Validation | manualNatSrc46AnyIpv6NotValid | The network corresponding to the full range of IPv6 addresses, i.e. ::/0, cannot be used in the source of an IPv4 to IPv6 manual NAT rule | ||||||
Validation | ipsecNoEnabledIkev1Policies | Cannot disable or delete IKEv1 policy, need at least one policy active while a site-to-site connection profile using IKEv1 exists | ||||||
Validation | invalidEtherChannelHAInterface | EtherChannel {0} must have at least one physical interface member. | ||||||
Validation | FMCHostOrNatIdRequired | Either FMC Host/IP Address or NAT ID is required. | ||||||
Validation | acRuleUnnamedInterfaceInDestZone | Destination security zone {0} contains an un-named interface that cannot be used in an access rule | ||||||
Validation | passwordCannotBeNull | Password field cannot be null | ||||||
Validation | AnyConnProxyExceptListTooLong | All addresses and ports in the proxy exception list combined can be no more than 255 characters | ||||||
Validation | acPolicyInvalidIdentityPolicyWithDisabledRealm | You cannot configure the identity policy with a disabled realm. | ||||||
Validation | AnyConnIOErrorXMLFile | {0} error while reading file. | ||||||
Validation | RaVpnGroupPolicyDeleteDefaultGP | Default Group Policy (DfltGrpPolicy) cannot be deleted. | ||||||
Validation | certKeyTypeEmpty | You must specify whether this file is a certificate or key. Please set the fileType to cert or key. | ||||||
Validation | invalidSlaTimeout | The timeout value has to be between 0 and 604800000 milliseconds (7 days) | ||||||
Validation | manualNatSrc46Ipv6HostObjNotAllowedInTransSrc | You cannot use an IPv6 host network object as the translated source in an IPv4 to IPv6 manual NAT source translation rule: {0} | ||||||
Validation | snmpUsersGroupHostType | User Group as SNMPAuthentication cannot be provided for SNMP Host with v3 security configuration. | ||||||
Validation | InvalidBgpNeighborMigrationRemoteAsBgpAsNumber | Cannot have remote-as number same as BGP AS number. | ||||||
Validation | vdbUpdateError_2 | No valid support contract found. Contact sales or support for more information | ||||||
Validation | natOrigMappedPortsAreNotBothTcpOrBothUdp | The original and translated ports should be either both TCP ports or both UDP ports | ||||||
Validation | duplicateZone | Selected interface is already assigned to security zone {0} | ||||||
Validation | variablesetmodify | Cannot add a new or delete an existing variable. | ||||||
Validation | switchModeNotSupportedOnInterface | Switch mode is not supported on this interface. | ||||||
Validation | ipAddressRangeIsBlocked | The IP address {0} is part of an internally reserved range, (from={1} to={2}), please choose an address outside this range. | ||||||
Validation | invalidBgpRedistribution | Redistribution for {0} is not supported for user defined virtual router. | ||||||
Validation | BinderRuleInstanceInvalid | Instance name/type combo is invalid. | ||||||
Validation | deleteUmbrellaDnsServerGroup | You cannot delete the system-defined CiscoUmbrellaDNSServerGroup object. | ||||||
Validation | InvalidMalwareLicenseForCloudRegistration | Missing Malware License. This license is required for registering with another AMP cloud. | ||||||
Validation | passwordDictWord | Password contains a dictionary word | ||||||
Validation | onlyStandardOrExtendedAccessList | The list should contain either all Standard Access List objects or all Extended Access List objects | ||||||
Validation | invalidThreatLicenseForFilePolicy | Missing Threat License. The associated file policy or rule requires this license. | ||||||
Validation | snort3IntrusionRuleNotFound | Can not find the intrusion rule {0} for the current version. | ||||||
Validation | objectNat46Ipv6HostObjNotAllowedInTransAddr | You cannot use an IPv6 host network object as the translated address in an IPv4 to IPv6 auto NAT rule: {0} | ||||||
Validation | manualNatDest64PrivateIpv4IsNotAllowedWithNat46WellKnownPrefix | The private IPv4 address "{1}" in translated destination "{0}" is not allowed with the well known NAT64 prefix "64:ff9b::" in the original destination | ||||||
Validation | acRuleMixedIpv4v6AddressInDestNetworks | Destination networks contain both IPv4 and IPv6 addresses | ||||||
Validation | cloudRegionIsRequiredForEnrollment | You should specify the cloud region when enrolling with the cloud. | ||||||
Validation | policyRuleIdNotEditable | The policy rule ID cannot be modified by editing the rule. Current rule-ID in the DB is {0}, rule-ID from request is {1} | ||||||
Validation | AnyConnNoCAServerCert | CA Server certificate is required | ||||||
Validation | invalidToken | The format of the provided token is invalid. The length of the token must not exceed 140 characters | ||||||
Validation | RangeInvalidStart | Invalid Start Address | ||||||
Validation | invalidOspfAreaTypeVLConfiguration | Virtual link cannot be configured on areas of type NSSA or Stub | ||||||
Validation | cannotCreateFMCRegistrationSettingsInHAMode | Your device has HA enabled. HA is not supported with this feature. | ||||||
Validation | manualNatDest46Ipv6HostCountTooHigh | The IPv6 host count {0} in the translated destination exceeds the maximum allowed {1} in an IPv4 to IPv6 manual NAT destination translation | ||||||
Validation | invalidLoggingListProvideStartId | Please provide message start ID. | ||||||
Validation | manualNatDest64Ipv6RangeObjNotAllowedInOrigDest | You cannot use an IPv6 range network object as the original destination in an IPv6 to IPv4 manual NAT destination translation rule: {0} | ||||||
Validation | invalidSecretKey | Secret Key field should contain only Alpha-Numeric characters with length equals 40. | ||||||
Validation | RuleNameMustUnique | A custom rule: {0} with same GID:SID already exists in the database, rule creation failed. | ||||||
Validation | smartAgentMakingAlreadyInProgress | Smart Agent making already in progress. | ||||||
Validation | invalidSyslogProtocol | Invalid protocol for Syslog Server. Protocol must be either TCP/UDP. | ||||||
Validation | invalidQualifiedPath | "{0}" is not a valid qualified path. A quailified path must resemble a file path beginning with a forward slash and can have alphabets, numbers, underscore, or forward slash. | ||||||
Validation | attemptToChangeNoneditSubInterfaceId | Validation failed, attempt to change a non-editable subinterface ID | ||||||
Validation | invalidDHCPRelayInterface | Interface used for DHCP Relay Service is null. | ||||||
Validation | invalidOspfInterfaceBviSelected | You cannot enable OSPF on a bridge group or bridge group member interface. | ||||||
Validation | ftdUpdateMgrError_238 | Cancel upgrade in progress. Cannot retry. | ||||||
Validation | s2sOutsideIntfNotNamed | Site-to-Site VPN outside-interface does not have logical name: {0} | ||||||
Validation | invalidObjectForNotInDHCPRelayInterfaceAnnotation | Validation could not be performed successfully. Field is not of the correct type for annotation. | ||||||
Validation | unsupportedMemberInterfaceType | Member interfaces in EtherChannels can only be physical interfaces. | ||||||
Validation | cleanOrCustomListFileInvalidEntries | Invalid entries. Each entry should contain a single SHA-256 value followed by a description. | ||||||
Validation | RaVpnConnectionProfileExists | There is one or more RAVPN Connection Profile(s) still on the device. Please remove all of them before removing RAVPN configuration. | ||||||
Validation | cleanOrCustomListFileInvalidType | Invalid file type. The uploaded file must be a simple text file with a .csv file name extension and with entry containing a single SHA-256 value followed by a description. | ||||||
Validation | invalidTemplate | The template "{0}" is invalid. The name can start with an alphanumeric character or an underscore. It can contain the special characters +, ., _, -, '{{', and '}}' | ||||||
Validation | packageDownloadSuccess | Pre-toggle update succeeded. | ||||||
Validation | ftdUpdateMgrError_241 | Upgrade was interrupted by system restart. Use the 'upgrade cancel' API to cancel. | ||||||
Validation | invalidHAFailoverPeerPollTime | Peer poll time must be between 200 and 999 milliseconds, or 1 and 15 seconds. | ||||||
Validation | securityIntelligenceBlacklistPolicyUnsupportedNetwork | The Security Intelligence Block list contains an unsupported network : {0} | ||||||
Validation | natTranslatedDestNetworkObjNotSupported | The translated destination does not support this network object. | ||||||
Validation | interfaceMigrateSourceAndDestinationCannotBeMembersOfVlanInterface | Source and destination IDs cannot belong to members of a VLAN Interface. | ||||||
Validation | staticRouteNetworkAddressMatchesInterfaceAddress | This IP address is associated with the Static Route and can not be the same as IP address of the interface {0}. | ||||||
Validation | AnyConnAuthMethodMustBeAAAAndClientCertificate | Auth method must be {0} for Prefill username from certificate on user login window | ||||||
Validation | resetCannotBeTrueWithRuleAction | File Rule validations failed. Reset can be true only for BLOCK_FILES and MALWARE_BLOCK rule actions. | ||||||
Validation | moreThanOneISE | You cannot create more than one ISE configuration | ||||||
Validation | CryptoRestrictedSSLCipher | Data SSL Cipher Settings uses SSL Ciphers with strong encryption, which is not allowed by your licensing setting. | ||||||
Validation | geoUpdateError_7 | Peer certificate cannot be authenticated with known CA certificates | ||||||
Validation | intfMigrationExportFailed | Failed at export step. Unable to export the configuration due to error {0} | ||||||
Validation | snmpServerNameCannotBeUpdated | SNMP Server name can not be updated. | ||||||
Validation | s2sVTIOnly1Allowed | If you enable static VTI, you must select a single interface for a site-to-site VPN connection. | ||||||
Validation | vtiMTUMustBeSameAsSourceMTU | The MTU value for a VTI must be the same as the MTU value for the associated tunnel source interface, which is {0}. | ||||||
Validation | invalidSmartCliPrefixListValue | {0} entity value must be an existing IPv4 or IPv6 Prefix List Object | ||||||
Validation | acPolicyDefaultActionIsNull | The access policy default action setting is null | ||||||
Validation | containsInvalidChar | the field cannot contain the following character ';' | ||||||
Validation | redundantTokenForEnrollmentViaSmartLicense | You should not specify the token when enrolling with the cloud using Smart License. | ||||||
Validation | manualNatSrc64Ipv6PrefixTooShort | The original source IPv6 network prefix length must be greater than or equal to 64 in an IPv6 to IPv4 manual NAT source translation: {0} | ||||||
Validation | invalidSmartCliBooleanValue | {0} value must be set to either true or false | ||||||
Validation | anyIPWithoutPrefix | The IP address requires a prefix. | ||||||
Validation | invalidFlexCliUnsupportedAsciiText | Non-printable ASCII text detected. If you are using copy/paste, some hidden ASCII characters might be included. Please try a different source editor, or type in the required text | ||||||
Validation | dadIsOutOfRange | DAD (Duplication Address Detection) attempts must be between 0 and 600 | ||||||
Validation | removedInterfaceCannotBeEnabled | Interface {0} is no longer present and cannot be enabled | ||||||
Validation | staticRouteWrongOptionalGateway | Gateway is mandatory when the egress interface belongs to the same virtual router as route you are defining. | ||||||
Validation | cryptoNonCompliantIkev1ProposalForAuthMethod | The upgraded IKEv1 proposals use ESP_MD5_HMAC authentication which is not supported on this FTD version: {0}. | ||||||
Validation | invalidEigrpIpv4Address | Only IPV4 networks are allowed. | ||||||
Validation | dhcpAutoConfigEnabled | DHCP Relay Agent cannot use the same interface {0} used for DHCP Server auto-config. | ||||||
Validation | commonInterfaces | Both a DHCP Relay Agent and a Server cannot be configured on the same interface {0}. DHCP Relay service cannot receive DHCP requests and forward them on the same interface. | ||||||
Validation | bridgeGroupInterfaceMemberEmptyName | Bridge Group interface member {0} cannot have empty name | ||||||
Validation | AnyConnDnsInvalid | {0} is not a valid IP and not a valid DNS server | ||||||
Validation | interfaceNameEmptyForMonitoring | You can monitor an interface only if the interface has a name. | ||||||
Validation | DuplicateEntry | Duplicate entry found for Intrusion Rule with ID {0}. | ||||||
Validation | SecurityIntelligenceDNSPolicyBlacklistContainsWhitelistItem | DNS policy Block rules cannot contain Do Not Block rules. | ||||||
Validation | networkInterfaceModuleFieldsReadOnly | You cannot edit the read-only fields of the Network Interface Module. You may only edit the enabled field for the Network Interface Module. | ||||||
Validation | sruUpdateError_7 | Peer certificate cannot be authenticated with known CA certificates | ||||||
Validation | SystemDefinedRuleGroupNotAllowed | Cannot associate a custom rule with system-defined rule group: {0}. | ||||||
Validation | bgpGracefulRestartTimeWithoutGracefulRestart | Graceful restart should be enabled before setting restart time | ||||||
Validation | broadcastAddressNotAllowed | You cannot assign a broadcast address as the IP address of an interface. | ||||||
Validation | interfaceCombineNeedsDeployment | Interface {0} has pending changes. You must deploy the changes before you can combine it. | ||||||
Validation | invalidAAARadiusMaxFailedAttempts | Max Failed Attempts must be in the range 1 to 5 | ||||||
Validation | acRuleTimeRangeObjectInvalidSize | Only one TimeRange Object should be associated with an ACL policy. | ||||||
Validation | multicastAddressNotAllowedAsFMCHost | FMC Host of "{0}" cannot be a multicast address. | ||||||
Validation | bridgeGroupMemberInterfaceReferencedInVirtualRouter | The following interfaces are referenced by Virtual Router: {0}. This feature is not compatible with a bridge group member interface. You must remove them before you can add the interfaces to a bridge group. | ||||||
Validation | nullValue | Value cannot be null. | ||||||
Validation | ipsecCryptoRestricted | Usable cryptography types are currently restricted by the licensing status of the device | ||||||
Validation | missingCertificates | Missing the following certificate from the trust chain: {0} | ||||||
Validation | haMandatoryDeploymentNeeded | Before attempting {0}, you must complete a successful deployment job. | ||||||
Validation | dnsServersMaximumLimit | A maximum of two IPv4 and two IPv6 DNS servers is allowed. | ||||||
Validation | ftdUpdateMgrError_133 | Update type missing or invalid. | ||||||
Validation | invalidNatId | NAT ID of "{0}" is invalid. It can start with an alphanumeric character or an underscore. It can contain the special characters +, ., _ and - | ||||||
Validation | snort3ToggleSuccessWithUpdate | Successfully switched to Snort version 3 with rule package updated. | ||||||
Validation | DHCPServerAutoConfigServer | You cannot define a DHCP server on the same interface used for the auto config default interface: {0} | ||||||
Validation | invalidSlaId | ID value must be between 1 and 2147483647. | ||||||
Validation | s2sDupBackupPeerIpAddr | Duplicate IP address found in two or more backup peers. Provide unique backup peer addresses. | ||||||
Validation | RACPrfInsideIntfHasNoName | The interface {0} added to RaVpn should have a logical name. | ||||||
Validation | manualNatRouteLookupAndIntfInTransSrc | You cannot select the Perform Route Lookup option if you select interface for translated source | ||||||
Validation | duplicateTunnelID | Tunnel ID {0} is already used by tunnel "{1}" | ||||||
Validation | AccessRulesWithDeletedCategories | Some of the access rules refer to deleted URL Categories. Number of access rules affected: {0}. | ||||||
Validation | invalidAuthType | Invalid authentication type in identity rule. Only Basic, NTLM, Negotiate and Response page methods are supported. | ||||||
Validation | insufficientDiskSpace | Insufficient disk space. | ||||||
Validation | vdbUpdateError_13 | Unable to update VDB database, please retry the update | ||||||
Validation | interfaceUsedInAAA | Interface name cannot be empty. It is used in RADIUS server "{0}" | ||||||
Validation | SSLRuleNullEventLogAction | You must specify an event logging action for the SSL rule | ||||||
Validation | dupliacteTemplateIdentifier | A template with same identifier already exists. {0} | ||||||
Validation | invalidSmartCliEnumValuesNull | Allowed enum values cannot be null or empty | ||||||
Validation | invalidFlexCliMissingVariable | Referenced variable {0} is not configured | ||||||
Validation | manualNatTranslatedDestHasIpDNSMismatchWithTranslatedSrc | The DNS resolution for the FQDN used in the translated destination must include an IP address of the same version (IPv4 or IPv6) as the translated source address | ||||||
Validation | NoRuleImportFile | You must specify a file to upload. | ||||||
Validation | acRuleMixedIpv4v6AddressInSrcNetworks | Source networks contain both IPv4 and IPv6 addresses | ||||||
Validation | bgpInvalidHoldTime | Hold time should be greater than keep alive time | ||||||
Validation | haDeploymentCouldNotAutoRecover | Could not auto-recover, check logs for details. Please retry {0} deployment. | ||||||
Validation | interfaceBreakoutCreate | An error occurred while breaking out Network Module interface {0} | ||||||
Validation | invalidSlaNumOfPackets | The number of packets has to be between 1 and 100. | ||||||
Validation | connectorGenerateTokenError | Connector token was not generated. | ||||||
Validation | bridgeGroupInterfaceInvalidCreation | Cannot create more than one Bridge Group Interface. Please delete the existing one before creating a new Bridge Group Interface. | ||||||
Validation | interfaceInDHCPServerOverlapsNetwork | The following interfaces have overlapping subnets and a DHCP server is already configured on one of them: {0} | ||||||
Validation | regexPatternNotUnique | Regular expression pattern should be unique across all entries. | ||||||
Validation | interfaceInDHCPRelayService | The interface {0} is already configured as part of the DHCP Relay Service. You must remove it before adding it to a bridge group. | ||||||
Validation | s2sCryptoRestrictedIkev1Policy | Your licensing setting does not allow to enable IKEv1 policy with strong encryption. Please use DES only | ||||||
Validation | invalidOspfExceededLimit | Only two OSPF processes are allowed per virtual router | ||||||
Validation | invalidSmartCliDependentEnabled | You cannot enable a dependent command when the parent command is disabled | ||||||
Validation | intfMigrationExportUnableToCreateSqliteFile | Unable to create the sqlite file. | ||||||
Validation | cryptoNonCompliantIkev2PolicyForGroup | The upgraded IKEv2 policies use either of DH groups 1, 2 or 24 which is not supported on this FTD version: {0}. | ||||||
Validation | subinterfacesCannotContainAnotherSubinterface | A subInterface cannot contain another subInterface. | ||||||
Validation | diskFileNameIncorrectExt | Disk file name extension is not {0}: {1} | ||||||
Validation | invalidSmartCliIPV6PrefixListValue | {0} entity value must be an existing IPv6 Prefix List Object | ||||||
Validation | s2sBackupPeerIkev1InvalidKey | Invalid IKEv1 pre-shared key. It must contain 1-128 ASCII printable characters, no whitespace, no single or double quotation marks, no question marks and cannot be a single digit | ||||||
Validation | createWithUuid | Validation failed, attempting to create a new object while specifying a UUID | ||||||
Validation | wrongObjectUsagesTypeParam | Type parameter is of the wrong class type. | ||||||
Validation | cannotCreateWithUnnamedInterface | You cannot create or edit an identity realm object to contain a directory configuration using unnamed interface. | ||||||
Validation | RuleGroupOverrideSecurityLevelNotAllowed | Custom intrusion rule group must not include an override security level. | ||||||
Validation | acRuleSrcUdpPortWithOtherDestPort | When you specify source UDP ports, the destination ports should either be empty or contain at least one UDP port | ||||||
Validation | missingRealmInPassiveAuthIdentityRule | No realm found in an identity rule that uses the Passive Auth action. | ||||||
Validation | AnyConnProxyServerNull | Proxy Server Address/host cannot be null | ||||||
Validation | DHCPServerSecondaryWINSOnly | DHCP server secondary WINS server cannot be specified unless a primary WINS server is also specified | ||||||
Validation | unsupportedIkevOneGroup | The following Diffie-Hellman groups are not supported in IKEv1 policies: 1, 2. | ||||||
Validation | CanNotUpdateAParentGroup | You cannot update a parent group:{0} | ||||||
Validation | objectNat66HostInTransAddrNotAllowedWithSubnetInOrigAddr | The IPv6 host object "{1}" in the translated address is not allowed with an IPv6 subnet object "{0}" in the original address | ||||||
Validation | bgpInvalidASNumberUpdated | Cannot change as-number when editing BGP protocol | ||||||
Validation | deploymentInProgress | Could not initiate upgrade: deployment is in progress. Please wait for deployment to finish, then try again. | ||||||
Validation | dhcpEnabled | DHCP Relay Service cannot be enabled if the DHCP Server feature is also enabled on any interface. | ||||||
Validation | invalidLoggingListRangeCollision | Message ID/range overlaps with existing range. | ||||||
Validation | AnyConnDnsMissing | At least one DNS has to be provided for AnyConnect VPN profile | ||||||
Validation | smartAgentManagerCannotBeRemade | SmartAgentManager cannot be remade | ||||||
Validation | updateCertAndKey | You must update both certificate and private key. | ||||||
Validation | interfaceMigrateDestinationMustBePresent | Destination ID must belong to a present interface. | ||||||
Validation | s2sLifetimeSec | Site to Site profile Lifetime Range should be between 120 and 2147483647 seconds | ||||||
Validation | noIntrusionRuleFound | Cannot find a intrusion rule with provided UUID. | ||||||
Validation | vlanInterfaceNotAllowedWhenSecurityZoneInPassive | Security zone in passive mode cannot have VLAN interfaces associated with it. | ||||||
Validation | acPolicyInvalidDefaultActionWithNullIps | Invalid default action {0}, only Block or Trust is allowed without intrusion inspection | ||||||
Validation | duplicateOrdinal | Validation failed due to duplicate Ordinal | ||||||
Validation | s2sInsideIntfNotNamed | Site-to-Site VPN inside interface for NAT exempt does not have a logical name | ||||||
Validation | ipsecDupIkev2Integrity | Cannot have duplicate integrity methods | ||||||
Validation | invalidV6StartMapped | IPv4-mapped IPv6 as start address is not supported. | ||||||
Validation | AnyConnNullRealmEncryptionType | Realm server encryption type cannot be null | ||||||
Validation | unsupportedNGFWInterfaceDuplex | Unsupported NGFW Interface Duplex on SSP platform | ||||||
Validation | cannotMoveContainedEntityToDifferentContainer | The contained entity cannot be moved to a different container in an update request | ||||||
Validation | IOCSystemDefinedNAPUpdate | You cannot update the inspector override config of a TALOS defined Network Analysis Policy. | ||||||
Validation | upgradeCancelOnFailureNotAvailable | Parameter {0} is not available for this upgrade image. | ||||||
Validation | invalidFlexCliLineBlacklist | Block list CLI error: {0} | ||||||
Validation | DHCPIntfModeIsPassive | You cannot configure a DHCP server on a passive mode interface. | ||||||
Validation | invalidObjectForNotMemberInterfaceAnnotation | Validation could not be performed successfully due to a server issue. Please reach Cisco Technical Support. | ||||||
Validation | contextDeletionFailed | Unregistration process failed. Please try again later. | ||||||
Validation | noRetryScript | The script to retry upgrade is not available at this stage. | ||||||
Validation | incompatibleStartEndAddress | Start and End Addresses must be the same IP type. | ||||||
Validation | realmIdChanged | The realm ID cannot be modified | ||||||
Validation | AnyConnOutsideIntfInDIMA | The selected outside interface is currently being used in a management access list and cannot be simultaneously used for AnyConnect VPN | ||||||
Validation | s2sRRIMulitpleInterface | Reverse Route cannot be enabled on multiple interfaces | ||||||
Validation | DapXmlUserMssgInvalid | DAP user message cannot exceed more than 490 characters | ||||||
Validation | invalidAAARadiusGroupDeadtime | Dead Time must be between 0 and 1440 minutes | ||||||
Validation | invalidOspfDuplicateBackbone | A backbone area already exists in the configuration | ||||||
Validation | RaVpnGPSplitDomainsRequired | Split DNS Domains have to be specified. | ||||||
Validation | certificateKeyMismatch | Certificate and Private key do not match | ||||||
Validation | vdbUpdateError_0 | VDB successfully updated | ||||||
Validation | ntpNotFound | Cannot find NTP settings. | ||||||
Validation | invalidFMCConnectivityInterfaceType | Invalid type of interface selected. | ||||||
Validation | objectNat64Ipv6PrefixTooShort | The original address IPv6 network prefix length must be greater than or equal to 64 in an IPv6 to IPv4 auto NAT rule: {0} | ||||||
Validation | manualNatDest66TransDestPrefixShorterThanOrigDestPrefix | The IPv6 prefix of the translated destination subnet "{0}" must be greater than or equal to the IPv6 prefix of the original destination subnet "{1}" | ||||||
Validation | Neo4JConfFileParsingFailed | Configuration file for neo4j was either not found or there was a failure while parsing it. | ||||||
Validation | AnyConnServerCertNeedsSubjectCommonName | The Server certificate {0} requires subject common name | ||||||
Validation | SSLRuleTls13OnlyOnSnort3 | TLS 1.3 requires Snort version 3 | ||||||
Validation | baseRealmDisabled | The realm used in the identity rule has been disabled. | ||||||
Validation | missingUuid | Validation failed due to an invalid UUID: null | ||||||
Validation | vpnOnlyWithPlusOrApex | VPN-only license cannot be enabled with PLUS or APEX | ||||||
Validation | interfaceIsMemberOfBGI | Interface {0} cannot be a member of a Bridge Group Interface and be used by DHCP Relay Service at the same time. | ||||||
Validation | invalidRegistrationKey | Registration Key of "{0}" is invalid. It can start with an alphanumeric character or an underscore. It can contain the special characters +, ., _ and - | ||||||
Validation | PullFileExtensionFailed | This file extension {0} is not supported for the given fileType {1}. | ||||||
Validation | invalidVariableSetInstance | Instance does not match with the template it uses. Found mismatch in the properties "{0}" of SmartCLIVariableSet having qualifiedPath "{1}". | ||||||
Validation | staticRouteInconsistentNetworkProtocol | Static route inconsistent protocol version for network: IPv4 vs IPv6 {0} | ||||||
Validation | noPcbSerialNumber | Cannot register because serial number is unavailable; try again. | ||||||
Validation | haLinkNotOnSameSubnet | The primary and secondary addresses of {0} must be on the same subnet. | ||||||
Validation | deviceMustBeSmartLicensed | Device must be Smart Licensed when enrolling with {0} account. | ||||||
Validation | AnyConnExcessPackages | Can have only one AnyConnectPackages | ||||||
Validation | missingRealmInActiveAuthIdentityRule | No realm found in an identity rule that uses the Active Auth action. | ||||||
Validation | unsupportedIkevTwoGroup | DH Groups DH1, DH2 and DH24 are not supported in IKEv2 Policies. | ||||||
Validation | ftdUpdateMgrError_131 | Invalid update mode. | ||||||
Validation | manualNatSrc46Ipv4AnyIsNotAllowedWithNat46WellKnownPrefix | The original source cannot be IPv4 "any" with the well known NAT46 prefix "64:ff9b::" in the translated source | ||||||
Validation | NoValidAction | Un-supported rule action [{0}] found in rule: {1}. Supported rule actions are ALERT and DROP. | ||||||
Validation | IntrusionRuleGroupNotFoundWithName | Unable to find the IntrusionRuleGroup with name: {0}. | ||||||
Validation | appFilterInvalidProductivityName | Invalid application filter business relevance name {0}. | ||||||
Validation | RuleGroupHasOrphanRuleHasOverride | Failed to delete Intrusion Rule Group: {0}. With cascadeDelete option, rule group along with rules that only belong to this group are deleted. Remove overridden state from rules before deletion. | ||||||
Validation | expiredCertificatePaste | The certificate has already expired. Please enter an unexpired certificate. | ||||||
Validation | indexListSizeIncorrect | Error when getting the indices of the filtered container objects. | ||||||
Validation | couldNotInitializeUpgrade | Could not initiate upgrade. | ||||||
Validation | sruUpdateError_1 | Connectivity problems. Unable to download the rule update. Please try again later. | ||||||
Validation | invalidObjectForNotHaInterfaceAnnotation | Invalid object type for NotHAInterface annotation. | ||||||
Validation | invalidSyncType | This is an invalid value for syncing. If you would like to sync, please set sync to be true | ||||||
Validation | unsupportedFecMode | Forward Error Correction mode {0} is not supported on this platform. | ||||||
Validation | passwordNoSpecial | Password does not contain a special character | ||||||
Validation | invalidEmptyFqdn | The fully-qualified domain name is empty. Please specify a name. | ||||||
Validation | NapNotSupportedInSnort2 | Network Analysis Policies are not available in Snort 2. | ||||||
Validation | lspInstallScriptMissing | Failed to locate an install script for LSP package installation. | ||||||
Validation | invalidSmartCliNetworkValue | {0} entity value must be an existing NetworkObject or NetworkObjectGroup | ||||||
Validation | etherChannelDuplexMatchMemberInterfaceDuplexCapability | EtherChannel duplex must match member interface duplex capability. | ||||||
Validation | invalidInterfaceForPolicyList | A policy list cannot include passive interfaces or bridge group member interfaces or an interface which is part of the high availability configuration. | ||||||
Validation | invalidIntegrationObject | Integration target object is inValid. | ||||||
Validation | DHCPServerInvalidName | DHCP server is already configured on this interface: {0} | ||||||
Validation | manualNatDest64DynamicNotAllowed | Dynamic NAT is not allowed in a manual NAT rule for IPv4 to IPv6 destination address translation | ||||||
Validation | duplicateValidationUsage | Validation usages should not contain duplicates. | ||||||
Validation | bridgeGroupInterfaceMemberHasDHCPIpv4Address | Bridge Group interface member {0} cannot contain a DHCP IPV4 address | ||||||
Validation | invalidConnectionTypeUpdate | Connection type can be updated only in Evaluation Mode. For other cases you have to unregister and register with a desired connection type. | ||||||
Validation | UnlockDeviceProvidedEulaIsNotCorrect | The provided End User License Agreement does not match with the End User License Agreement from the server. | ||||||
Validation | natDynamicRuleNotSupportRouteLookup | Dynamic NAT does not support the Perform Route Lookup option | ||||||
Validation | performanceTiersNotSupported | Performance Tiers are not supported on current platform | ||||||
Validation | facAddPerlGeneralError | An unexpected error occurred while creating a Firepower Analytics Center entity | ||||||
Validation | duplicatesClasses | Duplicate classes: {0} are not allowed. | ||||||
Validation | attemptToChangeNoneditVlanInterfaceId | Validation failed, attempt to change a non-editable vlan interface ID. | ||||||
Validation | bgpInvalidASNumber | The AS number in BGP should be same as AS number configured in BGP General Settings. | ||||||
Validation | XmlConfigNotBase64Encoded | XML configuration must be Base64 encoded | ||||||
Validation | geoUpdateError_0 | GeoDB successfully installed | ||||||
Validation | InvalidPredefinedUserVrfName | Virtual Router with name {0} is predefined and cannot be used. | ||||||
Validation | eciMemberInterfacesCannotHaveSubInterfaces | EtherChannel member interfaces cannot contain physical interfaces that have subinterfaces. | ||||||
Validation | RaVpnSpecialIdentityNotAllowed | Special-Identities-Realm not allowed as IdentitySource for RAVPN. | ||||||
Validation | ipsecEmptyIkev2Encryption | There must be at least one method of encryption | ||||||
Validation | timeRangeInvalidDailyInterval | The daily interval specification is incomplete. To configure a daily interval, you must specify the days, the daily start time, and the daily end time. | ||||||
Validation | vtiIPv6NotSupported | IPv6 is not supported on this interface, please remove the ipv6 field and try again. | ||||||
Validation | activeAuthCertInvalidStartEndDate | The value or format of the start or end date of the uploaded certificate is invalid | ||||||
Validation | SSLRuleNeedVersion | Need at least one SSL/TLS version checkbox selected | ||||||
Validation | emptyGroup | A group should contain at least one object. | ||||||
Validation | bridgeGroupInterfaceMemberHasIpv4Address | Bridge Group interface member {0} cannot contain IPV4 address | ||||||
Validation | cryptoCompliantS2SIkev1Proposal | The S2S VPN connection profile {0} is using IKEv1 proposals with strong encryption which is not allowed by your licensing setting, please de-reference them and use DES only: {1} | ||||||
Validation | interfaceCannotHaveIpv4AddressOfBgpNeighbor | An interface cannot have the same IPv4 address as a neighbor in BGP. | ||||||
Validation | invalidOspfBackboneArea | A backbone area cannot be of type nssa or stub | ||||||
Validation | DapXmlRecordNameInvalid | DAP record name must be between 4 and 64 characters | ||||||
Validation | mntCertNotFound | MNT Certificate not found. | ||||||
Validation | lockInvalidLock | Attempting to acquire an invalid lock: "{0}" | ||||||
Validation | unsupportedIkevTwoEncryptionStrong | The following encryption algorithms are not supported in IKEv2 policies when strong encryption is enabled: DES. | ||||||
Validation | sruUpdateError_3 | The update server did not have a file applicable to this device. Try again later. If the problem persists, contact Technical Support. | ||||||
Validation | IntfTypeInvalid | A virtual router can include physical or subinterfaces only. Interface {0} is of an unsupported type. | ||||||
Validation | unsupportedMethodForCurrentDelegate | The following method is not supported for this Smart Agent Delegate. | ||||||
Validation | adminFecCanBeSetOnlyToAutoWhenAutoNegIsEnabled | Updating interface {0} FEC mode to a different value than AUTO is not allowed when auto negotiation is enabled. | ||||||
Validation | unsupportedIkevTwoIntegrity | The following integrity hashes are not supported for IKEv2 Policies: MD5. | ||||||
Validation | SecurityIntelligenceDNSPolicyNoFeedProvided | You must specify at least one DNS object (feed, category, or list) on a DNS rule. | ||||||
Validation | nullBgpNeighborFilteringMaximumPrefixLimitOption | Neighbor Maximum Prefix Option can not be null. | ||||||
Validation | packageOutOfDate | Uploaded package version is lower than the one present on device. Skipping upload. | ||||||
Validation | lspVersionLowerThanMin | LSP installation failed because the candidate package has a lower version than the minimum compatible version[{0}] allowed by the current system software. | ||||||
Validation | invalidGateway | The Gateway entered is invalid | ||||||
Validation | invalidOspfRedistOspfSelfIdentifier | Identifier cannot be Process ID of the same OSPF process | ||||||
Validation | ipsecEmptyIkev2Integrity | There must be at least one method of integrity checking | ||||||
Validation | failedToExportPendingChangesToFile | Unable to export pending changes to the file. | ||||||
Validation | networkAddressNotAllowed | You cannot assign a network address "{0}/{1}" as the IP address of an interface. | ||||||
Validation | manualNatSrcIntfIpv6DisabledWithIpv6InOrigDest | Source interface "{0}" is not IPv6 enabled. You cannot use IPv6 addresses in the original destination | ||||||
Validation | invalidOspfAreaRange | 0.0.0.0/0.0.0.0 represents default and cannot be added as a range | ||||||
Validation | sysInfoFileNotFound | Unable to find file {0} | ||||||
Validation | postUpgradefeaturelistChanged | The featureList in PostUpgradeFlags cannot be modified. | ||||||
Validation | PullUpgradeInitiated | Pull upgrade job initiated | ||||||
Validation | raVpnConnectionProfileDhcpServerMaxLimit | A maximum of 10 DHCP servers is allowed. | ||||||
Validation | geoUpdateError_16 | This version of GeoDB is already installed. | ||||||
Validation | SSLPolicyAppMustHaveSSL | SSL rule cannot contain applications that do not use SSL | ||||||
Validation | invalidSmartCliIPV4PrefixListValue | {0} entity value must be an existing IPv4 Prefix List Object | ||||||
Validation | ftdUpdateMgrError_243 | Retry is not allowed. Contact Cisco TAC. | ||||||
Validation | httpsPortCannotConflictSshPort | HTTPS Port cannot conflict with default SSH port value 22. | ||||||
Validation | bridgeGroupInterfaceCannotHaveIpv4AddressOfBgpNeighbor | This IPv4 address is part of a neighbor that is being used in the BGP configuration. You cannot assign the same IPv4 address to a bridge group interface. | ||||||
Validation | invalidMetricsGroups | At least one metrics group should be configured. | ||||||
Validation | haBreakFromConfig | The units in this HA pair are synchronizing configuration. You cannot execute {0} until synchronization is complete. | ||||||
Validation | invalidLoggingListParams | Please provide either log level or message ID. | ||||||
Validation | invalidSmartCliRouteMapValue | {0} entity value must be an existing Route Map Object | ||||||
Validation | s2sVTIMaxUniqueIpsecProfiles | You cannot create more than {0} unique IPSec profiles. Uniqueness is determined by the combination of IKEv1/v2 proposals and certificates, connection type, DH group and SA lifetime. You can reuse existing profiles. | ||||||
Validation | s2sIkev2NoEnabledPolicy | Cannot enable site-to-site IKEv2 without enabling any IKEv2 policy | ||||||
Validation | PullUnknownError | Some unknown error occured | ||||||
Validation | IntrusionRuleOverrideStateCannotBeNull | You must specify an override state. | ||||||
Validation | CannotDeleteNap | You cannot delete a Network Analysis Policy. | ||||||
Validation | ipsecMixedCombinedNormalEncryption | Cannot mix combined mode (GCM) and normal mode encryption in an IKEv2 policy | ||||||
Validation | ecmpZonesWithIdentityRules | You should configure the same Identity Rules to all ECMP Traffic Zone member interfaces. Interfaces from ECMP Traffic Zones: "{0}" should be applied the same Identity Policies. Please make sure you configure ECMP Traffic Zones/Identity Rules accordingly. | ||||||
Validation | InvalidBasePolicySet | The Base Policy Set for the Intrusion Policy is not a Cisco TALOS defined policy | ||||||
Validation | operationalLinaCommandError | Error while running the configuration command {0}. Response is: {1}. | ||||||
Validation | noRollbackAvailable | Cancel upgrade is not available at this stage. | ||||||
Validation | invalidMetricsName | Validation failed due to invalid metric-name. | ||||||
Validation | cdoTokenNotNullIfActionNullOrAutoEnrollNetworkParticipation | Cisco Defense Orchestrator token should be null if action is 'null' or 'AUTO_ENROLL_NETWORK_PARTICIPATION' | ||||||
Validation | interfaceFieldReadonly | {0} is not user configurable, You cannot edit the read-only fields of the Interface. | ||||||
Validation | sruUpdateError_2 | No valid support contract. Unable to download the rule update | ||||||
Validation | cannotDeleteRealm | Cannot delete any realm | ||||||
Validation | AnyConnNoRealmServer | Realm server is required | ||||||
Validation | intfMigrationViolationsExist | Violations in {0} object(s). Use API explorer to get the entire list of violations against each object for this task. | ||||||
Validation | unableToInstallReservationWhileReservationAlreadyInstalled | A reservation is already installed on this device. You cannot install the reservation again. | ||||||
Validation | expiredCertificateMgmtWebServer | The chosen certificate has already expired. Please apply an unexpired certificate. | ||||||
Validation | vtiSourceCannotBeInUserVRF | Cannot have a virtual tunnel interface with tunnel source interface "{0}" as the source interface is part of a user VRF. | ||||||
Validation | interfaceIsDHCPClient | DHCP Relay Agent cannot use the interface {0} since it is currently configured as a DHCP client. | ||||||
Validation | invalidApplicationProtocolForUpload | File Rule validations failed. SMTP application protocol supports only UPLOAD direction of transfer. | ||||||
Validation | invalidFileTypeAndFileTypeCategory | File Rule validations failed. None of the file types or file type categories are supported by the specified attributes. | ||||||
Validation | managementInterfaceCannotBeDisabled | You cannot disable the Management interface | ||||||
Validation | pxGridCertNotFound | pxGrid Certificate not found. | ||||||
Validation | CannotFindNapByUuid | Network Analysis Policy specified by uuid {0} could not be found. | ||||||
Validation | SAMLSignAndCert | If a signature type is specified, an FTD certificate must be identified in order to perform signature. | ||||||
Validation | invalidV6Compatible | IPv4-compatible IPv6 addresses are not supported. | ||||||
Validation | AnyConnInvalidAuthenticationIdentitySource | You must select an identity realm or radius group as the authentication identity source if you select Local as the fallback identity source. | ||||||
Validation | timeZoneInvalidTime | The DST day recurrence specification is incomplete. To configure a dstDayRecurrence, you must specify the startTime and endTime where start time must be prior to the end time in the format HH:MM. | ||||||
Validation | s2sBackupPeerIkev1MaskedKeyNotAllowed | Masked value for IKEv1 pre-shared key is not allowed when creating a new backup peer or updating the IP address for an existing backup peer. | ||||||
Validation | invalidRegexPattern | The regular expression pattern is not valid. The pattern must not contain any question marks, or spaces. | ||||||
Validation | ecmpZoneWithConfigAccessRules | You should apply the same Access Rules to all ECMP Traffic Zone member interfaces. Interfaces from ECMP Traffic Zones: "{0}" should have the same Access rules. Please make sure you configure ECMP Traffic Zones/Access Rules accordingly. | ||||||
Validation | invalidFMCConnectivityInterfaceNoIP | Cannot configure on interfaces without IP address. Assign an IPv4 or IPv6 address to the Connectivity Interface. | ||||||
Validation | EmptySSLCipherProtocolVersionList | You must specify at least one SSL Protocol version | ||||||
Validation | stringTooLong | The string {0} length exceeds the limit of {1} | ||||||
Validation | IntfAlreadyUsed | The interface {0} is already used in another VRF. An interface can be part of only one VRF at a time. | ||||||
Validation | autoNegNotAllowedOnManagementInterface | AutoNeg cannot be set for management interface. | ||||||
Validation | nameNull | Name must not be null. | ||||||
Validation | invalidAllConfigured | Individual metric-groups configuration not required if All is configured. | ||||||
Validation | emptyBypassList | The hardware bypass list is empty | ||||||
Validation | unknownValidationError | System failed to validate the request due to an internal error, please contact support. | ||||||
Validation | provideAtLeaseOneField | You must define at least one option to create a valid certificate. | ||||||
Validation | interfaceNameRequired | Interface associated with a syslog server should have a non-empty NAME. | ||||||
Validation | cryptoNonCompliantIkev1ProposalForEncryptionType | The upgraded IKEv1 proposals use ESP_3DES Encryption which is not supported on this FTD version: {0}. | ||||||
Validation | interfaceCannotHaveIpv6AddressOfBgpNetwork | This IPv6 address is part of a network that is being used in the BGP configuration. You cannot assign an IPv6 address from this network to a management-only interface or subinterface. | ||||||
Validation | RuleGroupDefaultSecurityLevelNotAllowed | Custom intrusion rule group must not include a default security level. | ||||||
Validation | maxECMPZoneCountReached | You can create a maximum of 256 ECMP traffic zones. | ||||||
Validation | emptyInterfaceNameNotAllowedInDdns | An interface associated with the DDNS service must have a name. | ||||||
Validation | dnsServersCannotBeEmpty | You must specify at least one DNS server. | ||||||
Validation | invalidFTSFilter | You cannot combine a full-text search (filter=fts~) filter with any other filter parameter in a single request. | ||||||
Validation | SSPServerUnavailable | SSP Server Unavailable | ||||||
Validation | AnyConnInvalidModuleTypeProfile | Invalid module type in AnyConnect Client profile | ||||||
Validation | AnyConnPoolIpvMismatch | Network object {0} IP version is not correct | ||||||
Validation | interfaceShouldBeInGlobalVRF | Interface(s) {0} associated with {1} should belong to Global Virtual Router. | ||||||
Validation | snort3NoSGTDESTSupport | Snort 3 does not support Access Rule with Destination SGT. Checkout the following rule(s): {0} | ||||||
Validation | invalidFqdn | The fully-qualified domain name is invalid. | ||||||
Validation | CannotUpdateDefaultNapName | You cannot update the name of the default Network Analysis Policy. | ||||||
Validation | invalidPasswordChar | Invalid password. It cannot contain spaces and special character @ | ||||||
Validation | unableToGeneratePLRRequestCode | Unable to generate PLR Request Code. In order to generate a request code, you must enable Permanent Licensing first. | ||||||
Validation | memberInterfaceCannotBeUsed | An interface used by DHCP Relay Service cannot be associated with {0} object. Interfaces: {1} | ||||||
Validation | invalidNetworkSubTypeObjectsForPolicy | Unsupported type of network object: {0}. The object names are: {1}. | ||||||
Validation | vdbUpdateError_1 | Unable to connect to update server | ||||||
Validation | invalidOspfDuplicateArea | Area ID must be unique per OSPF process | ||||||
Validation | invalidEigrpWILDANY | 0.0.0.0 is not a valid Router ID.. | ||||||
Validation | interfaceWithECMPStaticRoutes | Interface "{0}" has these equal-cost static routes: [{1}]. | ||||||
Validation | registrationKeyLengthOutOfRange | Registration Key of "{0}" should be no less than {1} and no more than {2}. | ||||||
Validation | invalidMacAddress | Invalid MAC address. The allowed format is H.H.H, where H is a 16-bit hexadecimal digit. | ||||||
Validation | CertStatusSelfSignedNullCheck | IsSelfSigned cannot be null | ||||||
Validation | invalidFlexCliSecretValue | {0} value must be an existing Secret Object | ||||||
Validation | NoAssociatedIPSFound | Failed to find an IPS associated with the default policy {0}. | ||||||
Validation | appFilterMissingValue | The application filter should have a value {0}. | ||||||
Validation | appFilterInvalidNumericValueLow | The numeric input for {0} is too low. The minimum value {1}. | ||||||
Validation | natSourceIntfNotNamed | The interface used for NAT rule source interface must have a name | ||||||
Validation | timeZoneInvalidCustomSetting | Invalid Custom Setting for TimeZone Object.TimeZone Object custom configuration can be either done by DAY or DATE not by both. | ||||||
Validation | invalidLine | Line is not valid. {0} | ||||||
Validation | manualNatDestIntfIsNullWithIntfInTransSrc | Destination interface cannot be any if you select interface for the translated source | ||||||
Validation | interfaceNameNull | Cannot associate an interface with no logical name. | ||||||
Validation | invalidOspfInterfaceNetworkMismatch | Interface {0} IP address does not belong to the specified network {1} of area {2} | ||||||
Validation | timeZoneInvalidDate | Invalid startDateTime. The startDateTime must be prior to the endDateTime. Use the format YYYY-MM-DDTHH:MM, with time in 24-hour notation. | ||||||
Validation | invalidURLfilterLicense | URL filtering license is not enabled | ||||||
Validation | appFilterDupClassificationType | Duplicated classification type selected: {0} | ||||||
Validation | RuleNotFoundInRuleGroup | Could not find rule {0} in rule group {1}. | ||||||
Validation | invalidOspfRedistDuplicateConf | Multiple configurations found for the protocol {0} | ||||||
Validation | cfgImpInvalidExcludeEntitiesMatchers | Invalid exclude-entities matchers. Each matcher must have format like 'id= |
||||||
Validation | invalidPrivateKey | Private key is not valid | ||||||
Validation | noConnection | This device is currently not registered or in evaluation mode for Smart Licensing | ||||||
Validation | unableToInstallPLRAuthCode | Unable to install PLR Authorization Code. In order to install a PLR Authorization Code, you must enable PLR and generate a request code. | ||||||
Validation | agentAllowedInterfaceTypes | Invalid type of DCHP Relay Agent interface, the only types allowed are PhysicalInterface, SubInterface, VLAN, and EtherChannelInterface. | ||||||
Validation | realmInterfaceNotNamed | Identity realm directory interface does not have a logical name | ||||||
Validation | invalidAddress | Invalid address | ||||||
Validation | IntrusionRuleNotFound | Unable to find the IntrusionRule with ID:{0}. | ||||||
Validation | acRuleDestProtocolNotAllowedWithSrcPort | You cannot add a destination protocol object with non-empty source ports: {0} | ||||||
Validation | FMCRegistrationCurrentPendingChanges | Cannot start FMC registration while there are current pending changes. | ||||||
Validation | SecurityIntelligenceDNSPolicyGlobalWhitelistShouldBeFirstElement | The DNS policy global Do Not Block rules should be in the first position in the Do Not Block list. | ||||||
Validation | acPolicyInvalidNap | The selected network analysis policy cannot be used in the access policy. | ||||||
Validation | SSLCipherUnsupportedAlgorithms | Configured cipher algorithms {0} are either not supported in this version of FTD or not a valid algorithm for the selected protocol versions. | ||||||
Validation | cannotUseFQDNIPRangeNetworkObjects | Cannot use Network objects with FQDN or IP Range type configuration | ||||||
Validation | domainNameFeedUpdateError | The feed with the ID {0} was not downloaded. | ||||||
Validation | sruUpdateError_16 | Rulepack was successfully installed but skipping deployment as this is a STANDBY device. | ||||||
Validation | s2sVTIRRINotAllowed | You cannot configure reverse route injection when using a static virtual tunnel interface for a site-to-site VPN connection. | ||||||
Validation | cryptoCompliantIkev2Policy | The IKEv2 policies are using strong encryption which is not allowed by your licensing setting, please disable them or use DES only: {0} | ||||||
Validation | s2sCryptoEnabledIkev2Proposals | S2S VPN uses IKEv2 proposals with DES encryption. DES is not supported when strong encryption is enabled. | ||||||
Validation | loopbackAddressNotAllowedAsFMCHost | FMC Host of "{0}" cannot be a loopback address. | ||||||
Validation | unsupportedLACPModeForPlatform | Specified EtherChannel LACP Mode type is not supported on this platform. | ||||||
Validation | extraCertificates | One or more extraneous certificates were selected: {0} | ||||||
Validation | sslUpgradeFailed | SSL Policy upgrade failed due to a system error. Please contact Cisco Technical Support. | ||||||
Validation | cannotFindOutsideInterface | Please verify that outside interface is configured and connected to a gateway that can reach the internet. | ||||||
Validation | RaVpnGPTunnelNetworksRequired | Tunnel Networks have to be specified. | ||||||
Validation | cliCommandUnSupportedCharacters | Character {0} not allowed in CLI Console. | ||||||
Validation | SystemDefinedRuleGroup | You cannot modify system defined rule groups. {0} is a system defined rule group. | ||||||
Validation | ipsecDupIkev2Encryption | Cannot have duplicate encryption methods | ||||||
Validation | SSLCipherUnsupportedProtocolVersions | Protocol version DTSLV1_2 is not supported in {0} FTD model. | ||||||
Validation | PullFileDiskSpaceNotAvailable | File upload failed - Insufficient disk space. | ||||||
Validation | FMCRegistrationSettingsDoesNotExist | FMCRegistrationSettings object does not exist. Please make sure you create one before you start FMC Registration. | ||||||
Validation | snmpFruRemoveTrapNotSupportedOnVirtualPlatform | SNMP FRU Remove Trap not supported on Virtual Platform. | ||||||
Validation | haPrimaryAndSecondaryAddressesRequired | Both primary and secondary {0} addresses must be provided for {1}. | ||||||
Validation | RaVpnSecAuthCommPwdNotSpecified | Common Password is required | ||||||
Validation | staticRouteNoInterfaceName | Interface used for static route must have a logical name | ||||||
Validation | errorDuringInfoFetchFromSys | Error occurred during system information fetching. | ||||||
Validation | checksumUrlHasToBeMandatory | Checksum URL is required if update frequency is set to five minutes, otherwise it is optional. | ||||||
Validation | memberInterfacesNotSameSpeedCapabilities | EtherChannel member interfaces cannot have different speed capabilities. | ||||||
Validation | denyMtuChangeOnUnnamedInterface | You cannot change MTU on an unnamed interface. MTU must be set to 1500 on an unnamed interface | ||||||
Validation | invalidHAFailoverPeerHoldTimeUnit | Peer hold time unit must be MILLISECONDS or SECONDS | ||||||
Validation | invalidIntegrationTargetsLimit | You cannot associate more than one integration target. | ||||||
Validation | cannotUseBGIMemberInterfaces | The interface is part of a bridge group. You cannot configure management access list rules for a bridge group member. | ||||||
Validation | staticRouteDupGatewayForDiffInterfaces | You cannot use the same gateway for routes on more than one interface. | ||||||
Validation | vtiTunnelIdNotInRange | Invalid range for tunnelId. The allowed range is {0}-{1}. | ||||||
Validation | geoUpdateError_14 | GeoDB operation timed out. | ||||||
Validation | haConfigurationModificationNotAllowed | HA Configuration cannot be modified as the node is already in HA | ||||||
Validation | s2sVTIRemoteBackupPeersNotAllowed | You cannot configure remote backup peers when using a static virtual tunnel interface for a site-to-site VPN connection. | ||||||
Validation | metricBandwidthNullMetricTypeNotNull | Metric Bandwidth cannot be null when Metric Type is not null. | ||||||
Validation | etherChannelAutoSpeedNotInMemberInterfaceSpeedCapability | EtherChannel speed cannot be set to AUTO, the selected member interface(s) do not have AUTO speed capability. | ||||||
Validation | s2sVTIOnlyVTITypeAllowed | If you enable static VTI, you must select a virtual tunnel interface for the site-to-site VPN connection profile. | ||||||
Validation | staticRouteDupGatewayForDiffInterfacesConfigCheck | Some static routes use the same gateway and different interfaces. Number of static routes affected: {0}. | ||||||
Validation | invalidRealmId | Invalid realm ID | ||||||
Validation | sruUpdateError_0 | Rulepack successfully installed | ||||||
Validation | atLeastOneEntryRequired | Should have at least one entry | ||||||
Validation | manualNatNoDestNatWithSrcNat46 | Missing destination translation with IPv4 to IPv6 translation on source addresses | ||||||
Validation | unsupportedIkevTwoEncryption | The following encryption algorithms are not supported in IKEv2 policies: 3DES, NULL. | ||||||
Validation | cannotBeEtherChannelMemberInterfaces | The interface "{0}" is a member of a EtherChannel. You cannot use it in an ECMP Traffic Zone. | ||||||
Validation | NetmaskProvidedWithNoIPAddress | A Netmask has been provided with no IP address. | ||||||
Validation | PullFileTimeoutFailed | File upload failed due to timeout | ||||||
Validation | InvalidBgpNeighborDupPrefixListFilter | Only one prefix list can be configured in either direction | ||||||
Validation | emptyCustomURLValue | Custom URL should be provided for the CUSTOM Region. | ||||||
Validation | invalidIPV4NetworkObject | Invalid objects are: {0}. | ||||||
Validation | bridgeGroupInterfaceMemberPassive | You cannot add a passive mode interface to a bridge group. | ||||||
Validation | usedHAInterface | The {0} must be an unused interface | ||||||
Validation | DHCPServerWrongNetworkProtocol | DHCP server IP address range must use IPv4 addresses | ||||||
Validation | standbyWithoutActiveMacAddress | Standby MAC Address cannot be specified without an active MAC Address. | ||||||
Validation | ipAddressTypeMismatch | The IP addresses for {0} must be either IPv4 or IPv6 not both. | ||||||
Validation | invalidRangeBadOrder | Invalid range. The end IP address must be greater than the start IP address | ||||||
Validation | OpenSSLCipherDetailsNotAvailable | Unable to load the Open SSL protocol cipher details. | ||||||
Validation | cannotUpdateUnauthenticatedUser | Cannot perform update on unauthenticated user | ||||||
Validation | invalidHAFailoverThreshold | When the interface failure threshold unit is set to {0}, then the valid range is between {1} and {2}. | ||||||
Validation | exceedsMemberInterfacesLimit | EtherChannel cannot contain more than 16 active physical interfaces. | ||||||
Validation | VRFNotSupported | VRF is not supported in the current platform. | ||||||
Validation | ipsecPolicyNeedPrf | Policy must have at least one pseudorandom function | ||||||
Validation | prefixListIpAddressNotUnique | IP address/mask value should be unique across all entries in the prefix list. | ||||||
Validation | passwordsMustNotBeBlank | The password has not been changed from the default. You must specify a new password as well as the existing password. | ||||||
Validation | CertStatusIsValidNullCheck | IsValid cannot be null | ||||||
Validation | invalidOspfProcessUpdated | Cannot change process ID when editing OSPF process | ||||||
Validation | interfaceCannotHaveIpv4AddressOfBgpNetwork | This IPv4 address is part of a network that is being used in the BGP configuration. You cannot assign an IPv4 address from this network to a management-only interface or subinterface. | ||||||
Validation | DHCPServerSecondaryWINSHost | DHCP server secondary WINS server must be host type: {0} | ||||||
Validation | invalidFlexCliTemplateUnsupportedChar | Template cannot contain unsupported character sequence {0} | ||||||
Validation | invalidFMCConnectivityInterfaceMode | Physical interface {0} is not in ROUTED mode. Only ROUTED mode Physical interfaces can be assigned to Connectivity Interface. | ||||||
Validation | evalNotStarted | The evaluation mode was not started | ||||||
Validation | invalidFqdnDnsResolution | The fully-qualified domain name DNS resolution type is invalid. | ||||||
Validation | unsupportedNGFWInterfaceSpeed | Unsupported NGFW Interface Speed on SSP platform | ||||||
Validation | invalidFilterCondition | Invalid filter condition is provided. | ||||||
Validation | haConfigurationCloudServicesFailure | Unable to set the state of the box according to the content of the cloud communication settings object. | ||||||
Validation | dhcpRelayEnabled | DHCP feature cannot be enabled when DHCP Relay Agent is running. | ||||||
Validation | interfaceTrafficImpactWithConfig | One or more interfaces were moved from one virtual router to another. Any existing connections on moved interfaces will be dropped. | ||||||
Validation | duplicateSyslogServerIPAddressAndPortNumber | Two Syslog Servers cannot have same IP address and port number. Duplicate IP address: {0} and port number: {1} | ||||||
Validation | duplicateBridgeGroupInterfaceId | Bridge Group interface ID {0} is already being used. | ||||||
Validation | nameUseAAAReservedKeyWord | You cannot use a reserved AAA keyword as your Identity Source name: "{0}" | ||||||
Validation | bridgeGroupInterfaceCannotHaveIpv4AddressOfBgpNetwork | This IPv4 address is part of a network that is being used in the BGP configuration. You cannot assign an IPv4 address from this network to a bridge group interface. | ||||||
Validation | invalidOspfRedistIsisRequiredDisabled | Routing level must be specified to enable redistribution of ISIS protocol | ||||||
Validation | unsupportedIkevTwoIpsecEncryptions | The following encryption algorithms are not supported in IKEv2 IPsec proposals: 3DES, AES-GMAC, AES-GMAC-192, AES-GMAC-256. | ||||||
Validation | deviceUnenrollAlreadyInProgress | The device unenrollment process is already in progress. | ||||||
Validation | interfaceBreakoutNotSupported | Breaking out Interface is not supported for interface {0} | ||||||
Validation | DHCPServerInterfaceInBridgeGroup | The interface {0} is already a member of the bridge group interface {1} and hence cannot be configured as a DHCP server | ||||||
Validation | invalidImportValue | Importing Intrusion Rule has invalid override state {0} | ||||||
Validation | invalidBgpNeighborBridgeGroupInterface | BGP Neighbor can not be on the same network as Bridge group interface | ||||||
Validation | PullUpgradeCompleteMessage | Pull is completed | ||||||
Validation | invalidSmartCliPolicyListValue | {0} entity value must be an existing Policy List Object | ||||||
Validation | cannotAddManagementAccessInterface | Interface {0} is configured to allow management access. You cannot include it in an ECMP Traffic Zone. | ||||||
Validation | OverriddenAndDefaultStateInputNotAllowed | Inputs are not allowed for overriddenState and defaultState fields. | ||||||
Validation | timeoutExceedsFrequency | The timeout value should not exceed the frequency value | ||||||
Validation | haBreakFromStandby | You cannot execute {0} on the standby unit. Please log into the active unit to break HA. If you need to disable HA on this unit only, first suspend HA. Then you can execute {0}. | ||||||
Validation | onlyPrefixOrAccessList | The list should contain either all Access List objects or all Prefix List objects. | ||||||
Validation | invalidInterfaceMode | Interface "{0}" cannot be added to ECMP Traffic Zone. Only interfaces with ROUTED mode are allowed. | ||||||
Validation | invalidEnumForFilter | Value {0} not supported for filter {1}. Options are {2}. | ||||||
Validation | interfaceInDHCPServer | The following interfaces are configured as DHCP Servers {0}. You must remove them before you can add the interfaces to a bridge group | ||||||
Validation | maxInterfaceLimitInsideZone | An ECMP Traffic Zone can contain a maximum of 8 interfaces. | ||||||
Validation | timeRangeInvalidISODate | Invalid effective start or end date time. Use the ISO format YYYY-MM-DDTHH:MM, with time in 24-hour notation. | ||||||
Validation | invalidMethod | Validation failed, invalid method "{0}" marked as @AutoValidating | ||||||
Validation | InstanceMissingDataField | Instance is missing data field. | ||||||
Validation | manualNatSrc66OrigSrcIpv6PrefixTooShort | The original source IPv6 prefix must be greater than or equal to 64 in an IPv6 to IPv6 manual NAT source translation: {0} | ||||||
Validation | unsupportedIkevTwoPrf | MD5 Hash is not a supported PRF Type in IKEv2 Policies. | ||||||
Validation | ipsecDupIkev2Group | Cannot have duplicate DH groups | ||||||
Validation | invalidObjectForTimeRangeAnnotation | Invalid object type for TimeRange annotation. | ||||||
Validation | UnlockDeviceWithoutAcceptEula | The End User License Agreement has not been accepted. The device remains locked until you accept the EULA. | ||||||
Validation | emptyLocations | Please select at least one country or continent | ||||||
Validation | nestedNetworkGroupCycleDetected | The network group {0} includes a nested reference to the group you are editing. A network group cannot include references to itself. Please remove {0} | ||||||
Validation | duplicateFqdnInList | There is already an interface configured with the FQDN {0}. | ||||||
Validation | standbyIPNotInSameSubnetOfActiveIPAddress | Standby IP Address should be in the same subnet as the active IP Address. | ||||||
Validation | unsupportedDuplexType | Specified EtherChannel Duplex type is not supported. | ||||||
Validation | snmpIpv6ManagerAddressHostGroup | IPv6 manager networks are not allowed for SNMP Hosts with Host Group type. | ||||||
Validation | AnyConnNoIpv6InsideNetwork | With {0} as an IPv6 address pool, you must have at least one IPv6 inside network specified | ||||||
Validation | diskFileNotFound | Cannot find a file with name: {0} | ||||||
Validation | SSLCipherProtocolMissingAlgorithms | Selected protocol versions {0} should have at least one supported algorithm assigned. | ||||||
Validation | interfaceFecCanBeSetOnlyFor25GSpeedCapInterface | Interface {0} doesn't support 25G Speed Capability; you cannot set the FEC mode. | ||||||
Validation | OrphanRuleExist | If Intrusion Rule Group {0} is deleted then the following Intrusion Rules will not belong to any RuleGroup: {1}. Rules for this group can be deleted with the group by using cascadeDelete option. | ||||||
Validation | invalidSubnetMask | Invalid subnet mask. | ||||||
Validation | PullUpgradeInitiationSSLError | Pull upgrade job initiation failed due to an SSL verification error. | ||||||
Validation | ISETagInvalid | Invalid SGT with tag: {0} and externalId: {1}. | ||||||
Validation | invalidHAFailoverInterfaceHoldTimeUnit | Interface hold time unit must be MILLISECONDS or SECONDS | ||||||
Validation | communityNumbersNotUnique | Community numbers must be a unique set of values. | ||||||
Validation | invalidSecret | Secret cannot be blank or a masking string or a single digit or start with a digit followed by spaces and cannot contain a question mark or semicolon | ||||||
Validation | multipleAgentsOnInterface | Only a single DHCP Relay Agent can be configured on interface {0}. | ||||||
Validation | interfacePairShouldBeInSameBridgeGroup | Interface pair must be in the same bridge group to enable bypass | ||||||
Validation | featureCapabilitiesWriteException | Exception thrown while trying to write Feature Capabilities to file {0} | ||||||
Validation | realmSequenceNotAllowedForActiveAuthIdentityRule | Realm Sequence object cannot be used in an Active Auth identity rule. | ||||||
Validation | defaultActionCannotBeChanged | You cannot change the default action in the identity policy | ||||||
Validation | invalidRange | Invalid range | ||||||
Validation | invalidOspfNsfNone | Disabling NSF requires all LLS capability, Cisco helper, Opaque LSA, and IETF helper be negated | ||||||
Validation | haInterfaceNameNotEmpty | You cannot use a named interface for {0}. Please edit the interface and remove the name, or select a different interface. | ||||||
Validation | standardAccessListNetworksNotUnique | Standard Access List entries must have unique networks across all entries. | ||||||
Validation | cannotCreateFMCRegistrationSettingsWithFlexConfigPolicy | The device has a FlexConfig Object. You must remove all FlexConfig configuration before proceeding. | ||||||
Validation | cfgImpDuplicateImportJob | You cannot start a new configuration import job because either an existing job is already running or an import job is scheduled to run | ||||||
Validation | newInstanceWithDuplicateId | Validation failed, attempting to create a new object with duplicate ID | ||||||
Validation | ipsecPolicyInvalidPriority | Priority value not in range: {0} | ||||||
Validation | contextGetFailed | Could not get device registration context. Please try again later. | ||||||
Validation | duplicateLdapValue | Duplicate LDAP attribute value {0} in LDAP attribute map {1} is not allowed. | ||||||
Validation | manualNatSrc66OrigSrcPrefixShorterThanTransSrcPrefix | The IPv6 prefix of the original source subnet "{0}" must be greater than or equal to the IPv6 prefix of the translated source subnet "{1}" | ||||||
Validation | snmpEncryptPasswordShouldBeNull | Encryption Password should not be provided for SNMP Users with NOAUTH and AUTH security levels. | ||||||
Validation | AccessSslRulesWithNewlyAddedCategories | The following URL categories are new and not yet active: {0}. Please also add one or more active URL category to the rule. | ||||||
Validation | s2sBackupPeerIkev2InvalidLocalKey | Invalid IKEv2 pre-shared local key. It must contain 1-128 ASCII printable characters, no whitespace, no single or double quotation marks, no question marks and cannot be a single digit | ||||||
Validation | cancelFMCRegistrationJobAlreadyInProgress | Cancel FMC registration job is already in progress. | ||||||
Validation | dnsServerGroupCannotBeRenamed | The DNS server group {0} is being used in the data interface settings. Before you can rename the group, you must remove it from that setting. | ||||||
Validation | snmpNullAuthenticationPassword | Authentication password can not be null for SNMP users with security level AUTH and PRIV. | ||||||
Validation | DHCPServerAutoConfigFalseWithInterface | DHCP Server default interface cannot be set if Auto Configuration is off | ||||||
Validation | appFilterDupRisk | Duplicated risk selected: {0} | ||||||
Validation | loggingListNameSubString | Name cannot be substring of one of existing list's name. | ||||||
Validation | maxPrefixLimitCanNotBeDifferent | Cannot have different values for maximum prefix limit. | ||||||
Validation | genericTimeout | Timeout: {0} | ||||||
Validation | invalidSmartCliExtendedAccessListValue | {0} entity value must be an existing Extended Access List Object | ||||||
Validation | appFilterEmptyMatchers | The application filter has empty match conditions. | ||||||
Validation | cannotChangeIdentitySourceOfUser | You cannot update the identitySourceId of a user. | ||||||
Validation | hostNull | Host must not be null. | ||||||
Validation | unexpectedPLRUnsuccessfulCancellation | Unable to cancel Universal Permanent Licensing. | ||||||
Validation | cannotProceedHaActionWithRegenFlag | The device is part of an HA pair. You cannot force data regeneration during deployment when joining or breaking HA. | ||||||
Validation | noToken | In order to register, you must provide a token obtained from your Smart Software Manager Account | ||||||
Validation | cloudEventsCanNotBeEnabledWithEmptyEventTypes | You must select at least one type of event. | ||||||
Validation | acRuleLogFilesInvalidAction | You cannot enable Log Files because there is no file policy selected for this rule. | ||||||
Validation | nameBlank | Name must not be empty or blank. | ||||||
Validation | unresolvableUrl | Hostname cannot be resolved to an IP address. | ||||||
Validation | unableToCreateBypassPair | Unable to create hardware bypass pairs | ||||||
Validation | cliCommandEmpty | Please enter a command. | ||||||
Validation | NoBasePolicySet | No Base Policy Set for Intrusion Policy | ||||||
Validation | facDeletePerlGeneralError | An unexpected error occurred while deleting a Firepower Analytics Center entity | ||||||
Validation | SSLPolicyOnlyTCPPorts | SSL rule cannot use non-TCP port object {0}, referenced in {1} ports | ||||||
Validation | InvalidBgpNeighborDupASPathFilter | Only one as-path can be configured in either direction | ||||||
Validation | RaVpnInvalidPasswordPeriod | Password notification period is between 1-180 days. | ||||||
Validation | haBothLinksAreOnSameSubnet | The failover and statefulFailover addresses must not be on the same {0} subnet. | ||||||
Validation | objectNatPortNotAllowedWithDnsEnabled | You cannot enable DNS reply translation with port translation in an auto NAT rule | ||||||
Validation | InvalidBgpNeighborNeighborHopsRemoteAsBgpAsNumber | ttl-security should allow to configure for EBGP peers. You cannot configure if BGP AS number is same as remote-as number. | ||||||
Validation | staticRouteInvalidIpTypeForSlaMonitor | The SLA monitor cannot be referenced by IPV6 static route entry | ||||||
Validation | HTTPProxyNotAuthenticated | authenticate is set to false, please remove the username and password or set null. | ||||||
Validation | unknownHostIP | Could not determine device management IP address. | ||||||
Validation | cannotConfigureIPv6Address | The interface is configured in {0} mode. You cannot configure an IP v6 address on {0} interface. | ||||||
Validation | ecmpZoneWithConfigSSLRules | You should configure the same SSL Rules to all ECMP Traffic Zone member interfaces. Interfaces from ECMP Traffic Zones: "{0}" should have the same SSL rules. Please make sure you configure ECMP Traffic Zones/SSL Rules accordingly. | ||||||
Validation | DHCPServerSecondaryDNSHost | DHCP server secondary DNS server must be host type: {0} | ||||||
Validation | bgpUpgradeFailed | BGP upgrade failed due to a system error, please contact the support. | ||||||
Validation | interfaceisPassive | The selected interface {0} used in syslog server cannot be in passive mode. | ||||||
Validation | invalidOspfSpfTimers | Incorrect SPF timer configuration, expected initial-delay <= min-hold-time <= max-wait-time | ||||||
Validation | CannotUpdateSystemDefinedPolicyRule | You cannot update a rule for a system defined policy. | ||||||
Validation | RaVpnGroupPolicyRenameDefaultGP | Default Group Policy (DfltGrpPolicy) cannot be renamed. | ||||||
Validation | noHardwareNameProvided | No hardware names where provided in the url. Please provide a hardware name or a list of hardware names separated by commas in the hardwareName filter of the url. | ||||||
Validation | invalidDuplicateAccessSecretKey | Validation failed due to duplicate Access and Secret key. | ||||||
Validation | acRuleOverlapCountryContinentSrcNetworks | The source networks should not contain both country {0} and continent {1} | ||||||
Validation | mgmtMtuInvalidRange | Invalid MTU value. The MTU can be 68-1500 (IPv4) or 1280-1500 (IPv6). | ||||||
Validation | acRuleDestUdpPortWithOtherSrcPort | When you specify destination UDP ports, the source ports should either be empty or contain at least one UDP port | ||||||
Validation | invalidHAFailoverInterfaceHoldTime | Interface hold time must be between 5 and 75 seconds. | ||||||
Validation | s2sMultipleOutsideIntf | Site-to-Site VPN connection profile can only have a single outside interface | ||||||
Validation | timeRangeInvalidISOTime | Invalid effective start or end time. Use the ISO format YYYY-MM-DDTHH:MM, with time in 24-hour notation. The hour (HH) must be 0-23, and the minutes (MM) must be 0-59. | ||||||
Validation | selfSignedLeafWithChain | Self-signed certificates cannot have a trust chain. | ||||||
Validation | ddnsPasswordRequired | Password is required. | ||||||
Validation | noServers | No DHCP relay server configured. No relaying can be done without at least one Server. | ||||||
Validation | objectNatTransNetworkHasIpv6AndIpv4Addresses | The translated address cannot contain both IPv6 and IPv4 addresses | ||||||
Validation | bridgeGroupInterfaceIdNotEditable | The bridge group interface ID cannot be modified by editing the bridge group interface. Current bridge group interface ID in the DB is {0}, bridge group interface ID from request is {1} | ||||||
Validation | SSLRuleSyslogWithEventOff | Syslog cannot be used if events for the SSL rule are turned off | ||||||
Validation | RuleGroupNeeded | The Intrusion Rule {0} must belong to at least one rule group. | ||||||
Validation | BinderRuleMissingUseField | Binder Rule is missing "use" field. | ||||||
Validation | updateEntityWithoutChanges | This update request contained no changes to the object. The request is not processed. | ||||||
Validation | appFilterTypeInvalid | Invalid application filter entry type {0}. | ||||||
Validation | invalidVariableValue | Variable value is not valid. {0} | ||||||
Validation | pppoeDuplicateVpdnUserName | The Username is the same as the PPPoE username from interface {0}. | ||||||
Validation | invalidDuplicateInstrumentationKey | Validation failed due to a duplicate instrumentation key. | ||||||
Validation | emptyValue | Value cannot be empty. | ||||||
Validation | invalidIntegrationTarget | At least one integration target should be configured. | ||||||
Validation | RaVpnSecAuthPrefillPasswdBothNotSpecified | One of Password Type or Prefill Username has to be configured. | ||||||
Validation | unsupportedApiVersion | The API version specified is not supported. The supported API versions are {0} | ||||||
Validation | subnetConflictWithStaticRoutes | There is already a static route for the {0}/{1} network, which conflicts with address {2}/{3}. To assign this address to an interface, you must first delete the static route | ||||||
Validation | conflictingFlexConfigPolicyDHCPRelay | You can not add FlexConfig objects with prohibited commands to the FlexConfig policy while the DHCPRelay feature is enabled. You must either remove the prohibited commands from the objects, or remove the objects from the FlexConfig policy. | ||||||
Validation | objectNat46Ipv4AnyIsNotAllowedWithNat46WellKnownPrefix | The original address cannot be IPv4 "any" with the well known NAT46 prefix "64:ff9b::" in the translated address | ||||||
Validation | BannerTooLong | Banner display string cannot be longer than {0} | ||||||
Validation | invalidInterfaceHoldTime | You cannot enter an interface hold time value that is less than 5 times the interface poll time. | ||||||
Validation | DuplicateAnyConnNoRealmServerHosts | Realm servergroup {0} has duplicate server hosts {1},Realm server hosts must be unique. | ||||||
Validation | systemDefinedObject | You cannot modify or delete system defined objects. | ||||||
Validation | s2sIkev2ProposalsEmpty | IKEv2 proposals cannot be null or empty | ||||||
Validation | invalidOspfNsfCiscoOnly | NSF Cisco requires LLS capability, Cisco helper enabled and Opaque LSA, IETF helper negated | ||||||
Validation | invalidNetmask | The Network mask entered is invalid | ||||||
Validation | fmcConnectivityInterfaceIsRequired | Either Data interface or management interface should be selected. | ||||||
Validation | updateEasysetupStatusWithoutPasswordChange | Password has not been changed, unable to update easy setup status | ||||||
Validation | haNoneMatchingAddresses | When using the same interface for both the failover and statefulFailover, their addresses must match. | ||||||
Validation | acRuleCannotUseReservedRuleName | You cannot use the reserved hidden rule name: {0} | ||||||
Validation | invalidBgpScanTime | The scan time value should match the scan time value in General Settings. | ||||||
Validation | modelMismatch | This upgrade is not for this device model. | ||||||
Validation | acRuleDestinationZoneCannotBePassive | When you specify source zone as passive mode zone, the destination zone should be empty | ||||||
Validation | timeZoneInvalidTimeConfigurationDayRecurrence | Invalid time configuration for dstDayRecurrence. Start Time configuration including startMonth,startWeek,startDayOfWeek,startTime should be less than End Time configuration including endMonth,endWeek,endDayOfWeek,endTime. | ||||||
Validation | invalidType | Invalid type provided, please check all permitted types in the model. | ||||||
Validation | GlobalVRFDelRequested | Global VRF can not be deleted. | ||||||
Validation | externalBrowserPackageWithFileAlreadyExists | An external browser package with the following name already exists: {0} | ||||||
Validation | acRuleDestUdpProtocolNotAllowedWithUdpDestPort | You cannot add a destination UDP protocol object with destination UDP ports: {0} | ||||||
Validation | manualNatRouteLookupDestNetworkMismatch | The Perform Route Lookup option is available for identity NAT only. The original and translated destination networks must be identical to use the option. | ||||||
Validation | InvalidBinderRuleToDisabledInstance | You cannot configure binder rules for disabled inspectors; the following inspectors violate this rule: {0}. | ||||||
Validation | manualNatSrc64Ipv6HostCountTooHigh | The IPv6 host count {0} in the original source exceeds the maximum allowed {1} in an IPv6 to IPv4 manual NAT source translation | ||||||
Validation | s2sVTIOnly1ProfilePerVTI | The virtual tunnel interface "{0}" is already being used in another site-to-site VPN connection. You can use a single VTI in one site-to-site VPN connection only. | ||||||
Validation | invalidV6EndCompatible | IPv4-compatible IPv6 as end address is not supported. | ||||||
Validation | maxServers | Only up to {0} DHCP servers can be configured for relaying. | ||||||
Validation | lockInvalidUnlock | Attempting to acquire an invalid lock: "{0}" | ||||||
Validation | vtiIPCannotOverlapRavpnAddressPool | Interface {0} cannot be in the address pool range {1} used in RAVPN connection profile {2}. | ||||||
Validation | invalidSmartCliRequiredDisabled | {0}: This is a required command. You cannot disable it | ||||||
Validation | s2sIkev2InvalidLocalKey | Invalid IKEv2 pre-shared local key. It must contain 1 to 128 ASCII printable characters, no whitespace, no single or double quotation marks, no question marks and cannot be a single digit | ||||||
Validation | passwordTooLong | Password is too long. The password needs to be less than 129 characters long | ||||||
Validation | invalidNumberOfTrackedObjects | The number of tracked objects cannot exceed {0} | ||||||
Validation | snmpAuthPasswordShouldBeNull | Authentication Password should not be provided for SNMP Users with NOAUTH security level. | ||||||
Validation | IntfNameNullOrEmpty | There is no interface name for the {0} interface. You can use named interfaces only in the virtual router. | ||||||
Validation | invalidCustomURLValue | Custom URL should not be provided for the Region other than CUSTOM. | ||||||
Validation | sysInfoNullFileOrProcess | Cannot create reader for null file or process | ||||||
Validation | managementOnlyCannotBeDisabled | You cannot disable the management-only option on the Management interface | ||||||
Validation | noDatabaseAvailable | Snort 3 rule package installation failed: There is no database available from the current rule package. | ||||||
Validation | staticRouteDupMetricForSameNetworks | There is already a static route with the same networks. You must specify another metric. | ||||||
Validation | manualNatDest64Ipv6HostObjNotAllowedInOrigDest | You cannot use an IPv6 host network object as the original destination in an IPv6 to IPv4 manual NAT destination translation rule: {0} | ||||||
Validation | invalidUsage | Validation failed, method "{0}" cannot be used to process "{1}" | ||||||
Validation | snort3AnotherProcessRunning | Another switching task is running. | ||||||
Validation | s2sIkev1MaskedKeyNotAllowed | Masked value for IKEv1 pre-shared key is not allowed with connection profile creation | ||||||
Validation | duplicateUserInRule | {0} is in the rule more than once. | ||||||
Validation | cannotEditIPOfNeighborInterface | An interface cannot have the same IPv4 address as a neighbor in OSPF {0}. | ||||||
Validation | bridgeGroupInterfaceHardwareNameNotEditable | The bridge group interface hardware name cannot be modified by editing the bridge group interface. Current bridge group interface hardware name in the DB is {0}, bridge group interface ID from request is {1} | ||||||
Validation | appFilterInvalidTypeName | Invalid application filter type name {0}. | ||||||
Validation | shouldNotContainHTML | HTML tags are not allowed | ||||||
Validation | manualNatOrigDestIsNull | You must specify an original destination network | ||||||
Validation | bothCloudRegionAndActionTypeCannotBeNull | Both Cloud Region and CloudActionType cannot be null. | ||||||
Validation | invalidOspfInterfaceConflictingNetwork | OSPF area networks must all belong to Management interfaces or Data interfaces | ||||||
Validation | invalidUserIdentitySourceTypeInRule | The identity source for the users in the rule should be of type IdentityRealmBase or LocalIdentitySource | ||||||
Validation | invalidBooleanQueryParam | {0} must be either TRUE or FALSE. | ||||||
Validation | intfMigrationImportFailed | Failed at import step. Unable to import the configuration due to error {0} | ||||||
Validation | ipsecPolicySamePriority | Priority cannot overlap with existing policy: {0} | ||||||
Validation | versionSameError | Device version {0} is already installed on the device. | ||||||
Validation | invalidInterfaceSelected | Invalid type of interface selected, the only types allowed are PhysicalInterface, SubInterface, and EtherChannelInterface. | ||||||
Validation | bypassPairShouldContainTwoInterfaces | The hardware bypass pair does not contain two interfaces that are allowed to be paired | ||||||
Validation | nullPlatformLogSettings | Platform log settings cannot be null on this platform. | ||||||
Validation | unalbeToConvertResponse | Unable to convert response using the specified API version. Please use the latest API version. | ||||||
Validation | bridgeGroupInterfaceReferencedInStaticRoute | The following Interfaces are used in static route configuration: {0}. This feature is not compatible with a bridge group member interface. You must remove the interfaces from the configuration before you can add them to the bridge group. | ||||||
Validation | sysInfoIOException | IO Exception thrown while trying to read System Information | ||||||
Validation | InputInconsistent | Input values in the following fields {0} are different from the value in the ruleData. Exclude them from the request or match it with data in ruleData. | ||||||
Validation | AnyConnExcessFiles | Can only have one AnyConnectPackageFile per platform | ||||||
Validation | snmpInvalidCommunityString | SNMP Community is a case-sensitive value up to 32 alphanumeric characters long. Spaces are not permitted. | ||||||
Validation | emptyLdapValue | There is an empty LDAP attribute value in LDAP attribute map {0}. | ||||||
Validation | identityRealmMultipleDirectoryConfig | Multiple directory configurations are not allowed for the realm. | ||||||
Validation | invalidDupInAclRouteFilter | Only one access list is allowed per interface | ||||||
Validation | vdbUpdateError_12 | Error running VDB update | ||||||
Validation | RuleFileInvalid | The rule file is invalid and the stderr output is available at the designated API. | ||||||
Validation | sruUpdateError_8 | Rulepack download failed | ||||||
Validation | bridgeGroupMemberModeCannotChange | You cannot change the mode of a bridge group member interface. | ||||||
Validation | bgpInvalidBgpNeighborAdvertiseMapConfiguration | Cannot configure exist-map and non-exist map for the same advertise-route-map and exist-route-map. | ||||||
Validation | cryptoNonCompliantIkev1PolicyForEncryption | The upgraded IKE-V1 policies: {0} use 3DES Encryption which is not supported on this FTD version. | ||||||
Validation | natPatOptionsNotSupported | The PAT pool option is not supported in NAT rules | ||||||
Validation | unpersistedReferenceTarget | Un-persisted reference target is detected, reference source is {0}, reference target is {1} | ||||||
Validation | invalidLoggingListName | Severity level cannot be used as name. Name cannot be substring of severity level. | ||||||
Validation | snmpMaxHostTrapCount | Max count of SNMP Host with enabled traps is 128. | ||||||
Validation | emptyCertificateString | Certificate String cannot be empty. | ||||||
Validation | emptyFlexVariableName | The variable name is missing in {0} | ||||||
Validation | UnsupportedNetworkObjectTypeForgroupPolicy | Network Object is being used in RavpnGroupPolicy {0} , type can't be edited to FQDN or HOST | ||||||
Validation | interfaceIsRequired | Either data interface or management interface should be selected. | ||||||
Validation | invalidManagementInterface | Management interface "{0}" is not allowed in ECMP Traffic Zones. | ||||||
Validation | dhcpRelayMemberInterface | This interface is used by the DHCP Relay Service. You cannot update its properties or refer to it from other objects. | ||||||
Validation | invalidDeviceMetricsIntegrationsLimit | Only one Device Metrics Integrations object can be created. | ||||||
Validation | invalidLoggingListInvalidRange | Message start ID cannot be greater than or equal to message end ID. | ||||||
Validation | invalidSystemUpgradeFile | The uploaded file is not valid. Upgrade files must have file type REL.tar. Do not perform upgrades with file type .sh upgrade files. | ||||||
Validation | linaResponseTimedOut | Cannot establish connection with data-plane. Request/Response timed out. | ||||||
Validation | s2sIkev2MaskedRemoteKeyNotAllowed | Masked value for IKEv2 pre-shared remote key is not allowed with connection profile creation | ||||||
Validation | AnyConnACPrfOutsideIntfInBvi | The interface {0} added to AnyConnectProfile is invalid, it is member of BridgeGroup. | ||||||
Validation | objectNatRouteLookupNetworksMismatch | The Perform Route Lookup option is available for identity NAT only. The original and translated addresses must be identical to use the option. | ||||||
Validation | cannotHaveStaticRouteOnTheMemberOfBVI | Bridge Group Member Interface: {0} cannot have static route entry | ||||||
Validation | noSupportedFileTypeForLocalMalwareAnalysis | File Rule validations failed. You must add a file type or category that supports Local Malware Analysis. | ||||||
Validation | snmpInvalidEncryptionPassword | Authentication password can not be null for SNMP users with security level PRIV. | ||||||
Validation | invalidTypeForFilter | Value {0} not supported for filter {1}. Must be of type {2}. | ||||||
Validation | invalidOSPFAreaNetworkBrigeGroupInterface | Bridge group interface falls in the same network as Area network. OSPF can not be configured on BVI interface | ||||||
Validation | AnyConnCryptoCompliance | Current licensing status does not allow use of cryptography present in AnyConnect VPN | ||||||
Validation | appFilterInvalidTypeValue | Invalid application filter type value {0}. | ||||||
Validation | invalidParentVrfId | Invalid parent Virtual Router Id for the ECMP Traffic Zone. | ||||||
Validation | bridgeGroupInterfaceReferencedInNatRule | The following Interfaces are used in NAT rules configuration: {0}. This feature is not compatible with a bridge group member interface. You must remove the interfaces from the configuration before you can add them to the bridge group. | ||||||
Validation | interfaceWithPppoeType | HA cannot be enabled when interface {0} has PPPoE Type selected. | ||||||
Validation | cannotCancelFMCRegistrationJobBeingCleanedUp | Cannot cancel FMC Registration Job because clean up is already in progress. | ||||||
Validation | bypassObjectNotFound | The hardware bypass object not found | ||||||
Validation | invalidOspfNotEnabledOnInterface | OSPF is not enabled on the interface {0} for the configured networks | ||||||
Validation | invalidHAInterface | The {0} must be a physical or EtherChannel interface. | ||||||
Validation | upgradeFileNotFound | Upgrade file not found. | ||||||
Validation | timeZoneInvalidDayRecurrence | The dstDayRecurrence section is incomplete. To configure a dstDayRecurrence, you must specify the startMonth,startWeek,startDayOfWeek,startTime,endMonth,endWeek,endDayOfWeek and endTime. | ||||||
Validation | operationalLinaEmptyResponse | Operational response can not be empty. | ||||||
Validation | ftdUpdateMgrError_235 | Missing upgrade information file. Cannot retry. | ||||||
Validation | RaVpnSecAuthCommPwdNotValid | Common Password cannot be specified. | ||||||
Validation | lspPackageNotSigned | Downloaded rule update package is not correctly signed. | ||||||
Validation | unexpectedPLRUnsuccessfulEnable | Unable to enable Universal Permanent Licensing. | ||||||
Validation | invalidOspfRedistOspfNone | OSPF redistribution is not possible without enabling another OSPF process | ||||||
Validation | HTTPInvalidUserName | Invalid Username. Support characters are [a-z 0-9]. | ||||||
Validation | RaVpnGroupPolicyIntfAddrOverLap | Interface cannot be in the address pool range {0} used in RAVPN group policy {1} | ||||||
Validation | conflictingActiveAuthPort | The selected port {0} is currently being used in a management access list to allow FDM connections. You cannot use this same port for Identity Policy's Active Auth. | ||||||
Validation | s2sBackupPeerIkev2RemoteMaskedKeyNotAllowed | Masked value for IKEv2 remote pre-shared key is not allowed when creating a new backup peer or updating the IP address for an existing backup peer. | ||||||
Validation | SslRulesWithDeprecatedCategoriesDisabledPolicy | Some of the SSL decryption rules refer to deprecated URL Categories. Number of SSL decryption rules affected: {0}. Enable the SSL Decryption policy, remove deprecated URL categories in the rules, or replace them with new ones. You can then disable the policy. | ||||||
Validation | DHCPServerPrimaryDNSHost | DHCP server primary DNS server must be host type: {0} | ||||||
Validation | noRealmId | Realm ID is required | ||||||
Validation | passwordConsecutive | Password contains consecutive characters | ||||||
Validation | AnyConnNoAddrPools | IPv4 or IPv6 address pool is required | ||||||
Validation | geoUpdateError_8 | Unspecified error when doing remote update. GeoDB download failed | ||||||
Validation | interfaceInHA | This interface is being used in a high availability (HA) configuration. You cannot update its properties or refer to it from other policies or objects. | ||||||
Validation | s2sNatExemptIntfCannotBeBviMember | Inside interface for NAT exempt cannot be a bridge-group member: {0} | ||||||
Validation | ftdUpdateMgrError_187 | Revert failed. | ||||||
Validation | vtiCannotBeMonitoredInterface | Virtual Tunnel Interface cannot be set as monitored interface. | ||||||
Validation | raCaCertUsedAsInternalCertificate | A CA certificate cannot be used as identity certificate for authentication between remote access clients and FTD. Please provide a valid identity certificate for successful remote access VPN establishment. | ||||||
Validation | invalidBgpNextHopTriggerDelay | The Next hop trigger delay value should match the next hop trigger delay value in General Settings. | ||||||
Validation | timeRangeInvalidRangeTime | Invalid rangeStartTime. If rangeStartDay and rangeEndDay are equal, rangeStartTime cannot be equal to the rangeEndTime. | ||||||
Validation | operatorNotSupported | Filter operator not supported | ||||||
Validation | invalidSmartCliSecretValue | {0} entity value must be an existing Secret Object | ||||||
Validation | RaVpnGroupPolicyUnsupportedRekeyMethod | SSL Rekey Method supports only 'NEW_TUNNEL' method. | ||||||
Validation | interfaceBreakoutNeedsDeployment | Interface {0} has pending changes. You must deploy the changes before you can break it out. | ||||||
Validation | invalidUsernameChar | Invalid username. It cannot contain spaces and special characters @ and : | ||||||
Validation | invalidOspfRedistribution | Redistribution for {0} is not supported for user defined virtual router. | ||||||
Validation | cryptoNonCompliantIkev1PolicyForHash | The upgraded IKE-V1 policies: {0} use MD5 Hash which is not supported on this FTD version. | ||||||
Validation | deprecatedSecurityProtocolTypeIsUsedInSslCiphers | Deprecated security protocol version {0} is used in the following SSL Ciphers, please remove it: {1}. | ||||||
Validation | invalidOspfInterfaceSecretNotFound | Secret {0} is not found | ||||||
Validation | SecurityIntelligenceDNSPolicyWhitelistContainsBlacklistItem | DNS policy Do Not Block rules cannot contain Block rules. | ||||||
Validation | VRFDiagnosticIntfNotSupported | You can assign the interface "{0}" to the global virtual router only. | ||||||
Validation | invalidLicenseGracePeriodStateForTestRequest | Unable to change the license grace period state. The grace period state cannot be changed to not started or started when it is already expired. The grace period state cannot stay the same as well. | ||||||
Validation | snort3MandatoryDeploymentNeeded | Before switching Snort version, you need to deploy all pending changes. | ||||||
Validation | failedDeploymentBeforeUpgrade | Deployment before upgrade failed. | ||||||
Validation | identityRealmDuplicateADPrimaryDomain | This AD Primary Domain is already used by realm {0} | ||||||
Validation | invalidFMCHost | FMC Host of "{0}" is not a valid IP address. | ||||||
Validation | invalidConnectionTypeSync | You cannot perform a sync if you are not registered | ||||||
Validation | RuleGroupEnabledUnderPolicies | Intrusion Rule Group {0} is still enabled under the following policies: {1}. Disable the rule group in those policies before deletion or use the disableInAllPolicies option. | ||||||
Validation | nameUseReservedKeyWord | You cannot use a reserved keyword as an object or group name: "{0}" | ||||||
Validation | timezoneMalformed | Cannot find the time zone | ||||||
Validation | snmpUserPasswordsCannotContainSpaces | SNMP User encryption and authentication password cannot contain spaces. | ||||||
Validation | cannotChangeUserRoleOfUser | You cannot update the user role of a user. | ||||||
Validation | invalidFlexCliIncorrectSectionUsage | Incorrect section usage found | ||||||
Validation | invalidOspfMissingArea | Referenced Area ID {0} is not configured | ||||||
Validation | invalidHAFailoverPeerHoldTime | Peer hold time must be between 800 and 999 milliseconds, or 1 and 15 seconds. | ||||||
Validation | BinderRuleMissingTypeField | Binder Rule is missing "type" field. | ||||||
Validation | RaVpnConnectionProfileSAMLSourceNeedsSAMLType | If the identity source is a SAML server, the authentication method must be SAML. | ||||||
Validation | communityEntriesNotUnique | Community entries must be unique. | ||||||
Validation | dnsServerGroupMaxNoAllowedCheck | Some DNS groups have more than the allowed number of configured servers ({0}). Number of DNS groups affected: {1}. | ||||||
Validation | inCompatiblePowerOverEthernet | Power over ethernet is not supported on the {0} physical interface. | ||||||
Validation | manualNatTransSrcAndDestIpVersionMismatch | The translated source and translated destination addresses must have the same IP version | ||||||
Validation | invalidHAFailoverInterfacePollTimeUnit | Interface poll time unit must be MILLISECONDS or SECONDS | ||||||
Validation | webCertMissingInternalCert | The Web Server Certificate must be assigned an Internal Certificate. | ||||||
Validation | acPolicyInvalidDefaultActionWithIps | Invalid default action {0}; only Allow is allowed with intrusion inspection | ||||||
Validation | AnyConnACPrfOutsideIntfHasNoName | The interface {0} added to AnyConnectProfile should have a logical name. | ||||||
Validation | invalidSmartCliEnumValue | {0} value must be one of the allowed enum values {1} | ||||||
Validation | sruMaximumRuleUpdate | Failed to update Intrusion Rule, only {0} may be updated in single transaction. | ||||||
Validation | certHashingNotSupported | Certificate hashing is not supported, please use SHA256 or higher. | ||||||
Validation | RuleGroupContainsNames | Cannot delete a custom rule group that contains custom rules. You must delete all contained rules prior to deleting this rule group. | ||||||
Validation | cannotTriggerAutoEnrollmentApiIfNotLicensed | You must license the device before enrolling with the cloud using Auto Enrollment. | ||||||
Validation | objectNatDupRuleWithSameOrigNetwork | There is another auto NAT rule with the same original network. Only one auto NAT rule is allowed per each original network | ||||||
Validation | cfgExpDuplicateExportJob | You cannot start a new configuration export job because either an existing job is already running or an export job is scheduled to run | ||||||
Validation | ftdUpdateMgrError_189 | Revert failed. | ||||||
Validation | useOfUnspecifiedIPAddressOnly | {0} is known as an Unspecified Address. This address cannot be assigned to an interface. | ||||||
Validation | haIdenticalAddresses | {0} has identical primary and secondary {1} addresses. | ||||||
Validation | invalidOspfInterfaceMD5NotEnabled | Message digest has been chosen as the authentication type but message-digest-key is not configured | ||||||
Validation | upgradeCannotBeStartedWhenBaseIsMissing | Upgrade cannot be started when 'BASE' license is missing | ||||||
Validation | invalidTarget | Validation failed due to an invalid relationship target: "{0}" | ||||||
Validation | exceedLimitEnabledIkev2Policies | The maximum number of IKEv2 policies enabled has already been reached ({0}). Please disable the unused policies. | ||||||
Validation | diskFileNameInvalid | Disk file name cannot be null or empty or longer than 60 characters. It can start with an alphanumeric character or an underscore and contain the special characters +, ., _ and - | ||||||
Validation | sequenceNumberNotUnique | Sequence number needs to be unique across all entries. | ||||||
Validation | vdbUpdateError_17 | This version of VDB is already installed. | ||||||
Validation | s2sVTIRemoteNetworksNotAllowed | You cannot configure the remote networks when using a static virtual tunnel interface for a site-to-site VPN connection. | ||||||
Validation | vtiIPv4Netmask | You must provide an IPv4 address and netmask. | ||||||
Validation | CannotUpdateDefaultNapDescription | You cannot update the description of the default Network Analysis Policy. | ||||||
Validation | moveToDeployDirFailed | Unable to move the package to the deploy directory. | ||||||
Validation | acRuleNetworkObjectSubtypesNotSupported | Access list contains network-object of un-supported sub-types. | ||||||
Validation | invalidEigrpALLONES | 255.255.255.255 is not a valid Router ID. | ||||||
Validation | invalidSmartCliBranchRequired | Incomplete configuration, at least one command must be enabled for the chosen value {0} | ||||||
Validation | scheduleInvalidTrigger | Unable to schedule job {0}. Invalid start trigger. | ||||||
Validation | smartAgentManagerWasNotInitialized | SmartAgentManager was not initialized | ||||||
Validation | ftdUpdateMgrError_132 | Invalid command option. | ||||||
Validation | failedToDiscardPendingChanges | You cannot discard pending changes. The system must complete a successful deployment before you can have the option to discard pending changes. | ||||||
Validation | bgpGracefulStalePathTimeWithoutGracefulRestart | Graceful restart should be enabled before setting stale path time | ||||||
Validation | invalidSmartCliDuplicateConfiguration | You have already configured the command with the same values | ||||||
Validation | invalidSmartCliInterfaceNameRequired | Interface associated with {0} object of {1} (Smart CLI) should have a non-empty NAME. | ||||||
Validation | natNotSupportedNetworkObjects | You cannot use FQDN or IP-Range network objects in this field of the NAT rule. | ||||||
Validation | cannotChangeNameOfDynamicDNSTrustedCAGroup | You cannot change the name of Dynamic-DNS-Trusted-CA-Group. | ||||||
Validation | HTTPProxyAuthenticate | Enter username and password for the http proxy server. | ||||||
Validation | globalBroadcastAddressNotAllowedAsFMCHost | FMC Host of "{0}" cannot be a global broadcast address. | ||||||
Validation | registrationFailure | The device is not registered. | ||||||
Validation | invalidDuplicateMetricsName | Validation failed due to duplicate metric-name configured. | ||||||
Validation | AnyConnEmptyPackages | No any-connect package file is included, please upload and select at least one | ||||||
Validation | RaVpnConnectionProfileSAMLSecondarySource | The secondary authentication source cannot be a SAML server. | ||||||
Validation | invalidTimeoutSpecified | Timeout value has to be in the range {0} and {1} | ||||||
Validation | ftdUpdateMgrError_186 | Revert operation is not yet available. Try again after upgrade completes. | ||||||
Validation | s2sIkev2CertificateNotSpecifiedWhenAuthMethodCert | An internal certificate for IKEv2 policy must be provided when authentication via certificate is selected | ||||||
Validation | manualNatDuplicateRule | Another manual NAT rule is found to have identical address and port translation | ||||||
Validation | contextUpdateFailed | Could not update device registration context. Please try again. | ||||||
Validation | scheduleInvalidType | Unable to schedule job. Invalid type. | ||||||
Validation | invalidOspfInterfaceNeighborsDefined | Operation cannot be performed. An OSPF neighbor is defined for the interface {0} in the object {1} | ||||||
Validation | acRuleOverlapCountryContinentDestNetworks | The destination networks should not contain both country {0} and continent {1} | ||||||
Validation | RaVpnConnectionProfileSAMLTypeNeedsSAMLSource | If the authentication method is SAML, the identity source must be a SAML Server. | ||||||
Validation | interfaceCannotHaveIpv6AddressOfBgpNeighbor | An interface cannot have the same IPv6 address as a neighbor in BGP. | ||||||
Validation | portConflictWithIdentityPolicyPort | Port value cannot be the same as the existing Identity Policy object's active authentication port value. | ||||||
Validation | objectNatTransNetIsNullAndIntfInTransNetIsFalse | You must specify an address or interface for the translated address | ||||||
Validation | invalidInstrumentationKey | Instrumentation Key field should be in the valid UUID format. | ||||||
Validation | appFilterInvalidTagName | Invalid application filter tag name {0}. | ||||||
Validation | invalidNetworkSubtypeForDataInterface | The management access rule for the data interfaces contains a network object of an unsupported type. | ||||||
Validation | acPolicyNapNotSupportedSnort2 | Specifying the access policy's network analysis policy is not support in Snort 2. | ||||||
Validation | appFilterInvalidTagValue | Invalid application filter tag value {0}. | ||||||
Validation | cannotNotFindValue | Validation of depending objects could not be done successfully. The system failed to resolve the references of this entity for the depending objects. | ||||||
Validation | invalidOspfNsfIetfOnly | NSF IETF requires Opaque LSA, IETF helper enabled and LLS capability, Cisco helper negated | ||||||
Validation | noUpgradeDetected | There is no major upgrade operation in progress. | ||||||
Validation | cannotChangeNameOfUser | You cannot change the username of a user | ||||||
Validation | FMCRegistrationSettingsInvalidCreation | Cannot create more than one FMCRegistrationSettings object. Please delete the existing one before creating a new FMCRegistrationSettings object. | ||||||
Validation | zoneCannotBeDeletedIfECMPRouteExists | You cannot delete "{0}". ECMP Traffic Zones cannot be deleted if equal-cost static routes exist across multiple interfaces from ECMP Traffic Zone. The following static routes need to be deleted first: [{1}] | ||||||
Validation | SecurityIntelligenceDNSPolicyMoreThanOne | You cannot have more than one Security Intelligence DNS Policy. | ||||||
Validation | installOnStandbyNode | The standby node of an HA pair may not install a new SRU package; upload only is authorized. | ||||||
Validation | sruUpdateError_17 | Error downloading rule update, file is corrupt (Incorrectly Signed). Please contact technical support. | ||||||
Validation | unsupportedNetworkType | {0} {1} | ||||||
Validation | invalidOspfAreaDupPrefixFilter | Only one prefix list can be configured in either direction | ||||||
Validation | bgpDuplicateNetworksNotAllowed | Duplicate networks are not allowed | ||||||
Validation | cannotAddSourceTunnelInterfaces | Interface {0} is the source interface for a virtual tunnel interface (VTI). You cannot include it in an ECMP traffic zone. | ||||||
Validation | CannotUseApiDuringSnortToggle | This API cannot be used during a Snort toggle job. | ||||||
Validation | appFilterDupCondition | The application filter contains identical conditions. | ||||||
Validation | CannotImportRuleFileInSnort2 | You cannot import a custom rule file in Snort 2 mode. | ||||||
Validation | DomainNameGroupIsNotEqualToGlobalWhiteOrGlobalBlackList | Domain Name Group is not equal to global Block or Do Not Block list, it's allowed only to change domain names for Domain Name Group. | ||||||
Validation | invalidOspfDuplicateNetwork | {0} has already been configured | ||||||
Validation | managementInterfaceCannotBeParent | You cannot create a subinterface on the Management interface {0} | ||||||
Validation | cannotConfigureMacAddress | You cannot configure MAC address on interface {0} when it is in {1} mode. | ||||||
Validation | memberInterfaceModeNotSupportedForEtherChannels | You cannot add a switch port mode interface to an EtherChannel. | ||||||
Validation | ipsecNoEnabledIkev1PoliciesWithPreshareAuth | Cannot disable or delete IKEv1 policy with pre-shared key authentication, need at least one policy active while a site-to-site connection profile using IKEv1 exists | ||||||
Validation | externalBrowserPackageInvalidName | Invalid file name. The external browser package file name must end in .pkg. | ||||||
Validation | etherChannelSpeedMatchMemberInterfaceCommon | EtherChannel speed must match common member interface speed capability: {0}. | ||||||
Validation | invalidFlexCliNoBlocks | A group of blocks can be empty but not null | ||||||
Validation | invalidFlexCliLineSyntax | Syntax error with Flex Config CLI line: {0} | ||||||
Validation | AnyConnPrefillUsernameFromCertificateNotEnabled | Please enable PrefillUsernameFromCertificate to update DisablePrefilledUsernameEdit. | ||||||
Validation | objectNat46PrivateIpv4IsNotAllowedWithNat46WellKnownPrefix | The private IPv4 address "{1}" in original address "{0}" is not allowed with the well known NAT64 prefix "64:ff9b::" in the translated address | ||||||
Validation | aceLogIntervalNull | The log interval cannot be set to null when the logging option is enabled. | ||||||
Validation | sameIPGateway | IP address and Gateway cannot be same | ||||||
Validation | SecurityIntelligenceNetworkPolicyMoreThanOne | Cannot have more than one Security Intelligence Network Policy. | ||||||
Validation | invalidStateName | Invalid State name | ||||||
Validation | realmSequenceIsEmpty | Realm Sequence Object should contain at least one Identity Realm. | ||||||
Validation | vtiTunnelSourceNotNamed | An interface used as a tunnel source interface for a virtual tunnel interface must be named. | ||||||
Validation | interfaceBreakOutJoinIntfUsed | Interface {0} is being used in {1} with name {2}. Interface cannot be {3}. | ||||||
Validation | interfaceCannotMarkMissing | An error occured while scanning the no longer available interface {0} | ||||||
Validation | deviceEnrollmentAlreadyInProgress | The device enrollment with the Cisco cloud is already in progress. | ||||||
Validation | sruUpdateError_5 | The system could not download the update file. Please try again later. | ||||||
Validation | InvalidBgpNeighborMigrationLocalAsBgpAsNumber | Cannot have local-as number same as BGP AS number. | ||||||
Validation | InvalidSecurityLevelForRuleGroup | Invalid security level for rule group: {0}. | ||||||
Validation | featureCapabilitiesNoHandlers | No features capabilities handlers found in application context files | ||||||
Validation | ddnsUsernameShouldBeNull | Username should be set to null for Custom URL Service Provider. | ||||||
Validation | multicastAddressNotAllowed | The IP address cannot be a multicast address. | ||||||
Validation | interfaceInDHCPServerContainer | The interface {0} is already configured as DHCP auto configuration. You must remove it before adding the interface to a bridge group | ||||||
Validation | bridgeGroupInterfaceMemberIsMgmtOnly | Management interface {0} cannot be Bridge Group member interface | ||||||
Validation | RuleGroupChildNotAllowed | Custom intrusion rule group must not include any child rule groups. | ||||||
Validation | identityRealmDuplicateAD | There is already an AD configured with the Hostname {0} and Port {1} | ||||||
Validation | unsupportedSSPInterfaceFECType | Unsupported SSP Interface FEC (Forward Error Correction) Type on SSP Platform: {0} | ||||||
Validation | cloudResponseReadFailed | Snort 3 cloud update failed: Error reading response data from the update server. | ||||||
Validation | intfUsedInEtherChannel | Interface {0} is being used in an EtherChannel. | ||||||
Validation | invalidLineConfiguration | Line is not correctly configured. Please check the qualifiedPath and selfId values. | ||||||
Validation | invalidFxosVersion | Current FXOS version is {0}. This upgrade is for FXOS versions greater than or equal to {1}. | ||||||
Validation | vlanInterfacesLimit | You cannot create more than {0} VLAN interfaces on this device. | ||||||
Validation | newInstanceWithMetadata | Validation failed, attempting to create an object with pre-populated metadata | ||||||
Validation | invalidMalwareLicense | Malware license is not enabled | ||||||
Validation | timeZoneInvalidISOTime | Invalid startTime or endTime. Use the format HH:MM, with time in 24-hour notation. The hour (HH) must be 0-23, and the minutes (MM) must be 0-59. | ||||||
Validation | HashCountLimitExceeded | Hashcount limit has exceeded 10000 hashes | ||||||
Validation | ipsecExcessIkev2Policies | The maximum number of IKEv2 policies enabled has already been reached ({0}) | ||||||
Validation | s2sOverlapNetworks | Site-to-Site profile {0} has overlapping local and remote network address space with profile {1} | ||||||
Validation | geoUpdateError_6 | The latest GeoDB update is already installed | ||||||
Validation | vlan1CannotBeDeleted | VLAN 1 is the default VLAN interface and cannot be deleted. | ||||||
Validation | CouldNotFindBasePolicy | Could not find a base policy using the ID provided. | ||||||
Validation | s2sIkev2MaskedLocalKeyNotAllowed | Masked value for IKEv2 pre-shared local key is not allowed with connection profile creation | ||||||
Validation | linaUnableToResolveHostname | Unable to resolve the hostname {0} to an IP Address | ||||||
Validation | DHCPServerAutoConfigName | This interface is being used for DHCP auto configuration. You cannot remove the interface name until you change the DHCP server auto configuration settings. | ||||||
Validation | cfgImpInvalidObjTypesInExcludeEntities | Invalid entity types in exclude-entities matchers: {0} | ||||||
Validation | SecurityIntelligencePolicyEventLogOffWithSyslogOn | You cannot enable syslog with event log disabled | ||||||
Validation | FMCConnectivityPortPerlError | Failed to retrieve FMC Connectivity Port. | ||||||
Validation | missingRealmInAuthRule | No realm found in an identity Rule that uses the Auth action. | ||||||
Validation | s2sVTINoNATExempt | You cannot specify a NAT exempt interface when using a static virtual tunnel interface for a site-to-site VPN connection. | ||||||
Validation | customRulesFileImportSuccess | Successfully imported rules. | ||||||
Validation | cannotBeMgmtInterface | The interface is configured in {0} mode. You cannot configure it to be management interface. | ||||||
Validation | CannotImportEmptyFile | You cannot import an empty file. | ||||||
Validation | cannotCreateFMCRegistrationSettingsInUPLRMode | FMC registration is not supported when device is licensed in Universal PLR mode. Please unregister the device from Universal PLR before continuing with FMC registration. | ||||||
Validation | geoUpdateError_13 | GeoDB update file is not valid. | ||||||
Validation | cryptoNonCompliantIkev1Policy | The IKEv1 policies are using DES encryption which is disallowed when the Smart License Account has export-controlled features enabled: {0}. | ||||||
Validation | invalidBgpNeighborInterface | BGP Neighbor cannot have the same IP address as that of a device interface | ||||||
Validation | invalidOspfAreaIdLeadingZero | Numeric Area ID should be an unsigned integer without leading zeros | ||||||
Validation | invalidEigrpVRF | You can configure EIGRP in the global virtual router only. | ||||||
Validation | invalidBgpNetworkManagementInterfaceConfigured | BGP is not supported on management-only interface | ||||||
Validation | errorWhenRunningCLI | Cannot retrieve hardware bypass information | ||||||
Validation | invalidTopLevelDomainName | The top-level domain must start with an alphabetic character. | ||||||
Validation | snort2ForceInstallingInProgress | Snort 2 Package Installation in progress. | ||||||
Validation | invalidTrackId | Track ID value must be between 1 and 500. | ||||||
Validation | invalidBaseLicense | Base license is not enabled | ||||||
Validation | SSLSettingProtocolVersionsNotOrdered | You cannot skip a protocol version between start and end range. Missing protocol versions are {0}. | ||||||
Validation | unexpectedPLRUnsuccessfulGetReleaseCode | Unable to attain Release Code for Universal Permanent Licensing. Inputted authorization code may be incorrect or was not installed. | ||||||
Validation | invalidMalwareLicenseForFilePolicy | Missing Malware License. The associated file policy or rule requires this license. | ||||||
Validation | removeExistingIPFromHAInterface | Interface {0} is configured with IP addresses. You must remove the IP address configuration to use this interface for the failover or stateful failover interface. | ||||||
Validation | invalidObjectForSupportedNetworkObjectAnnotation | Invalid object type for SupportedNetworkObject annotation. | ||||||
Validation | ipPoolStartEndIpNotInSameSubnet | Start and end IP address are not in the same sub-net with given sub-net prefix | ||||||
Validation | ruleRevisionMustBeLarger | The updated rule must have a higher revision number compares to the original. | ||||||
Validation | RaVpnAddressPoolOverlapVal | IP Address Pool {0} with range {1} has overlapping addresses with Address Pool {2} with range {3}. | ||||||
Validation | invalidDupInRouteFilter | Duplicate configuration found for incoming route filter | ||||||
Validation | s2sIkev1ProposalsTooMany | Too many IKEv1 proposals. Number of assigned IKEv1 proposals cannot exceed {0} | ||||||
Validation | invalidSmartCliStringValuePattern | {0} value does not match the pattern it uses | ||||||
Validation | staticRouteInterfaceModePassive | The selected interface {0} used in static route cannot be in passive mode. | ||||||
Validation | vrfIdNotFound | Virtual Router is not found. | ||||||
Validation | genericException | Error: {0} | ||||||
Validation | manualNatTransSrcHasIpv6AndIpv4Addresses | The translated source network should not contain both IPv4 and IPv6 addresses | ||||||
Validation | invalidBGPNeighborPasswordLength | Passwords used for BGP Neighbor authentication cannot contain spaces and must be between 1 and 25 characters | ||||||
Validation | invalidNumericObjectName | The name "{0}" is invalid. The name must be an unsigned numeric value | ||||||
Validation | sruImportError | Failed to import Rule Update package | ||||||
Validation | sruUpdateError_9 | The latest Rulepack update is already installed | ||||||
Validation | sruUpdateError_12 | Unable to copy installed files | ||||||
Validation | invalidURL | Must be a valid URL | ||||||
Validation | acPolicyInvalidIdentityWIthNoSSL | You cannot configure identity policy without enabling SSL policy | ||||||
Validation | NeedAtLeastOneRuleGroup | You need to provide at least one rule group name to create the custom intrusion rule. | ||||||
Validation | interfaceHasSubInterfaces | You cannot configure {0} with an interface that has subinterfaces. Please edit the interface and remove subinterfaces, or select a different interface. | ||||||
Validation | bgpHaNotConfigured | High availability has not been configured. | ||||||
Validation | smartAgentNotReady | Smart Agent is not ready. | ||||||
Validation | attemptToChangeNonEditEtherChannelId | Validation failed, attempt to change a non-editable EtherChannel ID. | ||||||
Validation | fileNotFound | File not Found | ||||||
Validation | RaVpnMaxNumberAddressPoolVal | A maximum of 6 Address Pools are allowed. | ||||||
Validation | invalidOspfInterfaceConflictingInterval | Hello interval({0}) must be set to a value less than Dead interval({1}) | ||||||
Validation | lockTimeout | Unable to acquire the read-lock due to timeout | ||||||
Validation | cannotCreateHardwareBypassPairs | Cannot create hardware bypass Pair. | ||||||
Validation | objectNatDestIntfIsNullWithIntfInTransNetwork | Destination interface cannot be "any" if you select Interface for translated network | ||||||
Validation | SslRulesWithDeletedCategories | Some of the SSL decryption rules refer to deleted URL Categories. Number of SSL decryption rules affected: {0}. | ||||||
Validation | noSpaceAllowOnName | The logical name cannot contain any spaces | ||||||
Validation | s2sInvalidNetworks | Profile cannot have strictly {0} local networks and {1} remote networks | ||||||
Validation | cannotDeleteDynamicDNSTrustedCAGroup | You cannot delete Dynamic-DNS-Trusted-CA-Group. | ||||||
Validation | snort2DownloadInProgress | Snort 2 Package Downloading in progress. | ||||||
Validation | invalidThreatLicense | Threat license is not enabled | ||||||
Validation | PullDiskSpaceNotAvailable | Disk space is not available | ||||||
Validation | IntrusionPolicySnort2CreateNotAllowed | You cannot create an Intrusion Policy in Snort 2 mode. | ||||||
Validation | memberInterfaceCannotBeNamed | An interface with a logical name cannot be a member of an EtherChannel. | ||||||
Validation | registrationKeyBlankValue | Registration Key cannot be blank. | ||||||
Validation | ipsecCombinedModeNullIntegrity | Combined mode encryption must be used with solely null integrity type because combined modes internally set integrity type | ||||||
Validation | s2sConnTypeNotNull | The connection type for a Policy-based site-to-site VPN connection profile must be null. | ||||||
Validation | upgradeFileAndDeviceVersionSame | This upgrade is for the same version as the current device version. You cannot upgrade to the same version. | ||||||
Validation | cloudUpdateFailed | Snort 3 cloud update failed: {0}. | ||||||
Validation | snort3RuleParsingInProgress | Snort 3 rule parsing in progress. | ||||||
Validation | cannotContainPPPOEIpv4Config | The interface is configured in {0} mode. It cannot contain any PPPOE Configuration or IPV4 address. | ||||||
Validation | invalidLicenseForObject | Missing license for object: {0} requires the {1} license | ||||||
Validation | epmInterfaceNotDeployedCannotBeAdded | Network Module Interface {0} is not deployed yet. Perform deployment, and then you can add to an EtherChannel. | ||||||
Validation | BinderRuleInstanceNotFound | Instance {0} not found. | ||||||
Validation | unsupportedIkevTwoProposal | MD5 Hash is not supported in IKEv2 Policies. | ||||||
Validation | stringOutOfRange | The string length should be no less than {0} and no more than {1} | ||||||
Validation | entityNotFoundWithUuid | Failed to find DB entity of type {0} with UUID {1} | ||||||
Validation | invalidCountryCode | Invalid Country code | ||||||
Validation | standbyIPWithoutActiveIPAddress | Standby IP Address cannot be specified without an active IP Address. | ||||||
Validation | interfaceReferencedInOspfNeighbor | Interface cannot be updated when referenced in OSPF neighbor. You must remove the neighbor before updating the interface. | ||||||
Validation | DapXmlDfltPriorityInvalid | Cannot provide priority for default DAP record | ||||||
Validation | InvalidRuleGroupsString | Invalid value provided for ruleGroups, please specify a comma-separated list of IDs. | ||||||
Validation | invalidWebUrlPattern | Invalid DDNS Web URL. | ||||||
Validation | s2sIkev1ProposalsEmpty | IKEv1 proposals cannot be null or empty | ||||||
Validation | s2sMoreThanOneDynamicPeer | Only one Site-to-site profile can have a dynamic peer. | ||||||
Validation | invalidNetworkType | The NetworkObject {0} is invalid. NetworkObject must be of type Host. | ||||||
Validation | AnyconnInvalidClientPackage | AnyConnect client file uploaded is invalid {0} | ||||||
Validation | interfaceHasSubIntfBreakOutJoinFail | Interface {0} has {1} subinterface. Interface cannot be {2} until subinterfaces are deleted. | ||||||
Validation | interfaceWithDHCPAddress | HA cannot be enabled when interface {0} has a DHCP address. | ||||||
Validation | invalidSmartCliCommunityListValue | {0} entity value must be an existing Standard or Expanded Community List Object | ||||||
Validation | invalidEigrpRedistDuplicateConf | Multiple configurations found for the protocol {0}. | ||||||
Validation | s2sNoDynamicRRI | Dynamic reverse route injection cannot be configured on site-to-site VPN when Dynamic Crypto Map or IKEv1 policy are enabled | ||||||
Validation | RaVpnSecAuthNotValidOnCertOnly | Secondary Authentication not valid on selected Authentication method. | ||||||
Validation | objectUsageInvalidUuidParam | Uuid parameter used in object usages search for type "{0}" is invalid. | ||||||
Validation | currentAndNewPasswordCannotBeTheSame | Current and new password cannot be the same | ||||||
Validation | s2sOutsideIntfIsNullOrEmpty | Site-to-Site VPN outside-interfaces cannot be null or empty | ||||||
Validation | AnyConnDnsExcess | There can only be a maximum of two servers for {0} | ||||||
Validation | DHCPServerIPPoolRange | The interface DHCP server address pool {0} is not on the same subnet as the interface IP address, {1}. The pool must be on the same subnet and it cannot contain the interface IP address. If you are changing the interface IP address, you must first delete the DHCP server. | ||||||
Validation | InvalidBgpNeighborDupRouteMapFilter | Only one route map can be configured in either direction | ||||||
Validation | vdbUpdateError_14 | VDB successfully updated but skipping deployment as this is a STANDBY device. | ||||||
Validation | manualNatSrc46PrivateIpv4IsNotAllowedWithNat46WellKnownPrefix | The private IPv4 address "{1}" in original source "{0}" is not allowed with the well known NAT64 prefix "64:ff9b::" in the translated source | ||||||
Validation | invalidDefaultLoggingValues | When the logging option is set to default, the log level and log interval must be null. | ||||||
Validation | incompatibleTypes | ICMP Code and Type are not compatible. | ||||||
Validation | ipsecPolicyNeedGroup | Policy must have at least one DH group | ||||||
Validation | interfaceBreakOutJoinIntfUsedNoName | Interface {0} is being used in {1}. Interface cannot be {2}. | ||||||
Validation | passwordTooShort | Password is too short. The password needs to be at least 8 characters long | ||||||
Validation | invalidEigrpRedistBgpIdentifier | Identifier value {0} does not match the BGP autonomous system number in use. | ||||||
Validation | sameOperationInprogress | Another user or the system might be performing the same operation, please try again later. | ||||||
Validation | exceededNumCerts | Number of external certificates must not exceed 10. | ||||||
Validation | interfaceWithPassiveMode | You cannot use an interface in passive mode for HA configuration. | ||||||
Validation | s2sCryptoEnabledIkev1Proposals | S2S VPN uses IKEv1 proposals with DES encryption. DES is not supported when strong encryption is enabled. | ||||||
Validation | interfaceBreakoutOrJoinIntfHAMonitoringEnabled | Interface {0} is named, enabled and has HA Monitoring enabled. Interface {1} cannot be {2}. | ||||||
Validation | invalidSpeedDuplexPair | You cannot select 1000 or 10000 Mbps when Duplex is "Half" | ||||||
Validation | acRuleDestTcpProtocolNotAllowedWithTcpDestPort | You cannot add a destination TCP protocol object with destination TCP ports: {0} | ||||||
Validation | PullFileSizeCheckFailed | File upload failed - Invalid file size. | ||||||
Validation | upgradeFileNotFoundOnDisk | Upgrade file not found on disk. | ||||||
Validation | snmpInvalidEncryptionPasswordLength | Encryption password should be an encrypted string with length 8 - 257 characters. | ||||||
Validation | unknownHostName | Could not determine device hostname. | ||||||
Validation | opensslCertificates | Failed to verify the certificate chain | ||||||
Validation | uncommitedChanges | You must deploy all uncommited changes before starting a system upgrade. | ||||||
Validation | ftdUpdateMgrError_181 | Syntax error: Revert-to version not provided. Use 'show upgrade revert-info' API to determine available revert versions. | ||||||
Validation | noBaseLicense | Cannot add a license when the base license is not present | ||||||
Validation | unexpectedPLRUnsuccessfulGetRequestCode | Unable to attain Request Code for Universal Permanent Licensing. | ||||||
Validation | manualNatStaticTransSrcNotNullAndIntfInTransSrcIsTrue | You cannot select both a translated address and interface for the translated address in static NAT | ||||||
Validation | invalidSmartCliStandardAccessListValue | {0} entity value must be an existing Standard Access List Object | ||||||
Validation | interfaceFecModeUnsupportedPlatform | Forward Error Correction is not supported on this platform. | ||||||
Validation | ipsecNoEnabledIkev2Policies | Cannot disable or delete IKEv2 policy, need at least one policy active while a site-to-site connection profile using IKEv2 exists | ||||||
Validation | objectNatOrigNetworkIsNull | You must specify an original address in an auto NAT rule | ||||||
Validation | snmpUnsupportedSecurityConfiguration | The specified security configuration is not supported. Supported versions are v1, v2c and v3. | ||||||
Validation | HTTPInvalidPassword | Password must be 8 to 16 characters long. | ||||||
Validation | staticRouteNoNetworks | Static route should have at least one network | ||||||
Validation | manualNatSrc64AnyIpv6NotValid | The network corresponding to the full range of IPv6 addresses, i.e. ::/0, cannot be used in the source of an IPv6 to IPv4 manual NAT rule | ||||||
Validation | interfaceFecCanBeSetOnlyForPhysicalInterface | Interface {0} isn't a physical interface; you cannot set the FEC mode. | ||||||
Validation | invalidVlanId | Default VLAN is not correctly set on the device. | ||||||
Validation | interfaceDuplexWithSFPPorts | Interface {0} is of SFP type and must have Duplex set to FULL. | ||||||
Validation | ddnsUsernameRequired | Username is required. | ||||||
Validation | ftdUpdateMgrError_161 | No upgrade in progress. | ||||||
Validation | smartAgentUninitialized | Smart Agent was not initialized. | ||||||
Validation | haMonitoredNamedInterfaceCannotBeAdded | Cannot add a deployed, named and HA monitored {0} interface to this EtherChannel. Please remove interface monitoring or name, perform deploy and then try adding the interface as the member. | ||||||
Validation | PullValidationStarted | Upgrade installer file download is complete. Now validating the downloaded file. | ||||||
Validation | s2sOutsideIntfCannotBeBviMember | Outside interface cannot be a bridge-group member: {0} | ||||||
Validation | invalidTrafficThrottleState | Can not enable traffic throttle if device was in compliance at least once | ||||||
Validation | invalidConnectionEventTypes | You cannot select two different connection event types to send to the cloud. | ||||||
Validation | invalidUmbrellaDnsServerGroup | You cannot change the name or DNS server IP addresses in the system-defined CiscoUmbrellaDNSServerGroup object. | ||||||
Validation | InvalidBgpNeighborDupAccessListFilter | Only one access list can be configured in either direction | ||||||
Validation | ftdUpdateMgrError_245 | Upgrade failed and the system restarted. Cannot retry. | ||||||
Validation | IntrusionPolicySnort2UpdateRuleNotAllowed | You cannot update an Intrusion Rule for a specific Intrusion Policy in Snort 2 mode. | ||||||
Validation | facReadPerlGeneralError | An unexpected error occurred while retrieving Firepower Analytics Server entity(ies) | ||||||
Validation | aaaUpdatingName | Updating the name for a rule is not supported | ||||||
Validation | acRuleLogEndNotAllowedWithDeny | You cannot log at the end of connection only if the access rule action is Block. | ||||||
Validation | DHCPServerInvalidPlatformSupport | DHCP server is not supported on the following platforms: Virtual FTD, Firepower 4100, Firepower 9300. | ||||||
Validation | invalidV6EndMapped | IPv4-mapped IPv6 as end address is not supported. | ||||||
Validation | AnyConnInsideCannotBePassive | The interface {0} added to AnyConnectProfile is invalid, the inside interface cannot be in passive mode | ||||||
Validation | natIdLengthOutOfRange | NAT ID of "{0}" should be no less than {1} and no more than {2}. | ||||||
Validation | FMCRegistrationDeploymentInProgress | Cannot start FMC registration while deployment is in progress. | ||||||
Validation | invalidInterfaceForRouteMapEntry | A route map cannot include passive interfaces or bridge group member interfaces or an interface which is part of the high availability configuration. | ||||||
Validation | invalidOspfInterfaceEnabled | Selected Interface is enabled. | ||||||
Validation | s2sIkev1InvalidKey | Invalid IKEv1 pre-shared key. It must contain 1 to 128 ASCII printable characters, no whitespace, no single or double quotation marks, no question marks and cannot be a single digit | ||||||
Validation | vpnConnProfileNameIsIpAddress | VPN connection profile name must not be an IP-V4 or IP-V6 address value | ||||||
Validation | invalidManagementInterfaceInDdns | Management interface "{0}" is not allowed in DDNS Service. | ||||||
Validation | invalidNetworkSubtypeForPolicy | Policy contains network-object of un-supported sub-types. | ||||||
Validation | appFilterDupProductivity | Duplicated business relevance selected: {0} | ||||||
Validation | nullAuthToken | The registration key is mandatory. | ||||||
Validation | RaVpnConnProfOnlyRadiusSupported | Only RADIUS Identity source is supported. | ||||||
Validation | invalidNetworkSubtypeForSecIntelligencePolicyBlackList | The Security Intelligence Block list contains a network object of an unsupported type. | ||||||
Validation | vdbUpdateError_18 | VDB update file is not valid. | ||||||
Validation | InvalidOutsideInterface | Invalid outside interface selected. Default outside interface cannot be changed. | ||||||
Validation | evalExpired | Cannot set evaluation mode as it has expired or been interrupted | ||||||
Validation | invalidInterfaceModeInDdns | Interface "{0}" cannot be added to DDNS Service. Only interfaces with ROUTED mode are allowed. | ||||||
Validation | invalidOspfNeighborInterfaceNonBroadcast | Interface {0} network type must be point-to-point non-broadcast | ||||||
Validation | missingVrfId | Virtual Router is not specified. | ||||||
Validation | aaaInvalidUsernameLength | Username is too long. The username must be less than 128 characters long | ||||||
Validation | AnyConnDuplicateFileObj | Cannot create another AnyConnectPackageFile object for platform {0} | ||||||
Validation | licensingJobInProgress | Licensing task is in progress - {0}. Please try after some time | ||||||
Validation | invalidHAFailoverInterfacePollTime | Interface poll time must be between 500 and 999 milliseconds, or 1 and 15 seconds. | ||||||
Validation | ipv6SubnetOverlap | The prefix of IP address {0} overlaps with the prefix of the reserved range {1}, please use a higher prefix value or change the address. | ||||||
Validation | natDynamicRuleNotSupportNoProxyArp | Dynamic NAT does not support the Do Not Proxy ARP option | ||||||
Validation | geoUpdateError_9 | GeoDB installation failure | ||||||
Validation | staticRouteWrongGateway | Gateway is not supported when it's a route leak. | ||||||
Validation | vtiSourceCannotBeUsedByBVI | Interface {0} is being used as a source interface for VTI {1}. You cannot select it as a bridge group member. | ||||||
Validation | vdbUpdateError_9 | VDB Installation Failure | ||||||
Validation | invalidInterface | Management interface {0} is not allowed in security zones | ||||||
Validation | etherChannelCannotBeAddedToBridgeGroupInterface | EtherChannel Interface cannot be added to a Bridge Group Interface. | ||||||
Validation | pppoeObjectIsRequired | The pppoe object is required when the interface type is PPPoE. | ||||||
Validation | IntfModeInvalid | Physical interface {0} is not in ROUTED mode. Only ROUTED mode Physical interfaces can be part of a virtual router. | ||||||
Validation | intfMigrationNotSupportedInputTypes | Migration is not supported on the provided input. Only Interface types can be migrated. | ||||||
Validation | manualNatTransSrcIsNullAndIntfInTransSrcIsFalse | You must specify an address or interface for the translated address | ||||||
Validation | notCryptoCompliant | Current license settings do not allow use of strong cryptography for VPN | ||||||
Validation | newInstanceWithInitializedId | Validation failed, attempting to create a new object with initialized ID | ||||||
Validation | lspPackageNotExist | Can not find an appropriate LSP package for Snort 3. | ||||||
Validation | emptyKeyString | Key String cannot be empty. | ||||||
Validation | internalCertValidationError | There was an error validating the Internal Certificate. | ||||||
Validation | acRuleFilePolicyInvalidAction | The selected access rule action is invalid. You must select the Allow action for a rule that uses a file or intrusion policy | ||||||
Validation | acRuleCannotUseSystemDefinedPolicy | The selected intrusion policy is defined by the system. You must select a custom policy. | ||||||
Validation | s2sNoIkev1LocalAnyNetwork | For IKEv1 connections, a local network spanning the entire IP address space with specific remote networks is not allowed | ||||||
Validation | FMCRegistrationJobStillQueued | FMC Registration job is still queued. | ||||||
Validation | invalidSlaFrequency | The frequency value has to be between 1000 and 604800000 seconds (7 days). | ||||||
Validation | snort3DownloadInProgress | Snort 3 Package Downloading in progress. | ||||||
Validation | DNGroupDupDN | Group contains duplicate distinguished name objects | ||||||
Validation | InvalidParentNameForIOC | Parent Name for Inspector Override Config is not valid. | ||||||
Validation | updateEasysetupStatusWithoutEula | The End User License Agreement has not been accepted, unable to update easy setup status | ||||||
Validation | SSLSettingInvalidDHGroup | Invalid Diffie Hellman Group assigned. Valid values are GROUP_2, GROUP_5, GROUP_14 and GROUP_24. | ||||||
Validation | deviceNotEnrolled | The device is not enrolled with Cisco cloud. | ||||||
Validation | etherChannelSpeedMatchMemberInterfaceSpeedCapability | EtherChannel speed must match member interface speed capability. | ||||||
Validation | vtiMustBeInRoutedMode | Virtual Tunnel Interface must be in ROUTED mode. | ||||||
Validation | initialDeploymentNotPerformed | You must deploy changes at least once before you can upgrade the system software. | ||||||
Validation | ddnsWebURLRequired | Web URL is required. | ||||||
Validation | featureCapabilitiesGeneralException | Unable to build feature capabilities platform file | ||||||
Validation | invalidOSPFAreaNetworkVlanInterface | VLAN interface falls in the same network as Area network. OSPF can not be configured on VLAN interface. | ||||||
Validation | markAsSystemDefined | You cannot mark custom object as the system defined. | ||||||
Validation | passiveInterfaceCannotBeUsed | DHCP Relay Service cannot use the Passive interface {0}. | ||||||
Validation | invalidNetworkSubtypeForSecIntelligencePolicyWhiteList | The Security Intelligence Do Not Block list contains a network object of an unsupported type. | ||||||
Validation | invalidOspfVirtualLinkRouterId | Multiple peer router id values specified for the same virtual link | ||||||
Validation | invalidSmartCliStringValueChar | {0} value cannot contain spaces or reserved characters | ||||||
Validation | ErrorParsingRulesFile | Encountered an error when parsing the rules file. Showing {0} of {1} lines parsed from error file: {2}. | ||||||
Validation | adiCliTestCannotReachMQ | The connection test failed because ADI is not reachable. | ||||||
Validation | invalidDeviceMetrics | At least one device metrics should be configured. | ||||||
Validation | entityNotFoundWithName | Failed to find DB entity of type {0} with name {1} | ||||||
Validation | appFilterInvalidCatName | Invalid application filter category name {0}. | ||||||
Validation | s2sOutsideIntfIsPassive | You cannot use a passive mode interface for the outside interface of a site-to-site VPN connection. | ||||||
Validation | manualNatOrigDestNotNullAndIntfInOrigDestIsTrue | You cannot select both an address and interface for the original destination | ||||||
Validation | invalidMtuMIO | Invalid MTU for Firepower 4100/9300 device. You can set the MTU up to 9184 for this platform. | ||||||
Validation | invalidSpeedCapability | The interface does not support this speed | ||||||
Validation | bridgeGroupCannotHaveVlanAndOtherInterfaces | Bridge group member interfaces can either be all VLAN interfaces or physical/subinterfaces, but not both. | ||||||
Validation | snort3ToggleSuccess | Successfully switched to Snort version 3. | ||||||
Validation | cryptoCompliantSSLCipher | The Data SSL Cipher Setting is using SSL ciphers with strong encryption which is not allowed by your licensing setting, please de-reference them. | ||||||
Validation | geoUpdateError_1 | Unable to connect to update server | ||||||
Validation | queryParameterValueNotValid | Query parameter "{0}" is not valid because it contains semicolon or parenthesis. | ||||||
Validation | invalidHoldTimeKeepAliveTime | The keep alive time and hold time values must either both be zero, or both non-zero. You cannot have zero for one and non-zero for the other. | ||||||
Validation | invalidAccessKey | Access Key field should contain only Alpha-Numeric characters with length equals 20. | ||||||
Validation | contextDeletionSucceed | Device has been unregistered. | ||||||
Validation | pppoeNotSupportedOnBridgeGroupnterface | PPPoE is not supported on a Bridge Group Interface. | ||||||
Validation | deployPackageNotFound | You must first deploy the configuration before you can restore a backup | ||||||
Validation | s2sVTIDynPeerNotAllowed | You cannot use a dynamic remote peer when using a static virtual tunnel interface for the site-to-site VPN connection. | ||||||
Validation | invalidSmartCliNumericMaxValue | {0} value cannot be greater than {1} | ||||||
Validation | MustSpecifyBaseNapPolicy | You must choose a base Network Analysis Policy. | ||||||
Validation | featureCapabilitiesMissingHandler | Feature capabilities handler {0} can not be found in context | ||||||
Validation | parentInterfaceIsSwitchport | You cannot create a subinterface on the Switchport interface {0} | ||||||
Validation | snort2ToggleSuccessWithUpdate | Successfully switched to Snort version 2 with rule package updated. | ||||||
Validation | cannotEditIPOfBridgeGroupInterfaceMember | Interface {0} is a member of BridgeGroup Interface {1}. You cannot edit ip address for Interface {0} | ||||||
Validation | snmpBothTrapAndPollCannotBeDisabled | Both Trap and Poll cannot be disabled. You must enable at least one. | ||||||
Validation | acRuleSrcTcpPortWithOtherDestPort | When you specify source TCP ports, the destination ports should either be empty or contain at least one TCP port | ||||||
Validation | PullFileChecksumFailed | File upload failed due to checksum failure | ||||||
Validation | cannotUseIntfInRavpn | Port conflict. This interface is being used for remote access VPN on port {0}. You must either change the RA VPN port, or configure a different port number for HTTPS management access. | ||||||
Validation | invalidOspfInterface | An interface with OSPF configuration must be enabled and cannot be in passive mode, or be a bridge group, or be a VLAN interface, or a member of a bridge group, or be part of the high availability configuration. | ||||||
Validation | modeMisMatch | The mode for interface {0} does not match the mode of the security zone {1}. | ||||||
Validation | s2sLifetimeKB | Site to Site profile Lifetime Range should be between 10 and 2147483647 kilobytes | ||||||
Validation | basePolicyNotFound | Base Policy {0} not found in incoming LSP package. Please delete all Custom Intrusion Policies using this base policy and retry. | ||||||
Validation | manualNatDest64Ipv6PrefixTooLong | The original destination IPv6 network prefix length must be less than or equal to 96 in an IPv6 to IPv4 manual NAT destination translation rule: {0}({1}) | ||||||
Validation | cryptoNonCompliantIkev2PolicyForIntegrityType | The upgraded IKEv2 policies use MD5 as Integrity which is not supported on this FTD version: {0}. | ||||||
Validation | RaVpnConnProfUserNameSettingsNotSupported | Username Settings are not supported for this Authentication Type of AAA only | ||||||
Validation | switchPortConfigurationNotNull | Interface {0} cannot have a switch port configuration when it is in {0} mode. | ||||||
Validation | AnyConnRealmEncryptionTypeNotSupported | Realm server encryption type not supported by AnyConnect. | ||||||
Validation | acRuleUnnamedInterfaceInSourceZone | Source security zone {0} contains an un-named interface that cannot be used in an access rule | ||||||
Validation | SSLPolicyAppFilterAppsMustHaveSSL | SSL rule cannot contain application filter with applications that do not use SSL | ||||||
Validation | invalidLineInstance | Instance does not match with the template it uses. Found mismatch in the properties "{0}" of Line having selfQualifier "{1}". | ||||||
Validation | routeMetricIsOutOfRange | The Route Metric must be between 1 and 255 | ||||||
Validation | invalidSHA512Checksum | The checksum is not valid. | ||||||
Validation | diagIntfMgmtIntfIpv6 | You cannot configure the same IPv6 address for the management interface and the diagnostic physical interface. | ||||||
Validation | DHCPServerAutoConfigInterface | DHCP server auto config requires a default interface | ||||||
Validation | invalidServerSecretKeyLength | The server secret key exceeds the length limit, which is 64 characters. | ||||||
Validation | RaVpnConnectionProfileSAMLDuplicate | The SAML Server {0} is already in use in a connection profile. | ||||||
Validation | numberofinterfacesDoNotMatch | The number of interfaces in Lina do not match with the number in SSP | ||||||
Validation | staticRouteManagementOnlyInterface | There are static routes configured for this interface. You must delete the static routes before changing the interface to management-only. | ||||||
Validation | invalidMaskedPasswordString | Password cannot be the reserved masking string: "{0}" | ||||||
Validation | timeZoneInvalidTimeZoneId | Invalid TimeZone Id. A valid UTC TimeZone ID must be provided for TimeZoneObject configuration. | ||||||
Validation | memberInterfacesNotAtLeastOneCommonSpeedCapability | The selected member interfaces do not share a common speed capacity; you can only include interfaces that can operate at the same speed. | ||||||
Validation | invalidWebUpdateType | Web Update Type "{0}" is not supported for Google Service Provider. | ||||||
Validation | SSLPolicyNoKeysForKnownKey | You must identify at least one internal certificate to configure decrypt known-key rules in the SSL decryption policy | ||||||
Validation | sruUpdateError_10 | 3D version mismatch, unable to proceed with installation | ||||||
Validation | invalidBgpNetworkBridgeGroupInterface | A Bridge group interface was configured for the same network. BGP cannot be configured on BVI interfaces. | ||||||
Validation | snort3NoPlatformSupport | Snort 3 does not support the current platform. | ||||||
Validation | cannotUseDataInterfaceInVirtualPlatform | Data interface cannot be assigned to Connectivity Interface in virtual platform. | ||||||
Validation | encProtocolCannotBeNullWithCert | A certificate has been provided but no encryption protocol has not been provided | ||||||
Validation | easySetupCompletionFailed | The device setup wizard was not completed. | ||||||
Validation | invalidV6Mapped | IPv4-mapped IPv6 addresses are not supported. | ||||||
Validation | natDestinationModePassive | Destination interface {0} is in passive mode. You cannot a use passive mode interface in NAT rules : {1} | ||||||
Validation | timeZoneInvalidISODate | Invalid startDateTime or endDateTime. Use the ISO format YYYY-MM-DDTHH:MM, with time in 24-hour notation. The hour (HH) must be 0-23, and the minutes (MM) must be 0-59. | ||||||
Validation | conflictingFlexConfigPolicy | There are FlexConfig objects in the FlexConfig policy that include prohibited commands. You must either remove the prohibited commands from the objects, or remove the objects from the FlexConfig policy. | ||||||
Validation | blacklistedCli | You are not allowed to use the following commands in the object: | ||||||
Validation | acRuleInvalidRiskReputation | You must specify a valid reputation | ||||||
Validation | ftdUpdateMgrError_162 | Upgrade or cancel upgrade already in progress. Cannot cancel. | ||||||
Validation | switchModeNotSupported | Switch mode is not supported on this platform. | ||||||
Validation | interfaceMigrateSourceAndDestinationMustBeInterfaces | Source and destination IDs must belong to interfaces. | ||||||
Validation | nestedNetworkGroupMaxNestingLevel | This network group has more than 10 levels of nested objects, which is the maximum allowed nesting level. | ||||||
Validation | snmpHostInterfaceNameNull | Interface associated with an SNMP Host must have a valid name. | ||||||
Validation | AnyConnAddressPoolTooBig | {0} address pool is too large, {1} contains more than 16384 addresses | ||||||
Validation | ntdDbCreationFailed | Snort 3 rule package installation failed: Unable to create ntd.db. | ||||||
Validation | invalidFMCConnectivityInterfaceManagementIntfNotRoutedToDataIntf | Connectivity Interface cannot be a data interface when management interface has a gateway address or not routed to a data interface. | ||||||
Validation | ipsecPolicyNeedIntegrity | Policy must have at least one integrity checking method | ||||||
Validation | cfgExpEmptyEncryptionKey | You must specify an encryption key to encrypt the zip archive generated by the configuration export job | ||||||
Validation | cfgImpEmptyConfigInput | No configuration data is specified for the import job. Please specify either a config-file ID or input entities | ||||||
Validation | cannotCreateOrEditLDAPRealm | Cannot create or edit LDAP Realm | ||||||
Validation | objectNatStaticTransNetNotNullAndIntfInTransNetIsTrue | You cannot select both a translated address and interface for the translated address in static NAT | ||||||
Validation | invalidGatewayForInternalRouting | You cannot specify a gateway when you are routing management traffic through the data interfaces. | ||||||
Validation | AnyConnOverlapNetworks | Address pool {0} has address space overlap with the selected inside networks | ||||||
Validation | cliCommandSpaceBeforeAndAfterPipe | Space not present before/after pipe symbol. | ||||||
Validation | ftdUpdateMgrError_182 | No revert version available. Cannot revert. | ||||||
Validation | vtiCannotModifyTunnelId | Cannot modify the tunnel ID of the Virtual Tunnel Interface as it is being used by another object. If this object is already deployed, you will need to remove the reference to the VTI in the object and redeploy. | ||||||
Validation | cannotCreateBaseLicense | The base license cannot be created | ||||||
Validation | portNotExpected | The protocol type selected does not require a port. | ||||||
Validation | fileMalwareSyslogServerRequired | File malware syslog server is required. | ||||||
Validation | invalidLoggingListInvalidOPtions | Please provide either message ID or class. | ||||||
Validation | attemptToChangeNoneditHardwareName | Validation failed, attempt to change a non-editable name | ||||||
Validation | invalidSmartCliStringValuePatternAnnotation | {0} value does not match the pattern it uses | ||||||
Validation | invalidRAVPNUsernameLength | Invalid username length. Username length should be between {0} to {1} characters | ||||||
Validation | emptySSHAAASettingServerSecretKey | AAASetting for SSH access cannot reference a {0} that has a {1} with an empty server secret key; "{2}" contains an empty server secret key | ||||||
Validation | addressDoesNotMatchPrefixLength | The IP Address {0} does not match with the prefix length {1}. To specify a network use {2}/{3}. To specify a host use {4}. | ||||||
Validation | PullFileSuccess | File upload was successful | ||||||
Validation | sseGetTokenAndRegionFailed | Error in connecting to SSE Registration server to get token and domain. | ||||||
Validation | invalidConnectionType | The Connection Type entered for Smart Licensing is invalid, please give either "Eval" for Evaluation Mode, "Register" with a token to register to the cloud or "UNIVERSAL_PLR" to enable Universal Permanent Licensing. | ||||||
Validation | failedToExportConfig | You cannot export the configuration at this time. The system must complete an initial successful deployment before you can export the configuration. | ||||||
Validation | invalidSmartCliASPathValue | {0} entity value must be an existing ASPath Object | ||||||
Validation | deleteObjWithContained | Cannot delete object because it contains {0}. You must delete the contained objects prior to deleting this object. | ||||||
Validation | invalidObjectName | The name "{0}" is invalid. The name can start with an alphanumeric character or an underscore. It can contain the special characters +, ., _ and - | ||||||
Validation | invalidFlexCliTemplate | Template could not be resolved. {0} | ||||||
Validation | s2sDupRemotePeerIpAddr | Duplicate remote-peer IP-address is found, remote-peer IP address must be unique across all S2S VPN connection profiles | ||||||
Validation | sequenceNumberInAscending | IP prefix entries should be arranged in the ascending order of sequence number of an entry. | ||||||
Validation | SecurityIntelligencePolicyMoreThanOne | Cannot have more than one Security Intelligence Policy. | ||||||
Validation | ipsecDupIkev2Prf | Cannot have duplicate pseudorandom functions | ||||||
Validation | snmpUnsupportedSecurityLevel | The specified SNMP user security level is not supported. | ||||||
Validation | unsupportedIkevTwoIpsecEncryptionsStrong | The following encryption algorithms are not supported in IKEv2 IPsec proposals when strong encryption is enabled: DES. | ||||||
Validation | ftdUpdateMgrError_157 | Cancel upgrade failed. | ||||||
Validation | bridgeGroupInterfaceUsedUnsupportedOptions | {0} contains unsupported options. | ||||||
Validation | invalidSubinterfaceHardwareName | Subinterface hardware name "{0}" does not match parent interface's hardware name "{1}" and Subinterface ID "{2}" | ||||||
Validation | unknownBooleanInput | The Input for a Boolean type should be TRUE or FALSE | ||||||
Validation | sruUpdateError_13 | Unable to install package | ||||||
Validation | natOrigMappedPortsAreNotBothSpecified | The original and translated ports should be either both specified or both empty | ||||||
Validation | invalidOspfInterfaceNetworkType | Network type must be point-to-point non-broadcast when OSPF neighbors are defined on this interface | ||||||
Validation | invalidInterfacesForBypassPair | Invalid interfaces for bypass pair | ||||||
Validation | snort3ToggleFailed | Failed to switch to Snort version 3: {0} | ||||||
Validation | userPreferenceNotFound | Cannot find User Preferences. | ||||||
Validation | s2sVTIDynRRINotAllowed | You cannot enable dynamic reverse route injection when using a static virtual tunnel interface for a site-to-site VPN connection. | ||||||
Validation | upgradeIncorrectTypeInvocation | Upgrade could not be performed because of a system error, please contact the support. | ||||||
Validation | cannotCreateFMCRegistrationSettingsWithBackupInProgress | Cannot create an FMCRegistrationSettings object while backup job "{0}" is in progress. | ||||||
Validation | invalidNodeId | Validation failed due to invalid node ID: {0} | ||||||
Validation | performanceTierUnsupportedMethod | The following method is not supported for tired licensing API. | ||||||
Validation | s2sIkev2InvalidRemoteKey | Invalid IKEv2 pre-shared remote key. It must contain 1 to 128 ASCII printable characters, no whitespace, no single or double quotation marks,no question marks and cannot be a single digit | ||||||
Validation | interfaceMigrateSourceAndDestinationCannotBeUsedInHa | Source and destination IDs cannot belong to interfaces used in HA. | ||||||
Validation | ddnsPasswordShouldBeNull | Password should be set to null for Custom URL Service Provider. | ||||||
Validation | fileMalwareSeverityLevelRequired | File malware severity log level is required. | ||||||
Validation | DHCPServerNoInterfaceNetMask | The interface must have a netmask | ||||||
Validation | DHCPServerInterfaceModePassive | You cannot use a passive mode interface for the DHCP server default interface. | ||||||
Validation | portSecurityInTrunkMode | You cannot enable port security on a trunk port. | ||||||
Validation | IntrusionRuleUpdateNotAllowed | You cannot change the state of a rule whose default state is Disabled | ||||||
Validation | unableToUpgradeToDestinationVersion | The upgrade versions are invalid for source version {0} and destinationVersion {1}. This means that either the source version is greater than the destination version or the minimum required version to update to the destination version is higher than the current source version. | ||||||
Validation | invalidFlexCliLineNull | A cli command cannot be null | ||||||
Validation | cannotTurnOffNetmodForHaMonitoredNamedInterfaces | You cannot disable the Network Module on the active unit in a High Availability pair while an interface is being monitored for HA; this limitation does not apply to the standby unit. Interface {0} is currently being monitored. You must disable monitoring for this interface, deploy the configuration, and then disable the Network Module. Alternatively, you can make this unit the standby unit without altering the monitoring configuration. | ||||||
Validation | modeNotSupportedForEtherChannels | Switch port mode is not supported for EtherChannels. | ||||||
Validation | invalidInterfaceInAAA | Only routed mode interface is allowed in RADIUS server "{0}". | ||||||
Validation | aceDestinationEmptySourceIsNot | The destination network list cannot be empty when the source network list has entries. | ||||||
Validation | cfgExpEmptyEntityIds | You must specify at least one valid entity identity matcher for field entity IDs for a partial export job. Each matcher can either just be a UUID value or have a matcher pattern like 'id= |
||||||
Validation | SSLRuleNullCertStatus | Certificate Status cannot be null | ||||||
Validation | configDependentOnMissingInterface | This configuration relates to an interface that is no longer on the system. You cannot modify this configuration, you must delete it. This configuration will not be deployed. | ||||||
Validation | invalidOspfInterfaceDuplicateConfiguration | Interface {0} has already been configured for the protocol {1} in the object {2} | ||||||
Validation | haDeploymentAutoRecovered | Successfully auto-recovered {0} deployment. | ||||||
Validation | ISETagDeleted | Tag is deleted: {0} | ||||||
Validation | showPostUpgradeDialogCannotBeTrue | The showPostUpgradeDialog value in PostUpgradeFlags cannot be set to true. | ||||||
Validation | passwordNoUplower | Password does not contain an upper and a lower case character | ||||||
Validation | invalidFlexCliNetworkValue | {0} value must be an existing NetworkObject or NetworkObjectGroup | ||||||
Validation | containedEntityNotFoundInContainer | The contained entity to be updated is not found in the specified container | ||||||
Validation | RaVpnPriSecUsernameSame | Primary and Secondary username fields cannot be the same. | ||||||
Validation | invalidFlexCliNumericValue | {0} value is not a valid integer | ||||||
Validation | invalidSmartCliObjectNameValue | {0} value must be same as the Smart CLI object name | ||||||
Validation | adiCliTestFailed | The connection test failed. | ||||||
Validation | bridgeGroupInterfaceReferencedInSmartCli | The following interfaces are referenced by Smart CLI: {0}. This feature is not compatible with a bridge group member interface. You must remove them before you can add the interfaces to a bridge group. | ||||||
Validation | AnyConnInvalidXMLFile | {0} is a Invalid XML file. | ||||||
Validation | featureCapabilitiesIOReadException | IO Exception thrown while trying to read Feature Capabilities from file {0} | ||||||
Validation | bridgeGroupInterfaceReferencedInDdnsService | The following interfaces are referenced by DDNS Service: {0}. This feature is not compatible with a bridge group member interface. You must remove the interfaces from the configuration before you can add them to the bridge group. | ||||||
Validation | invalidFlexCliStringValue | {0} value cannot be null or blank | ||||||
Validation | BannerHasQuestionMarkChar | Banner display string cannot contain question mark character | ||||||
Validation | nullBgpNeighborRoutesAdvertisementInterval | Advertisement Interval can not be null. | ||||||
Validation | cannotHaveRealmOnTheMemberOfBVI | This interface is a member of a bridge group. You cannot use it in an identity realm configuration. | ||||||
Validation | s2sVTILocalNetworksNotAllowed | You cannot configure the list of local networks when using a static virtual tunnel interface for a site-to-site VPN connection. | ||||||
Validation | packageFileShouldBePresentWhenEnableExternalBrowserIsTrue | You must specify an external browser package when you select to use the default OS browser for SAML authentication. | ||||||
Validation | AnyConnACPrfInsideIntfHasNoName | The interface {0} added to AnyConnectProfile should have a logical name. | ||||||
Validation | certKeyTypeAndSizeWeak | Certificate digital signature key size is {0}, which is not supported. Supported key sizes for {1} signatures are: {2} | ||||||
Validation | unableToGetMaxDestinationVersio | Unable to find the maximum destination version for the current source version. | ||||||
Validation | snmpConfigChangeTrapNotSupportedOnVirtualPlatform | SNMP Config Change Trap not supported on Virtual Platform. | ||||||
Validation | IntfIsUsedInBvi | Interface {0} is used in a bridge group interface. | ||||||
Validation | interfaceWithSpeedSFPDetect | Interface {0} has speed type set on Detect SFP, FEC mode should be AUTO, auto negotiation should be enabled and duplex type should be set to FULL. | ||||||
Validation | bridgeGroupInterfaceReferencedInMgmtAccess | The following Interfaces are used in management access configuration: {0}. This feature is not compatible with a bridge group member interface. You must remove the interfaces from the configuration before you can add them to the bridge group. | ||||||
Validation | monitoredAddressInvalidNetworkType | The SLA Monitored address network object contains unsupported type. | ||||||
Validation | interfaceMissingName | Interfaces used in DHCP Relay Service are required to have a name assigned. Interface with UUID {0} is missing a name. | ||||||
Validation | queryParameterNotValid | Query parameter "{0}" is not valid because it contains forbidden characters. | ||||||
Validation | objectNatNoInterfaceSelectedWithRouteLookup | Please specify both source and destination interfaces to enable route lookup | ||||||
Validation | bridgeGroupInterfaceMemberHasIpv6Address | Bridge Group interface member {0} cannot contain IPV6 address | ||||||
Validation | msexeFileTypeShouldBeAddedForSperoAnalysis | File Rule validations failed. You must add MSEXE file type to the selected list to use Spero Analysis. | ||||||
Validation | fileTypeAndFileTypeCategoryCannotBeNullAtOnce | File Rule validations failed. At least one file type or file type category should be present. | ||||||
Validation | sruUpdateError_4 | Error downloading rule update, file is corrupt (MD5 does not match). Please contact technical support or try again later. | ||||||
Validation | timeNotInRange | The time value has to be between {0} and {1} {2}. | ||||||
Validation | featureInfoIOException | IO Exception thrown while trying to read Feature Information | ||||||
Validation | invalidSmartCliUnsupportedVariableType | {0} is not a supported variable type | ||||||
Validation | cloudAutoEnrollmentNotSupported | This platform does not support Cloud Auto Enrollment. Supported device types are the Firepower 1100 and 2100 series. | ||||||
Validation | objectNat46DynamicNotAllowed | Dynamic NAT is not allowed in an auto NAT rule for IPv4 to IPv6 address translation | ||||||
Validation | invalidSmartCliExpandedCommunityListValue | {0} entity value must be an existing Expanded Community List Object | ||||||
Validation | searchDomainNameTooLong | The domain search name in the DNS group is longer than 63 characters. The name must be shorter than 63 characters to use the group for data interfaces. | ||||||
Validation | performanceTierUpdateNotAllowedForUnregistered | Performance Tier update operation is not allowed when device is unregistered. | ||||||
Validation | portConflictWithRAVPN | The RA VPN outside interface is already using {0} as the HTTPS port. You must select a different value for the data interface's HTTPS port, or first change the RA VPN port number. | ||||||
Validation | SSLRuleNullRuleAction | You must specify an SSL rule action | ||||||
Validation | existingConnection | The device is currently operating in Evaluation, Registered or Universal PLR mode. If you would like to change the mode, you must update the existing connection object. | ||||||
Validation | invalidPasswordCombination | You must enter both the new and old password | ||||||
Validation | s2sBackupPeerIkev2InvalidRemoteKey | Invalid IKEv2 pre-shared remote key. It must contain 1-128 ASCII printable characters, no whitespace, no single or double quotation marks, no question marks and cannot be a single digit | ||||||
Validation | manualNatNoDestNatWithSrcNat64 | Missing destination translation with IPv6 to IPv4 translation on source addresses | ||||||
Validation | unExpectedExitCode | The script returned an unexpected exit code, {0}. | ||||||
Validation | invalidObjectForNotECMPZoneInterfaceAnnotation | Validation could not be performed successfully due to a server issue. Please contact Cisco Technical Support. | ||||||
Validation | s2sNoRemotePeerIpAddr | Remote-peer IP-address can not be null in case of static peers. | ||||||
Validation | unableToCancelPLRReservation | Unable to cancel the Permanent Licensing reservation. In order to cancel PLR, Permanent Licensing deregistration must be in-progress. | ||||||
Validation | PullUpgradeSuccess | Pull is completed successfully | ||||||
Validation | mandateVlanOnNamedInterface | Interface cannot have a logical name if it has no VLAN assigned to it | ||||||
Validation | communityNumberNotInRange | Community number {0} should be between 1 and 4294967295 or in the format aa:nn where aa and nn are 2-byte numbers. A number from 1 to 65535 can be entered for each 2-byte number. | ||||||
Validation | duplicateInterfaceInList | There is already a management access list rule for this interface. Edit the existing rule. | ||||||
Validation | invalidDupOutAclRouteFilter | Only one access list is allowed per protocol process | ||||||
Validation | SslRuleCannotHavePassiveZone | You cannot use a passive security zone in an SSL rule. | ||||||
Validation | dynamicObjectGeneral | An error has occurred. | ||||||
Validation | autoNegHasToBeNull | AutoNeg field has to be set to null on this Platform. | ||||||
Validation | invalidEigrpDuplicateProcess | Identifier value {0} does not match the EIGRP autonomous system number in use. | ||||||
Validation | cryptoNonCompliantIkev2PolicyForEncryptionType | The upgraded IKEv2 policies use 3DES or NULL Encryption which is not supported on this FTD version: {0}. | ||||||
Validation | cannotConfigureIPAddress | The interface is configured in {0} mode. You cannot configure an IP address on a {0} interface. | ||||||
Validation | licenseAlreadyExists | This device already has a license of this type. You cannot have multiple licenses of the same type | ||||||
Validation | identityRealmNullEncryptionCert | No encryption certificate defined for the realm | ||||||
Validation | interfaceNotPresentWithConfig | The configuration includes references to a missing interface. Any elements that are dependent on the missing interface will not be deployed. Please re-evaluate the configuration, and if necessary, re-create the undeployable parts of the configuration for a valid interface. | ||||||
Validation | AnyConnNotSupportedNestedNetworkGroup | You cannot use Nested network group {0} in the AnyConnectProfile {1} | ||||||
Validation | contextRetrieveFailed | Could not retrieve device registration context. Please try again later. | ||||||
Validation | canNotUpdateTokenOnRegisterConnection | Cannot update token on existing SmartAgentConnection object if it already has token and connection type is REGISTER. | ||||||
Validation | EmptySSLCipherSecurityLevel | You must specify one of the open SSL security level | ||||||
Validation | geoUpdateError_10 | Error running GeoDB Update | ||||||
Validation | invalidAuthorizationCode | The Reservation Authorization code entered is invalid. The Reservation Authorization Code must follow the format XXXXXX-XXXXXX-XXXXXX-XXXXXX-XXXXXX-XXXX where X is any alphanumeric character. | ||||||
Validation | certTypeEmpty | Certificate Type is empty. You must specify a type. | ||||||
Validation | invalidOspfInerfaceIsPassive | Interface {0} cannot be passive | ||||||
Validation | cliCommandNotSupported | This command is not supported or not recognized. Command abbreviations are not allowed. | ||||||
Validation | s2sIkev1NoEnabledPolicyWithAuth | Cannot enable site-to-site IKEv1 without enabling any IKEv1 policy with authentication type {0} | ||||||
Validation | invalidSlaDataSize | The size of the data payload value has to be between 0 and 16384 bytes. | ||||||
Validation | intrusionSettingsTooManySyslogServers | This version does not support multiple syslog servers. | ||||||
Validation | cliCommandCommandNotAllowedAfterPipe | Command {0} is not valid after pipe symbol. Only include, grep, exclude or begin allowed after pipe symbol. | ||||||
Validation | invalidRuleActionWithMalwareAnalysis | File Rule validations failed. Malware analysis options are valid only for MALWARE_BLOCK and MALWARE_CLOUD_LOOKUP rule actions. | ||||||
Validation | AnyConnSplitTunnelNoInsideNet | Split tunnel functionality requires at least one inside network | ||||||
Validation | standbyIPSameAsActiveIPAddress | Standby IP Address cannot be the same as an active IP Address. | ||||||
Validation | sruUpdateUnknownError | Unknown error occurred while updating Rule Update | ||||||
Validation | objectNatPortNotAllowedWithDynamicRule | Port translation is not allowed with dynamic auto NAT | ||||||
Validation | bridgeGroupInterfaceCannotHaveIpv6AddressOfBgpNeighbor | This IPv6 address is part of a neighbor that is being used in the BGP configuration. You cannot assign the same IPv6 address to a bridge group interface. | ||||||
Validation | MaxCountReached | FDM can support a maximum of {0} VRFs. | ||||||
Validation | acRuleMixedIpv4v6AddressInSrcDestNetworks | Source and destination networks contain a mix of IPv4 and IPv6 addresses | ||||||
Validation | scheduleDoesNotExist | Unable to modify a scheduled job. No pending schedule. | ||||||
Validation | invalidOspfRouterId | 0.0.0.0 is not a valid Router ID | ||||||
Validation | manualNatPortsNotAllTcpOrAllUdp | Manual NAT rule port references should be either all TCP ports or all UDP ports | ||||||
Validation | interfaceCannotCreate | An error occured while scanning the newly added interface {0} | ||||||
Validation | invalidEtherChannelId | EtherChannel ID must be an integer between 1 and 48. | ||||||
Validation | vlanIdBeingUsedBySubInterface | VLAN ID {0} is being used by subinterface "{1}" and cannot be assigned to a VLAN interface. | ||||||
Validation | PullUpgradeJobFailed | Pull Upgrade job failed because stuck in progress | ||||||
Validation | invalidOspfInterfaceNotEnabled | Interface {0} must be enabled to configure OSPF | ||||||
Validation | deprecatedApps | An application filter cannot contain deprecated applications. | ||||||
Validation | RaVpnGroupPolicyAnyConnectClientProfileModuleNotAllowed | ANY_CONNECT_CLIENT_PROFILE is not allowed as a module name | ||||||
Validation | invalidOspfNsfMechanismRequired | You must specify the NSF mechanism to configure graceful restart | ||||||
Validation | PullFileFailed | File upload failed. | ||||||
Validation | invalidCliObjectName | The name "{0}" is invalid. The name can start with an alphanumeric character or an underscore. It can contain the special characters _ and - | ||||||
Validation | ipsecNormalModeNullIntegrity | Normal encryption modes cannot be used with null integrity type, null integrity type is for combined modes | ||||||
Validation | invalidBGPExceededLimit | Only one BGP protocol can be running in the system | ||||||
Validation | invalidNetworkSubtypeForManagementInterface | The management access rule for the management interface contains a network object of an unsupported type. | ||||||
Validation | unsupportedIkevOneIpsecEncryption | The following encryption algorithms are not supported in IKEv1 IPsec proposals: ESP-3DES. | ||||||
Validation | aceLogLevelNull | The log level cannot be set to null when the logging option is enabled. | ||||||
Validation | redundantRegionForEnrollmentViaAutoEnrollment | You should not specify the region when enrolling with the cloud using Auto Enrollment. | ||||||
Validation | trunkAllowedVlansLimit | In trunk mode, the allowed VLANs must be from 1 to 20. | ||||||
Validation | invalidStaticMacAddress | MAC address {0} is invalid. The allowed format is H.H.H, where H is a 16-bit hexadecimal digit. | ||||||
Validation | cannotUseDiagnosticInterface | Diagnostic interface cannot be assigned to Connectivity Interface. | ||||||
Validation | InspectorSharedStateInvalid | The following inspectors must always be enabled or disabled together: ({0}). | ||||||
Validation | adiCliTestSucceeded | The connection test succeeded. | ||||||
Validation | ToggleToSnort3WithTimeBasedACLNotSupported | Switching to Snort 3 is not allowed because you have Time Based ACL. Remove timeRange configuration and re-try. | ||||||
Validation | redundantTokenForEnrollmentViaAutoEnrollment | You should not specify the token when enrolling with the cloud using Auto Enrollment. | ||||||
Validation | cannotTurnOffNetmodWhenNetmodInterfaceIsFailoverInterface | You cannot disable the Network Module on the active unit in a High Availability pair while an interface {0} is being used as a failover or stateful failover link; this limitation does not apply to the standby unit. | ||||||
Validation | CannotDeleteOverriddenRule | Cannot delete intrusion rule {0} as it is currently overridden in policies: {1}. | ||||||
Validation | DHCPServerIPPoolNetwork | DHCP server IP address range {0} must not include the network address: {1} | ||||||
Validation | RaVpnConProfileIntfAddrOverLap | Interface cannot be in the address pool range {0} used in RAVPN connection profile {1} | ||||||
Validation | exceedsMemberInterfacesLimitKPWM | EtherChannel cannot contain more than 8 active physical interfaces on this platform. | ||||||
Validation | interfaceNotBrokenout | Cannot perform join on an interface that is not broken out {0} | ||||||
Validation | unexpectedPLRUnsuccessfulGetAuthorizationCode | Unable to attain the Authorization Code for Universal Permanent Licensing. | ||||||
Validation | SecurityIntelligenceExceededMaxNetworkListSize | The combined number of entries in the network Block and Do Not Block lists cannot exceed 255. | ||||||
Validation | invalidAAARadiusIdentitySourceGroupSize | RADIUS identity sources in a RADIUS identity source group must not exceed 16 entries | ||||||
Validation | invalidInterfaceBreakout | The interface provided cannot be used for the breakout operation. Valid interfaces are interfaces with type PhysicalInterface. | ||||||
Validation | RuleGroupSnort2NotAllowed | Custom rule groups are not supported with Snort 2. | ||||||
Validation | staticRouteWrongGatewayType | Wrong gateway type for static route: {0} | ||||||
Validation | managementInterfaceCannotBeCreated | You cannot create a new management interface. | ||||||
Validation | staticRouteInconsistentInterfaceProtocol | Static route inconsistent protocol version for interface: IPv4 vs IPv6 {0} | ||||||
Validation | accountTypeNotPresent | You should specify the account type you want to use for enrollment. | ||||||
Validation | invalidBackupFile | Backup file is invalid. It does not have the manifest file. | ||||||
Validation | integrationkeyinvalid | The Integration Key should be 20 characters containing only the characters A-Z, 0-9. | ||||||
Validation | nullObject | Input object is null | ||||||
Validation | memberInterfaceShouldBeAutoNegCapable | All member interfaces should have AutoNeg capability. | ||||||
Validation | objectNat66OrigAddrIpv6PrefixTooShort | The original address IPv6 prefix must be greater than or equal to 64 in an IPv6 to IPv6 auto NAT rule: {0} | ||||||
Validation | updateTimedOut | Update failed. Installation timed out. | ||||||
Validation | invalidGroupPolicy | Invalid group policy configured for LDAP attribute value {0} in LDAP attribute map {1}. | ||||||
Validation | s2sIkev1CertificateNotSpecifiedWhenAuthMethodCert | An internal certificate for IKEv1 policy must be provided when authentication via certificate is selected | ||||||
Validation | SSLSettingNoTLSV1_2ProtocolsAssigned | Along with DTLSV1_2 protocol version, TLSV1_2 protocol version should be assigned. | ||||||
Validation | duplicateECMPZone | Selected interface is already assigned to ECMP Traffic Zone "{0}". | ||||||
Validation | s2sBackupPeerIkev2LocalMaskedKeyNotAllowed | Masked value for IKEv2 local pre-shared key is not allowed when creating a new backup peer or updating the IP address for an existing backup peer. | ||||||
Validation | invalidDuplexType | Validaton Failed, This interface does not support {0} for duplex mode. | ||||||
Validation | ftdUpdateMgrError_183 | Upgrade in progress. Cannot revert. | ||||||
Validation | ftdUpdateMgrError_184 | Upgrade in progress. Cannot revert. | ||||||
Validation | manualNatRouteLookupSrcNetworkMismatch | The Perform Route Lookup option is available for identity NAT only. The original and translated source networks must be identical to use the option. | ||||||
Validation | SystemDefinedCannotHaveBasePolicy | A policy that is system defined cannot have a base policy. | ||||||
Validation | SSLRulesWithSnort3AndDetectionPolicy | The access control policy is linked to a network analysis policy in detection mode with SSL decryption or TLS server identity configured. This feature combination is not supported. Change your network analysis policy to prevention mode or disable SSL decryption or TLS server identity and try again. | ||||||
Validation | cannotTriggerAutoEnrollmentApi | Error in getting the token and domain from the Cisco Cloud Registration server. Refer to the Smart Agent logs for more details. Please retry and if the problem persists, contact Cisco TAC. | ||||||
Validation | useOfUnspecifiedIPAddressWithPrefix | {0}/{1} is known as an Unspecified Address. This address cannot be assigned to an interface. | ||||||
Validation | troubleshootFailed | Error generating troubleshooting file | ||||||
Validation | invalidFlexCliIPValue | {0} value must be a valid IPv4 or IPv6 address | ||||||
Validation | s2sVTICannotBeUnnamed | You must give an interface name to a virtual tunnel interface to use it in a site-to-site VPN connection. | ||||||
Validation | pppoeObjectIsOnlyRequiredWithPppoeType | The pppoe object is only required when the PPPoE type is selected. | ||||||
Validation | downloaderNoResponse | Snort 3 cloud update failed: The package downloader failed with no response. | ||||||
Validation | emptyMappings | There are no mappings in the LDAP attribute map {0}. A map must contain at least one mapping of an LDAP attribute to a Cisco attribute name, or a group policy should be defined. | ||||||
Validation | upgradeDeviceNotRegistered | You must register the device before starting a system upgrade. | ||||||
Validation | exceedLimitEnabledIkev1Policies | The maximum number of IKEv1 policies enabled has already been reached ({0}). Please disable the unused policies. | ||||||
Validation | s2sNetworksStrictToMixed | Local networks contain only {0} addresses but remote networks contain both IPv4 and IPv6 | ||||||
Validation | invalidLoggingListMessageId | Message ID should be in between {0} and {1}. | ||||||
Validation | invalidOspfNsfBoth | NSF Cisco and IETF requires all LLS capability, Cisco helper, Opaque LSA, and IETF helper be enabled | ||||||
Validation | bridgeGroupInterfaceIdNotAvailable | All bridge group interface IDs have been assigned between {0} and {1} | ||||||
Validation | selfSignedStartDateAfterEndDate | The self-signed certificate validity end date cannot be in the past. | ||||||
Validation | FMCConnectivityInterfaceCannotBeMemberOfUserDefinedVrf | The data management interface can only belong to the global virtual router. | ||||||
Validation | bgpAsDotNotationEnabled | You must disable AS dot notation if you do not use the X.Y number format. | ||||||
Validation | unexpectedPLRUnsuccessfulDisable | Unable to disable Universal Permanent Licensing. | ||||||
Validation | vtiTunnelSourceAllowedTypes | Invalid type of tunnel source interface, the only types allowed are PhysicalInterface, SubInterface and EtherChannelInterface. | ||||||
Validation | noRetryAvailable | No upgrade to retry at this stage. | ||||||
Validation | SecurityIntelligenceDNSPolicyGlobalBlacklistShouldBeFirstElement | The DNS policy global Block rules should be in the first position in the Block list. | ||||||
Validation | s2sIntfForNatIsPassive | You cannot use a passive mode interface for the NAT exempt interface of a site-to-site VPN connection. | ||||||
Validation | invalidMtuVirtual | Invalid MTU for virtual device. You can set the MTU up to 9000 for virtual devices. | ||||||
Validation | snmpInvalidSnmpUserNameLength | The SNMP user name cannot be longer than 33 characters, and it cannot be empty. | ||||||
Validation | valueNotInRange | {0} value must be between {1} and {2}. | ||||||
Validation | monitoredInterfaceCannotBeDeleted | You cannot delete an HA-monitored named interface on this platform. Please remove the interface from the HA monitoring list, perform deployment, and then you can delete the interface. | ||||||
Validation | SSLSettingInvalidECDHGroup | Invalid Elliptical Curve Diffie Hellman Group assigned. Valid values are GROUP_19, GROUP_20 and GROUP_21. | ||||||
Validation | interfaceIsMemberOfEtherChannel | Interface {0} cannot be a member of an EtherChannel interface and be used by DHCP Relay Service at the same time. | ||||||
Validation | noLogFileCorrupted | Upgrade status JSON and log files maybe corrupted. | ||||||
Validation | nextHopNullSpecificIPNotNull | Next Hop setting cannot be null when Specific IP is provided. | ||||||
Validation | unsupportedSpeedType | Specified EtherChannel Speed type is not supported. | ||||||
Validation | AnyConnInvalidNetworkObjectType | Network object type is not valid for address pool | ||||||
Validation | DHCPServerIntInIPPool | Interface address {0} must not be in the IP address range: {1} | ||||||
Validation | AnyConnACPkgMissing | AnyConnect client package {0} is missing | ||||||
Validation | invalidEigrpBVIInterface | Cannot configure EIGRP on BVI Interface. | ||||||
Validation | IntfAddrOverLap | Interface {0} cannot be in the address pool range {1} | ||||||
Validation | unsupportedRedistribution | Unsupported redistribution protocol selected | ||||||
Validation | natPortRangeNotSupported | Port range is not supported in auto NAT rules | ||||||
Validation | invalidOspfDuplicateNeighborInterface | An OSPF neighbor is already defined on the interface {0}. Only one neighbor is allowed on point-to-point interfaces | ||||||
Validation | invalidEigrpDuplicateNetwork | {0} has already been configured. | ||||||
Validation | invalidPrefix | The Prefix entered is invalid | ||||||
Validation | emptyGroupPolicyForLdap | There is no group policy mapping for LDAP attribute value {0} in the LDAP attribute map {1}. | ||||||
Validation | invalidObjectNameSpaceCommaAllowed | The name "{0}" is invalid. The name can start with an alphanumeric character or an underscore. It can contain spaces and the special characters +, ., _, -, and ,. However, the name cannot include a leading or trailing space. | ||||||
Validation | CustomRuleGidInvalidValue | The gid value for a custom rule must be {0}. | ||||||
Validation | AnyConnACPrfOutsideIntfCannotBeMgmt | The interface {0} added to AnyConnectProfile is invalid, the outside interface cannot be for management only | ||||||
Validation | acRuleMoreThanOneEmbeddedAppFilter | An access rule should not have more than one embedded application filter | ||||||
Validation | failedToExportHugePendingChangesToClipboard | Pending Changes size exceeds the limit for copying to clipboard. Please download pending changes as a file. | ||||||
Validation | handlerError | Internal error during feature toggle | ||||||
Validation | cryptoNonCompliantS2SIkev2Proposal | The S2S VPN connection profile {0} is using IKEv2 proposals {1} having DES encryption which is disallowed when the Smart License Account has export-controlled features enabled. | ||||||
Validation | invalidObjectType | The type is invalid. | ||||||
Validation | invalidHostName | The fully-qualified domain name (FQDN) or IP address is not valid. | ||||||
Validation | unsupportedIkevOneEncryptionStrong | The following encryption algorithms are not supported for IKEv1 policies when strong encryption is enabled: DES. | ||||||
Validation | AnyConnExcessProfile | Can have only one Any-Connect connection profile | ||||||
Validation | SecurityIntelligenceExceededMaxURLListSize | The combined number of entries in the URL Block and Do Not Block lists cannot exceed 32767. | ||||||
Validation | cannotDiscardDuringDeploy | You cannot discard pending changes while a deployment is in progress. Please wait for the current deployment to finish. | ||||||
Validation | pppoeNotSupportedOnManagementInterface | PPPoE is not supported on Management Interface. | ||||||
Validation | taskStatusNotAvailable | Status not available | ||||||
Validation | SSLSettingNoTLSVProtocolsAssigned | Along with DTLSV protocol family version at least one TLSV protocol family version should be assigned. | ||||||
Validation | haBreakFromSingle | The device does not have HA configured, {0} cannot be executed. | ||||||
Validation | methodException | Validation failed due to an exception: {0} | ||||||
Validation | snort2ToggleFailed | Failed to switch to Snort version 2: {0} | ||||||
Validation | invalidCertificate | Certificate is not valid | ||||||
Validation | acPolicyInvalidIPS | The selected intrusion policy cannot be used in an access rule. | ||||||
Validation | userServiceTypesIsNullOrEmpty | The user service types cannot be null or empty | ||||||
Validation | s2sCryptoRestrictedIkev1Proposals | S2S VPN uses IKEv1 IPsec proposals with strong encryption, which is not allowed by your licensing setting. Please use DES only | ||||||
Validation | invalidOspfAreaCost | Area cost is not applicable for backbone area | ||||||
Validation | invalidFlexCliBooleanValue | {0} value must be set to either true or false | ||||||
Validation | autoSpeedMustHaveAutoDuplex | Interface with speedType and duplexType must match if either is set to AUTO. | ||||||
Validation | invalidAgentStatus | Invalid Smart agent status | ||||||
Validation | externalBrowserPackageFileIsMissing | The following external browser package is missing: {0} | ||||||
Validation | invalidLocalUserType | The local user selected must be of type "trafficuserentry" | ||||||
Validation | DapXmlDuplicateRecords | There are one or more duplicate records : {0} | ||||||
Validation | invalidNetworkObjectType | Type has been set to an invalid value {0} | ||||||
Validation | minIpv6MtuIs1280 | To configure IPv6, the minimum MTU is 1280. | ||||||
Validation | missingBuildNumber | Snort 3 rule package installation failed: Unable to obtain package build number. | ||||||
Validation | cannotFindDiagnosticInterface | Cannot find diagnostic interface for convergence in the database. | ||||||
Validation | unsupportedIkevOneIpsecAuth | The following ESP hash algorithm is not supported in IKEv1 IPsec proposals: ESP-MD5-HMAC. | ||||||
Validation | s2sCryptoRestrictedIkev2Proposals | S2S VPN uses IKEv2 IPsec proposals with strong encryption, which is not allowed by your licensing setting. Please use DES only | ||||||
Validation | ftdUpdateMgrError_156 | Cancel operation is not available. | ||||||
Validation | interfaceMigrateCannotMigrateBetweenPassiveAndNonPassive | You cannot migrate between passive and non-passive interfaces. | ||||||
Validation | invalidOspfVirtualLinkAuthKeyNotEnabled | The selected authentication type is password authentication. You must also configure the authentication key | ||||||
Validation | featureCapabilitiesNoResource | No feature capabilities resource found in application context files | ||||||
Validation | AnyConnInsideIntfAddrOverLap | Cannot use an address pool with range {0} because it contains the address used on inside interface {1} | ||||||
Validation | switchPortConfigurationNull | Interface {0} must define a switch port configuration when it is in switch mode. | ||||||
Validation | externalBrowserPackagesExceedsAllowedNumber | You can upload a maximum of {0} external browser packages. | ||||||
Validation | blacklistedFlexConfigPolicy | There are FlexConfig objects in the FlexConfig policy that include prohibited commands. You must either remove the prohibited commands from the objects, or remove the objects from the FlexConfig policy, before you can add new Smart CLI objects. | ||||||
Validation | s2sPfsNoGroup | The S2S VPN connection profile {0} uses unsupported {1}. The following Diffie-Hellman groups can no longer be used for Perfect Forward Secrecy: 1, 2, 5, 24. | ||||||
Validation | invalidBgpNextHopTriggerEnable | The Next hop trigger enable value should match the next hop trigger enable value in General Settings. | ||||||
Validation | bridgeGroupInterfaceEnableIpv6AutoConfig | Bridge group interface do not support IPV6 option auto-config | ||||||
Validation | invalidFlexCliUnsupportedNumericValue | {0} value cannot have signs or leading zeros | ||||||
Validation | configImpExpUnsupportedVersion | Configuration Import Export feature is only supported on the latest version. | ||||||
Validation | noRollbackScript | The script to cancel upgrade is not available at this stage. | ||||||
Validation | cannotCreateIdRuleWithoutCert | Cannot create an identity rule if the Server Certificate for Active Authentication is not provided | ||||||
Validation | defaultActionNotPassiveOrNoAuth | The default action in the identity policy should be Passive or No Authentication | ||||||
Validation | appFilterInvalidRiskValue | Invalid application filter risk value {0}. | ||||||
Validation | AnyConnPrefillUsernameAndDisabledUsernameEditFromCertificateNotEnabled | Please enable PrefillUsernameFromCertificate and DisablePrefilledUsernameEdit option to update password type. | ||||||
Validation | invalidDomainName | The Domain name is invalid. It can contain only letters, digits and the characters '.' or '-'. It can consist of multiple sections, each separated by a '.' | ||||||
Validation | unsupportedIkevOneIpsecEncryptionStrong | The following encryption algorithms are not supported in IKEv1 IPsec proposals when strong encryption is enabled: ESP-DES. | ||||||
Validation | invalidTemplateIdentifier | Template identifier is not valid. {0} | ||||||
Validation | onlySupportsMajorUpgrade | This API is only available for major upgrades. | ||||||
Validation | vdbUpdateError_7 | Peer certificate cannot be authenticated with known CA certificates | ||||||
Validation | AnyConnNatNoInsideNet | NAT exempt functionality requires at least one inside network | ||||||
Validation | s2sVTISVTINotEnabled | You must enable static VTI to use a virtual tunnel interface for a site-to-site VPN connection. | ||||||
Validation | subIntfVlanIdNotNull | VLAN ID must be null when sub-interface is in switchport mode. | ||||||
Validation | cryptoNonCompliantIkev2ProposalForEncryptionType | The upgraded IKEv2 proposals use either 3DES or AES_GMAC or AES_GMAC192 or AES_GMAC256 Encryption which is not supported on this FTD version: {0}. | ||||||
Validation | invalidSmartCliPortValue | {0} entity value must be an existing TCPPortObject or UDPPortObject | ||||||
Validation | unableToParseIseConfigTestOutput | An error occurred trying to parse the response from ISE. | ||||||
Validation | interfaceJoinCreate | An error occurred while joining Network Module interface {0} | ||||||
Validation | invalidEtherChannelIdWMDesktop | EtherChannel ID must be an integer between 1 and 8. | ||||||
Validation | snmpUnsupportedManagementAddressType | SNMP Hosts with Host Group type supports only Range and Network manager address types. SNMP Hosts of SNMP Host type supports only Host manager address. | ||||||
Validation | interfacePresentFieldReadOnly | Presence of an interface is not user configurable. | ||||||
Validation | snort3LspTarDdVersionUnknown | Unable to find a appropriate datasource that matches the installed Snort 3 Version. | ||||||
Validation | memberInterfaceCannotBeEmpty | EtherChannel must have at least one physical interface member. | ||||||
Validation | timeZoneInvalidOffset | Invalid DST Offset. A valid offSet must be provided for TimeZone Object custom configuration. Valid Offset must be between 1-1440. | ||||||
Validation | bgpNeighborFilterDistributedListSameFilterDirection | Prefix list and Distribute list can not co-exist for same filter direction. | ||||||
Validation | staticRouteUsingInterface | Interface {0} referenced in static route {1} can not be moved to a different VRF | ||||||
Validation | DHCPServerIPPoolBroadcast | DHCP server IP address range {0} must not include the broadcast address: {1} | ||||||
Validation | appFilterAppNotFound | Application filter application not found {0}. | ||||||
Validation | InvalidRuleGroupId | Could not find a rule group with the ID of {0}. | ||||||
Validation | AnyConnMaxConnTimeoutInvalid | Anyconnect maximum connection timeout cannot be greater than 4473924 minutes | ||||||
Validation | s2sNoBackupPeerIpAddr | Backup peer IP address cannot be null or empty. | ||||||
Validation | vdbUpdateError_15 | VDB update file not found. | ||||||
Validation | invalidDisabledLoggingValues | When the logging option is set to disabled, the log level and log interval must be null. | ||||||
Validation | SSLSettingSameProtocolVersion | You cannot refer to multiple SSL Cipher objects with overlapping Protocol versions in Data SSL Cipher Settings. Overlapping versions are {0} part of Cipher objects {1}. | ||||||
Validation | invalidSmartCliUnsupportedNumericValue | {0} value cannot have signs or leading zeros | ||||||
Validation | AnyConnAuthMethodMustBeAAAAndClientCertificateToEnablePasswordType | Auth method must be {0} for using Password Type on user login window | ||||||
Validation | TimeBasedACLNotSupportedWithSnort3 | TimeRange is configured. This is not supported with Snort3. Remove timeRange configuration and re-try. | ||||||
Validation | appTagInvalidName | Invalid application tag name {0}. | ||||||
Validation | subInterfaceNotAllowed | The interface is configured in {0} mode. You cannot create subinterfaces on a {0} interface. | ||||||
Validation | RaVpnGroupPolicyInvalidNumberVal | Invalid Value. Valid range is {0} to {1}. | ||||||
Validation | PullInvalidFilename | Filename is invalid | ||||||
Validation | duplicateSubInterfaceId | Subinterface ID {0} already exists for {1} | ||||||
Validation | cannotAssignDHCPWhenHAIsEnabled | Interface {0} cannot be assigned a DHCP address when HA is enabled. | ||||||
Validation | RuleMustHaveValidRevision | Rule must have a revision number greater than or equal to 1. | ||||||
Validation | disableSha256CantBeLesserThanMaxFileSize | SHA 256 can be disabled only for a file which exceeds the maximum file size. | ||||||
Validation | IntrusionPolicySnort2DeleteNotAllowed | You cannot delete an Intrusion Policy in Snort 2 mode. | ||||||
Validation | aaaSpecifiedAuthIdentitySourceNotSupported | Specified authentication identity source is not supported | ||||||
Validation | invalidPortRange | Invalid port range. Beginning port must be less than ending port. | ||||||
Validation | noImsConfFile | The ims conf file cannot be found. | ||||||
Validation | ntpDuplicate | NTP server {0} is specified more than once. Please remove duplicate servers. | ||||||
Validation | IntrusionPolicyNameOrDescriptionChangeNotAllowed | You cannot change the name or description of an intrusion policy. | ||||||
Validation | invalidAsciiCharacterForLina | The name and password can contain any printable ASCII alphanumeric or special character except spaces and question marks. Printable characters are ASCII codes 33-126. | ||||||
Validation | subInterfaceNotAllowedInSecurityZone | SubInterfaces are not allowed in a security zone with mode passive. | ||||||
Validation | ftdUpdateMgrError_254 | Retry upgrade failed. Use the 'upgrade cancel' API to cancel. | ||||||
Validation | hardwareNameCannotBeNull | Hardware name cannot be null. | ||||||
Validation | invalidOspfInterfaceNoIP | Cannot configure neighbor on interfaces without IP address. Assign an IPv4 address to the interface | ||||||
Validation | s2sFQDNNetwork | Site-to-site profiles cannot have FQDN type network objects | ||||||
Validation | vdbUpdateError_10 | The latest VDB update is already installed | ||||||
Validation | invalidOspfNsfConflictingConfiguration | Conflicting NSF graceful restart configuration | ||||||
Validation | emptyConnectivityInterfaceNameNotAllowed | Interface associated with ConnectTest should have a non-empty NAME. | ||||||
Validation | bridgeGroupInterfaceCannotHaveIpv6AddressOfBgpNetwork | This IPv6 address is part of a network that is being used in the BGP configuration. You cannot assign an IPv6 address from this network to a bridge group interface. | ||||||
Validation | s2sBackupPeerSameAsPrimaryPeer | IP address of one of the backup peers is the same as that of the primary peer. | ||||||
Validation | prefixNotAllowed | Invalid range. Prefix/subnet mask is not allowed in range object. | ||||||
Validation | appTagInvalidDesc | Invalid application tag description {0}. | ||||||
Validation | SslRulesWithDeprecatedCategories | Some of the SSL decryption rules refer to deprecated URL Categories. Number of SSL decryption rules affected: {0}. | ||||||
Validation | CustomRuleGroupSnort2 | Custom rule groups are not supported in Snort 2. | ||||||
Validation | invalidLicenseForDeployment | Deployment is blocked. This device does not have a base license. You cannot deploy changes. | ||||||
Validation | threadError | Error occurred during thread sleep. | ||||||
Validation | ipsecPolicyInvalidLifetime | Lifetime value not in range: {0} | ||||||
Validation | AnyConnNoIpv4InsideNetwork | With {0} as an IPv4 address pool, you must have at least one IPv4 inside network specified | ||||||
Validation | UpgradeReadinessJobFailed | Upgrade Readiness job failed because stuck in progress | ||||||
Validation | AnyConnOutsideIntfAddrOverLap | Cannot use an address pool with range {0} because it contains the address used on the selected outside interface {1} | ||||||
Validation | objectNat64AnyIpv6NotValid | The network corresponding to the full range of IPv6 addresses, i.e. ::/0, cannot be used in an IPv6 to IPv4 object NAT rule | ||||||
Validation | invalidOperationOSPFNeighborDefined | Operation cannot be performed when an OSPF neighbor is enabled for this network | ||||||
Validation | invalidNetworkSubtypeForFlexPolicy | The FlexConfig policy contains a variable for a network object of an unsupported type. | ||||||
Validation | duplicateInterfaceSelected | Selected interface is already assigned to DDNS Service "{0}". | ||||||
Validation | onlyIPv4NetworkObjectsAllowed | Only IPV4 networks are allowed. | ||||||
Validation | authTokenNotEqual32 | The registration key must be 32 characters. | ||||||
Validation | AnyConnNatNoInsideIntf | NAT exempt functionality requires at least one inside interface | ||||||
Validation | manualNatNoInterfaceSelectedWithRouteLookup | Please specify at least one interface to enable route lookup | ||||||
Validation | invalidIdentitySourceGroup | "identitySourceGroup" field can only be of type {0} | ||||||
Validation | InvalidOverrideStateForRule | Invalid security level for rule group: {0}. | ||||||
Validation | lspExtractingFailed | Failed to extract package {0} during LSP package installation. | ||||||
Validation | vdbUpdateError_4 | Error downloading rule update, file is corrupt (MD5 does not match). Please contact Technical Support or try again later. | ||||||
Validation | snmpInvalidAuthenticationPasswordLength | Authentication password should be an encrypted string with length 8 - 257 characters. | ||||||
Validation | sruUpdateError_14 | Error running Rule update | ||||||
Validation | invalidDuplexSpeedComboNotSupported | Invalid duplex and speed combination. | ||||||
Validation | conflictingInterface | All syslog servers should have same interface type. i.e either all servers should have management interface or all should have data interfaces. | ||||||
Validation | accountTypeNotSupported | You cannot enroll in the cloud with the specified account type. | ||||||
Validation | unnamedInterfaceInSecurityZoneNotAllowed | This interface is part of security zone: {0}. You must remove the interface from all zones before you can remove the interface name. | ||||||
Validation | updateSkipped | The latest rule package is already installed. | ||||||
Validation | manualNatSrc46Ipv6RangeObjNotAllowedInTransSrc | You cannot use an IPv6 range network object as the translated source in an IPv4 to IPv6 manual NAT source translation rule: {0} | ||||||
Validation | cryptoCompliantS2SIkev2Proposal | The S2S VPN connection profile {0} is using IKEv2 proposals with strong encryption which is not allowed by your licensing setting, please de-reference them and use DES only: {1} | ||||||
Validation | cryptoNonCompliantS2SIkev1Proposal | The S2S VPN connection profile {0} is using IKEv1 proposals {1} having DES encryption which is disallowed when the Smart License Account has export-controlled features enabled. | ||||||
Validation | managementInterfaceAttributeCannotBeUpdated | You cannot change which interface acts as the management interface. | ||||||
Validation | failedToConvertJSON | Failed to convert upgrade revert info JSON to java object. | ||||||
Validation | bgpAsDotNotationNotEnabled | You must enable AS dot notation to use the X.Y number format. | ||||||
Validation | externalBrowserPackageCannotBeDeletedFromRavpnWhenUsedInProfiles | You cannot delete the external browser package from RA VPN {0}, because it is being used in a connection profile. | ||||||
Validation | emptyInterfaceNameNotAllowed | Interface associated with an ECMP Traffic Zone should have a non-empty NAME. | ||||||
Validation | DHCPServerIPPoolAsClient | DHCP server IP address range is not valid if its already defined as a DHCP Client. | ||||||
Validation | geoUpdateError_3 | The update server did not have a file applicable to this device. Try again later. If the problem persists, contact Technical Support. | ||||||
Validation | pppoeDuplicateVpdnGrpName | The vpdnGrpName is the same as the PPPoE from interface {0}. | ||||||
Validation | ecmpZoneInterface | This interface is being used in an ECMP Zone. You cannot use this interface for other purposes. | ||||||
Validation | checksumError | Error in {0} checksum. The file is corrupt, obtain a new copy. | ||||||
Validation | cannotAddRaVPNInterface | Interface {0} is used for remote access VPN. You cannot include it in an ECMP traffic zone. | ||||||
Validation | invalidNetworkSubtypeForIdentityRuleSource | The identity rule source criteria contains a network object of an unsupported type. | ||||||
Validation | cfgExpInvalidObjTypesInEntityIds | Invalid entity types for a partial export job: {0} | ||||||
Validation | updateJobExists | A Manual Update Job of this type already exists. | ||||||
Validation | cannotDeleteReferredLocalUserInRule | Cannot delete local user object because it is being used by an access or SSL rule. | ||||||
Validation | bgpInvalidMinHoldTime | Minimum hold time should be less than hold time | ||||||
Validation | s2sIkev1Ikev2BothDisabled | IKEv1 and IKEv2 cannot be both disabled. You must enable either one or both | ||||||
Validation | appFilterInvalidProductivityValue | Invalid application filter business relevance value {0}. | ||||||
Validation | bgpInvalidGracefulRestartAndStalepathTimeDifference | There should be at least 240 secs difference between the restart timeand the stale path time | ||||||
Validation | invalidSmartCliStandardCommunityListValue | {0} entity value must be an existing Standard Community List Object | ||||||
Validation | illegalNumBitsForMask | Invalid number of bits for mask - {0}. Mask cannot be greater than 128 | ||||||
Validation | ECMPStaticRouteNotInECMPZone | There is already a static route with the same networks on different interface. You must specify another metric or add interfaces to an ECMP Zone. | ||||||
Validation | errorInEnablingCDO | Enabling Cisco Defense Orchestrator service failed. | ||||||
Validation | manualNatDest64AnyIpv6NotValid | The network corresponding to the full range of IPv6 addresses, i.e. ::/0, cannot be used in the destination of an IPv4 to IPv6 manual NAT rule | ||||||
Validation | InvalidBgpNeighborRoutesRemovePrivateAs | Private AS cannot be removed for IBGP peers. You cannot configure if BGP AS number is same as remote-as number. | ||||||
Validation | cryptoNonCompliantIkev2Policy | The IKEv2 policies are using DES encryption which is disallowed when the Smart License Account has export-controlled features enabled: {0}. | ||||||
Validation | passiveModeNotSupported | Passive mode is not supported on this interface. | ||||||
Validation | jobRunning | The task you are requesting is already in progress or it is queued to start. | ||||||
Validation | s2sIkev2ProposalsTooMany | Too many IKEv2 proposals. Number of assigned IKEv2 proposals cannot exceed {0} | ||||||
Validation | customRulesFileImportFailure | Failed to import rules. | ||||||
Validation | aaaInvalidUsername | Username cannot be empty or contain spaces | ||||||
Validation | invalidCacheTimeValue | Refresh time (minutes) for the CRL cache is invalid. | ||||||
Validation | haActionOnInvalidState | The current node state {0} does not allow HA {1} action. | ||||||
Validation | securityProtocolIsDeprecated | Security protocol version {0} is deprecated. You cannot use it. | ||||||
Validation | InstanceMissingNameField | Instance is missing name field. | ||||||
Validation | pppoeIpv4AddressIsStatic | The pppoe IPv4 IPAddress is static and should be provided. | ||||||
Validation | MustProvideRuleGroupId | You must provide at least one rule group ID. | ||||||
Validation | manualNatDestIntfIpv6DisabledWithIpv6InTransSrc | Destination interface "{0}" is not IPv6 enabled. You cannot use IPv6 addresses in the translated source | ||||||
Validation | napConfigOverrideCheck | Latest LSP update affected inspector overrides {0} under policy [{1}]. | ||||||
Validation | invalidOspfRedistBgpIdentifier | Identifier value {0} does not match the BGP autonomous system number in use | ||||||
Validation | invalidLengthFqdn | The fully-qualified domain name cannot be more than 128 characters. | ||||||
Validation | unsupportedSSPInterfaceSpeed | Unsupported SSP Interface Speed on NGFW: {0} | ||||||
Validation | overlappingSubnet | The IP address, {0}/{1}, cannot overlap with the subnet of interface {2} | ||||||
Validation | cloudRegionWithRegionDoesNotExist | The {0} cloud region does not exist. | ||||||
Validation | featureCapabilitiesNoHandler | Found feature capability without a matching capabilities handler | ||||||
Validation | maxOneInterface | Either Data interface or management interface can be selected. | ||||||
Validation | dupRealmInRealmSequence | Realm Sequence Object should not contain duplicate realms. | ||||||
Validation | IntfAddedIsOutside | The interface {0} is already added as an outside interface. | ||||||
Validation | snmpUserGroupContainAltLeastOneUser | SNMP User Group has to contain at least one user. | ||||||
Validation | invalidOspfRedistEigrpIdentifier | Identifier value {0} does not match the EIGRP autonomous system number in use | ||||||
Validation | reservedAddressNotAllowed | The IP address cannot be a reserved address (240.x.x.x to 255.x.x.x). | ||||||
Validation | ipAddressIsBlocked | The IP address {0} is reserved. You cannot assign it to the interface. | ||||||
Validation | powerOverEthernetConsumptionWattageShouldBeNull | Consumption wattage cannot be set on PoE disabled physical interface. | ||||||
Validation | PullFileHTTPFailed | File upload failed - Http(s) Transfer Error Status - | ||||||
Validation | XmlConfigNotWellFormed | XML configuration must be a well formed XML | ||||||
Validation | SSLPolicyDefaultActionBlockorDND | Default action for SSL policy can only be block or do-not-decrypt | ||||||
Validation | bgpInvalidAggregationToAnyIP | Aggregating to default is not allowed | ||||||
Validation | bypassInterfacePairEmpty | The hardware bypass pair contains no interfaces | ||||||
Validation | ftdUpdateMgrError_240 | Retry operation is not available. Reboot to continue. | ||||||
Validation | geoUpdateError_12 | GeoDB update file not found. | ||||||
Validation | ddnsRunTimesShouldBeNull | run times should be set to null when UpdateInterval is On Change. | ||||||
Validation | invalidSmartCliStringValueBlank | {0} value cannot be null or blank | ||||||
Validation | bridgeGroupInterfaceRederencedInBridgeGroup | The following interfaces are referenced by another Bridge Group Interface: {0}. You must remove them before you can add the interfaces to a bridge group. | ||||||
Validation | invalidOspfInterfaceVrf | Interface {0} should be a member of virtual router {1}. | ||||||
Validation | InvalidInspectionMode | The inspection mode must be DETECTION or PREVENTION. | ||||||
Validation | DHCPServerInterfaceName | This interface is being used as a DHCP server. You cannot remove the interface name until you change the DHCP server configuration. | ||||||
Validation | manualNatSrc46Ipv6PrefixTooLong | The translated source IPv6 network prefix length must be less than or equal to 96 in an IPv4 to IPv6 manual NAT source translation rule: {0}({1}) | ||||||
Validation | interfaceMigrateSourceAndDestinationCannotBeDiagnostic | Source and destination IDs cannot belong to the management interface. | ||||||
Validation | ftdUpdateMgrError_185 | Cancel upgrade in progress. Cannot revert. | ||||||
Validation | manualNatDest66TransDestIpv6PrefixTooShort | The translated destination IPv6 prefix must be greater than or equal to 64 in an IPv6 to IPv6 manual NAT destination translation: {0} | ||||||
Validation | AnyConnAuthenticationIdentitySourceNotSupported | Authentication identity source of type {0} is not supported. | ||||||
Validation | frequencyShouldBeMultipleOfThousand | The frequency value should be a multiple of 1000. | ||||||
Validation | versionMismatch | This upgrade is for software versions greater than or equal to {0} and less than {1}. | ||||||
Validation | DHCPServerInterfaceMgmt | DHCP server cannot be configured on the management interface. | ||||||
Validation | appFilterInvalidRiskName | Invalid application filter risk name {0}. | ||||||
Validation | snort2ToggleSuccess | Successfully switched to Snort version 2. | ||||||
Validation | AnyConnInsideNetNoPool | {0} address pool is required if {0} inside networks are specified | ||||||
Validation | DapXmlMustContainDfltRecord | Provide only DfltAccessPolicy record config when the DAP XML is empty | ||||||
Validation | invalidManagementIP | Cannot configure on managementip without IP address. Assign an IPv4 or IPv6 address to the Connectivity Interface. | ||||||
Validation | connectorIOError | Connector failed to connect. Please check the connection. | ||||||
Validation | noRevertInfo | No other version is available for Upgrade Revert. | ||||||
Validation | sslUnsupportedForCryptoCompliantAlgorithms | The DES encryption algorithm is not supported when strong encryption is allowed by your license. | ||||||
Validation | manualNatTransDestHasIpv6AndIpv4Addresses | The translated destination network should not contain both IPv4 and IPv6 addresses | ||||||
Validation | emptyAddressPoolForNatEnabled | NAT Exempt cannot be enabled when there is no client address assignment pool configured on any RAVPN connection profile or any of the group policies. | ||||||
Validation | natOtherOptionsNotSupported | The following options are not supported and should not be selected in NAT rules: {0} | ||||||
Validation | HTTPProxyCheckConfigAfterRestore | HTTP proxy is enabled after restore, please check the proxy reachability. | ||||||
Validation | invalidECMPZoneInterfaceVrf | Interface "{0}" should be a member of Virtual Router "{1}". | ||||||
Validation | invalidEtherChannelHardwareName | EtherChannel Hardware must be null, empty, or in the correct format (correct format is: Port-channel appended with EtherChannelID) | ||||||
Validation | natRuleImpactWithInterfaceChangingVRFConfig | One or more interfaces were moved from one virtual router to another. Any existing connections on moved interfaces will be dropped. One or more interfaces that were moved also have NAT rules configured. Please ensure you have configured appropriate routes across the virtual routers for those rules to function correctly. | ||||||
Validation | DapXmlMissingRecords | DAP XML configuration is missing some records : {0} | ||||||
Validation | CustomRuleMinSidValue | The sid of a custom rule must be {0} or higher. | ||||||
Validation | s2sNoRRIAndDynamicRRI | Dynamic reverse route injection cannot be enabled without enabling reverse route injection in site-to-site VPN | ||||||
Validation | backupInvalidEncryptionKey | Encryption key cannot be the reserved masking string: "{0}" | ||||||
Validation | prefixGreaterThanMask | The {0} prefix length should be greater than the IP address subnet mask value. | ||||||
Validation | cannotChangeExternalUserPassword | You cannot change the password for an externally authenticated user. Change the password in the external AAA server instead. | ||||||
Validation | bgpDuplicateInjectMapEntryNotAllowed | Duplicate Inject Map Entries are not allowed. | ||||||
Validation | s2scaCertUsedAsInternalCertificate | CA or self-signed certificate cannot be used as identity certificate for authentication between Site-to-Site VPN peers. Please provide a valid identity certificate for successful VPN establishment. | ||||||
Validation | cryptoNonCompliantIkev2PolicyForPrfType | The upgraded IKEv2 policies use MD5 as Pseudo Random Function (PRF) Hash which is not supported on this FTD version: {0}. | ||||||
Validation | securityIntelligenceWhitelistPolicyUnsupportedNetwork | The Security Intelligence Do Not Block list contains an unsupported network : {0} | ||||||
Validation | SAMLSystemDefinedCert | System defined certificates are prohibited. Use a certificate provided by the SAML issuer. | ||||||
Validation | SSLCipherInvalidSecurityLevelForProtocolVersion | Security level {0} not applicable for protocol versions {1} | ||||||
Validation | objectNat46AnyIpv6NotValid | The network corresponding to the full range of IPv6 addresses, i.e. ::/0, cannot be used in an IPv4 to IPv6 object NAT rule | ||||||
Validation | cryptoCompliantIkev1Policy | The IKEv1 policies are using strong encryption which is not allowed by your licensing setting, please disable them or use DES only: {0} | ||||||
Validation | invalidSlaTypeOfService | The value defines the Type of Service (ToS) type has to be between 0 and 255. | ||||||
Validation | scheduleInvalidName | Invalid schedule name | ||||||
Validation | invalidCharacters | Cannot contain special characters {0} | ||||||
Validation | IntrusionRuleGroupNotFound | Unable to find the IntrusionRuleGroup with ID:{0}. | ||||||
Validation | invalidPlatformLogSettings | Platform log settings property cannot be accepted on this platform. | ||||||
Validation | missingIdentityPolicyinAccessPolicy | You cannot disable the realm because an identity policy that uses it is associated with an access control policy. | ||||||
Validation | taskRunning | The task is queued/in-progress. Task cannot be deleted. | ||||||
Validation | timeRangeInvalidRange | The time range specification is incomplete. To configure a time range, you must specify the range's start day, end day, start time, and end time. | ||||||
Deployment | checksumTimeoutError | The deployment process could not retrieve the checksum. Please run deployment again. | ||||||
Deployment | missingRequiredPackage | A package file required for deployment, {0}, does not exist. The installation of a {1} update package may be required. | ||||||
Deployment | error | Error during deployment | ||||||
Deployment | alreadyQueued | There is already a deployment task pending. Wait until it completes before deploying changes again. | ||||||
Deployment | sruInfoLoadFail | The rule installation is corrupted. Please run a rule update to fix the problem. | ||||||
Deployment | deltaCliError | Internal error during delta CLI generation | ||||||
Deployment | nothingTodeploy | Nothing to Deploy. | ||||||
Deployment | ASAConfigExportFailedMessage | Deployment failed because exporting the Lina configuration failed. | ||||||
Deployment | failedUnknownReason | Deployment failed for an unknown reason. Please try deploying changes again. If the problem persists, reboot the device and try again. If you continue to have problems, contact Technical Support. | ||||||
Deployment | invalidPeerState | Failed to run {0} deployment because the peer is not ready to synchronize configuration. Peer state: {1} | ||||||
Deployment | noChassissSerialNumber | Failed to retrieve the chassis serial number. | ||||||
Deployment | deployPendingChanges | There are pending changes or mandatory deployment is required. Please deploy changes first. | ||||||
Deployment | missingHaConfiguration | Failed to read Interfaces from HAConfiguration object. | ||||||
Deployment | mergedDbNotEqual | Encountered an error when merging the databases for export. | ||||||
Deployment | generalIOError | Deployment cannot be performed due to an internal server error | ||||||
Deployment | currenrPolicyBundleUpdateFailed | Configuration is partially deployed and not completed. Please run deployment again. | ||||||
Deployment | failedEncryptionOnCertificateKey | Failure in encrypting the certificate key. | ||||||
Deployment | archiveError | Error creating deployment archive | ||||||
Deployment | generalError | Internal error during deployment: {0} | ||||||
Deployment | deployInProgress | You cannot start deployment with a deployment job already in progress | ||||||
Deployment | unfinished | The previous deployment did not finish properly. Please redeploy the changes. | ||||||
Deployment | invalidNodeState | Failed to run {0} deployment because the node is in {1} state. | ||||||
Deployment | pwdDecryptionError | Server failed to decrypt password for user {0}. If the problem persists, please re-create the user instance. | ||||||
Deployment | sensorExportFailedMessage | Deployment failed because exporting the Sensor configuration failed. | ||||||
Deployment | failedUnableToResolveHostname | Unable to resolve the hostname {0} with exception {1}, failing the deployment | ||||||
Deployment | timeoutError | The deployment process timed out. Please run deployment again. | ||||||
Deployment | requireNetModFixIntfSpeeds | The inserted Network Module interfaces changed some of the interface speed capabilities. Before deploying, please fix the interface speeds for: {0} | ||||||
Deployment | requireInterfaceScan | Some interfaces have been added to or removed from the device. Please perform an interface inventory scan before deploying the current configuration. | ||||||
General | fileTypeAndCategoryCsvFilesNotFound | The required CSV files for File Type and Category Bootstrap not found. | ||||||
General | accessDeniedHaStandbyWriteProhibited | This device is part of a high availability (HA) pair and is currently not in the active state. With few exceptions, you cannot edit the configuration for this device. To make any changes, please log into the active unit. | ||||||
General | invalidNeighborGeneralDescription | Neighbor General description cannot contain spaces or question mark | ||||||
General | FailedStringToJsonConversion | Failed to convert String to Json. | ||||||
General | FailedJsonToStringConversion | Failed to convert Json to String. | ||||||
General | HitcountCliParseFailure | Failed to parse output from FTD CLI | ||||||
General | smartLicenseDeregistrationJobInProgress | Deregistration is in progress. | ||||||
General | tooManyFailedAttempts | Too many failed attempts. You must wait before you can try again. | ||||||
General | ltpSudiConnectionError | Failed to connect to the Cisco Cloud from the platform. Check network connectivity with the cloud and retry. | ||||||
General | exportCommittedConfig | Committed state configuration. Cannot export if deployment is not performed. | ||||||
General | deviceAlreadyRegistered | The device was already enrolled. | ||||||
General | couldNotFindStatus | The requested deployment status id, {0}, does not exist. | ||||||
General | prefixNameContainsInvalidChar | Prefix name cannot contain characters other than a-z, A-Z, 0-9, -, and _ | ||||||
General | smartLicenseDeRegistrationJobCompleteSuccessfully | Smart License successfully deregistered. | ||||||
General | ciscoSseRegistrationSuccessful | Cisco cloud registration is successful | ||||||
General | failedToToggleCloudServiceState | Failed to toggle Cloud Service state. | ||||||
General | ltpSudiToolNotFound | Suditool script not found. Please retry. If the problem persists, contact Cisco TAC. | ||||||
General | addFMCManagerSuccess | FMC manager was successfully added. | ||||||
General | CouldNotUpdateRule | Failed to update rule with Uuid: {0} | ||||||
General | cloudUnregistrationInternalError | Received internal server error from cloud service. Retry after some time. If problem persists, contact Cisco TAC. | ||||||
General | cloudEnrollmentDroppedConnection | Cloud service dropped connection. Retry after some time. | ||||||
General | cleaningUpAfterCancellation | Cleaning up after FMC registration job was canceled. | ||||||
General | cloudServiceEnablingNeedsCloudEnrollment | Before enrolling in {0}, you must enroll the device in cloud. | ||||||
General | errorConnectingToRadiusIdentitySource | Error connecting to RADIUS identity source | ||||||
General | cloudRegistrationConnectionUnauthorized | Connection to cloud service unauthorized. Re-register with a new valid token. | ||||||
General | ampConnectionSuccess | Successfully connected to cloud | ||||||
General | couldNotGetValidURLResources | Failed to get the list of valid URL resource names for authorization enforcement | ||||||
General | cleaningUpAfterTimeOut | Cleaning up after FMC registration job timed out. | ||||||
General | CliCommandFileParsingError | Exception occurred while parsing the command file. | ||||||
General | ciscoSseRegistrationFailed | Cisco cloud registration failed | ||||||
General | storedFileDownloadError | Unable to download the stored file's hash list. | ||||||
General | FDMInReadOnlyModeFMCRegistrationInProgress | Registration with FMC is in progress. Configuration changes are not allowed. You can only cancel FMC registration. | ||||||
General | storedFileSuccess | Stored SHA list file successfully generated. | ||||||
General | registrationFailedDueToInvalidToken | The Smart License registration can not be completed because the provided token is invalid | ||||||
General | FMCRegistrationJobFailedAndRemoveFMCManagerFail | FMC registration job and clean up failed because FMC Manager cannot be removed. | ||||||
General | currentlyInDeadTime | Failed to authenticate user against identity source group because it is currently in dead time | ||||||
General | cloudServicesMessagingConnectionFailed | Failed to connect to a cloud service. Check network connectivity and retry. | ||||||
General | cloudEnrollmentInternalError | Received internal server error from cloud service. Retry after some time. If problem persists, contact Cisco TAC. | ||||||
General | couldNotFindFile | Failed to find Lina CLI file, {0}. | ||||||
General | cleanUpFMCRegistrationJobRemoveFMCManagerFail | Clean Up failed to remove FMC Manager. | ||||||
General | errorOccurredWhileProcessingRadiusClient | Error occurred while processing RADIUS client | ||||||
General | cliCommandExecutionFailed | Command execution failed. | ||||||
General | FMCRegistrationJobCancelledAndRemoveFMCManagerFail | FMC registration job was cancelled and clean up failed because FMC Manager cannot be removed. | ||||||
General | classNotFound | Class not found: {0} | ||||||
General | cannotCancelFMCRegistrationJob | Cannot start cancellation on FMC Registration job within {0} milliseconds. | ||||||
General | failedToSyncWebUiCertificateToDevice | Failed to synchronize the Web UI Certificate to the device. | ||||||
General | smartLicensePerformanceTierUpdateJobInProgress | Performance Tier update is in progress. | ||||||
General | cannotCompleteCancelFMCRegistrationJob | Cannot finish cancellation on FMC Registration job within {0} milliseconds. | ||||||
General | versionMismatch | Failed to import the configuration from the active peer. The software version of the peer, {0}, does not match the software version of this unit, {1}. Please install the same software version on each peer. Then, ensure that you make the currently active peer the active peer again, and deploy the configuration from the active unit. | ||||||
General | failedToConnect | The device was unable to connect to the Smart Licensing server. This might indicate a gateway problem for the management interface. Please select Evaluation Mode for now. Then, after completing setup, go to Device > System Settings > Management Interface and verify the management address and gateway configuration. There must be a path from the management IP address to the Internet to complete Smart License registration. You can then go to Device > Smart License and try registering again. | ||||||
General | cloudRegistrationDroppedConnection | Cloud service dropped connection. Retry after some time. | ||||||
General | errorOccurredUpdatingUser | Error occurred when updating user information | ||||||
General | FMCRegistrationJobTimedOutAndRemoveFMCManagerFail | FMC registration job timed out and clean up failed because FMC Manager cannot be removed. | ||||||
General | ampConnectionNormal | Cloud connectivity functioning normally | ||||||
General | HitcountDBCreateFailure | Failed to initialize hit count database tables | ||||||
General | changePasswordFailed | Current password is not correct. You must enter the correct current password to change it. | ||||||
General | invalidFMCRegistrationObject | Valid FMCRegistrationSettings object is required for FMC registration job. | ||||||
General | ciscoSseUnregistrationInProgress | Unenrolling the device from the cloud. | ||||||
General | FMCRegistrationJobSuccess | FMC configuration and communication were successful. | ||||||
General | smartLicenseRegistrationJobFailed | Smart License registration job cannot be completed. | ||||||
General | smartLicenseRegistrationJobInProgress | Registration is in progress. | ||||||
General | duplicatePathsWithConflicts | Duplicate resource pointing to same path without correct overriding path. Resource Mappings process is incomplete. | ||||||
General | failedToAuthenticateUser | Failed to authenticate user | ||||||
General | cliCommandExecutionTimeOut | Command execution timed out. Please try again. | ||||||
General | ltpProxyAuthFailure | Failed to connect to the Cisco Cloud due to a HTTP Proxy authentication error. Check the HTTP Proxy Authentication configuration and retry. | ||||||
General | ltpSerialNumberNotClaimed | Claim the device in Cisco Defense Orchestrator using the serial number before starting the Cloud Auto Enrollment process. | ||||||
General | cloudRegionCertificateNotReceived | The certificate was not received from the cloud regions domain. | ||||||
General | storedFileFailed | Error generating stored SHA list file. | ||||||
General | cloudRegistrationInternalError | Received internal server error from cloud service. Retry after some time. If problem persists, contact Cisco TAC. | ||||||
General | accessDeniedDueToUserRole | You do not have access to edit this feature based on your User Role. | ||||||
General | cloudRegistrationRefreshFailed | The registration refresh with the Cisco cloud failed. | ||||||
General | cleaningUpAfterFailure | Cleaning up after FMC registration job failed. | ||||||
General | invalidSessionId | User session id is not valid. | ||||||
General | ciscoSseUnregistrationRequestWasNotFulfilled | Cisco cloud deregistration request was not fulfilled by the Cisco cloud server. | ||||||
General | fileTypeAndCategoryBootstrapFailure | Failed at File Type and Category Bootstrap step. | ||||||
General | cloudRegistrationRefreshConnectionUnauthorized | Connection to cloud service unauthorized. Re-register with a new valid token. | ||||||
General | smartLicenseDeRegistrationJobFailed | Smart License deregistration job cannot be completed. | ||||||
General | duplicateRadiusServerInGroup | Radius Identity Source Group cannot contain duplicates of the same server. | ||||||
General | FMCRegistrationJobTimedOut | FMC registration job timed out. | ||||||
General | invalidPassword | Invalid password: A blank or masked password is not allowed. | ||||||
General | HPMServerUnavailable | System is unable to obtain the device metrics at this moment, please try again later. | ||||||
General | unknownHost | Unknown Host: {0} | ||||||
General | unableParseFile | Unable to parse file | ||||||
General | cloudUnregistrationFailedResolveFqdn | Failed to resolve cloud service FQDN. Check network connectivity or DNS configuration and retry | ||||||
General | couldNotResolveAuthorization | Failed to resolve authorization for current user | ||||||
General | cloudEnrollmentConnectionUnauthorized | Connection to cloud service unauthorized. Re-register with a new valid token. | ||||||
General | cloudRegistrationRefreshDroppedConnection | Cloud service dropped connection. Retry after some time. | ||||||
General | failedToGenerateTokenViaSmartLicense | Failed to generate token to enroll with the Cisco cloud using Smart License. | ||||||
General | fdmIsStillStarting | FDM is performing bootstrap initialization following an install or upgrade. Use the REST api '/api/fdm/latest/jobs/bootstrap' to check status. | ||||||
General | smartLicenseRegistrationJobCompleteSuccessfully | Smart License successfully registered. | ||||||
General | cloudServicesReRegistrationDeactivateFailed | Failed to re-register device to cloud: Unable to un-register the device from the default tenant. Check network connectivity with cloud and retry. | ||||||
General | noAuthorizationFoundForUser | No external authorization cisco-av-pairs were found; unable to authorize user | ||||||
General | deviceEnrollmentRequiredForThisOperation | The device is not enrolled, but enrollment is required for this operation. | ||||||
General | getparamsArgumentLength | Argument length less than 1 | ||||||
General | SecurityIntelligenceFeedsUpdateSucceeded | Security Intelligence feeds download succeeded. | ||||||
General | interfaceNeedsToBeSpecified | Interface to connect to radius server "{0}" needs to be specified. | ||||||
General | FMCRegistrationJobCancelled | FMC registration job was cancelled. | ||||||
General | cloudRegistrationConnectionForbidden | Connection to cloud service forbidden. | ||||||
General | performanceTierUpdateJobCompleteSuccessfullyReleaseFailed | Performance Tier updated but some licenses for previous tier are failed to release. Please re-sync connection from the Smart Licensing page | ||||||
General | malwareUpdateSuccess | Malware signature pack is up to date. | ||||||
General | smartLicensePerformanceTierUpdateJobFailedResync | Performance Tier update job cannot be completed. Please re-sync connection from the Smart Licensing page | ||||||
General | FMCRegistrationJobFailure | FMC registration job failed. | ||||||
General | fileTypeAndCategoryNotFound | File Type or Category details with Id {0} not found | ||||||
General | smartAgentDelegateUnsupportedConnectionType | Connection type {0} is not supported. | ||||||
General | failedToConnectDueToDnsIssue | Unable to resolve IP by {0}. Please verify that the DNS server addresses are correct. | ||||||
General | cloudUnregistrationDroppedConnection | Cloud service dropped connection. Retry after some time. | ||||||
General | waitingForSmartLicenseRegistration | Waiting for the device being registered via Smart License. | ||||||
General | cancelFMCRegistrationJobFailUnknownReason | Cancellation on FMC Registration job failed with unknown reason. | ||||||
General | invalidFile | Invalid export file. | ||||||
General | failedToSendTelemetryData | Could not send telemetry data: the device is not enrolled or there was a connection issue. | ||||||
General | malwareUpdateFailed | Recent malware update attempt failed. | ||||||
General | createInstanceError | Cannot create instance of class: {0} | ||||||
General | cryptoFtdKeyFailure | Server failed to encrypt the FTD certificate key | ||||||
General | ampConnectionFailure | Cannot connect to cloud | ||||||
General | cloudRegistrationRefreshFailedResolveFqdn | Failed to resolve cloud service FQDN. Check network connectivity or DNS configuration and retry. | ||||||
General | cloudEnrollmentConnectorInternalError | Connector internal error. Check network connectivity and retry. If problem persists, contact Cisco TAC. | ||||||
General | userNotFound | User not found | ||||||
General | cloudRegistrationRefreshConnectorInternalError | Connector internal error. Check network connectivity and retry. If problem persists, contact Cisco TAC. | ||||||
General | timeout | The attempt to ping {0} timed out. Please verify that the interface is connected to a gateway that can reach the internet. | ||||||
General | injectionDetected | Invalid input data | ||||||
General | cloudRegistrationRefreshConnectionFailed | Failed to connect to a cloud service. Check network connectivity and retry. | ||||||
General | cloudRegistrationRefreshInternalError | Received internal server error from cloud service. Retry after some time. If problem persists, contact Cisco TAC. | ||||||
General | cannotFindHTTPSAAASetting | You cannot connect using HTTPS due to possible database corruption. If this device is the secondary device in a high-availability pair, synchronization might have failed; please try deploying from the primary again to trigger a sync to the secondary. Otherwise, please contact Cisco TAC. | ||||||
General | entityNotCompatibleWithDestinationInterface | Entity is not compatible with the destination interface. | ||||||
General | importFail | Unable to import database | ||||||
General | failedToAuthenticateAgainstLocal | Failed to authenticate user against local identity source | ||||||
General | deviceEnrollmentInProgress | The device enrollment with the Cisco cloud in progress. | ||||||
General | accessDeniedConfigImportInProgress | The device is importing its configuration from the peer unit. After the import completes, you might need to log in again. | ||||||
General | cloudServiceEnablingFailure | Could not complete enrollment in {0}. | ||||||
General | cloudRegistrationConnectorInternalError | Connector internal error. Check network connectivity and retry. If problem persists, contact Cisco TAC. | ||||||
General | ProcessTimedOut | Process timed out. Please try again later. | ||||||
General | exportMixedConfig | Mixed state configuration. Cannot export if deployment is not performed. | ||||||
General | exportFail | Unable to export database | ||||||
General | errorGettingPermissions | Error occurred when getting the access rights for the user | ||||||
General | rsyncFail | Failed to download file {0} via rsync for database import | ||||||
General | unsupportedImport | Unsupported import type: {0} | ||||||
General | HitcountDBReadFailure | Failed to read from hit count database tables | ||||||
General | SecurityIntelligenceScheduleDisableError | Exception occurred while disabling default Security Intelligence feed download schedule. | ||||||
General | couldNotLogoutUser | Could not terminate session. Please try again. | ||||||
General | configSkipped | Config import skipped. Please upgrade both units in the HA pair to the same version, and perform a deployment from the active unit to synchronize the configuration. | ||||||
General | cloudUnregistrationConnectorInternalError | Connector internal error. Check network connectivity and retry. If problem persists, contact Cisco TAC. | ||||||
General | cloudRegistrationConnectionFailed | Failed to connect to a cloud service. Check network connectivity and retry. | ||||||
General | cloudEnrollmentConnectionForbidden | Connection to cloud service forbidden. | ||||||
General | conflictingAuthorizationFoundFromProvider | Conflicting authorization cisco-av-pairs were received from the AAA provider this user. Unable to resolve the authorization profile for this user | ||||||
General | addFMCManagerFail | FMC manager cannot be added. | ||||||
General | cloudServiceEnablingSuccess | Completed enrollment in {0}. | ||||||
General | performanceTierUpdateJobCompleteSuccessfully | Performance Tier successfully updated. | ||||||
General | smartLicenseRegistrationRequired | Smart License registration required to enroll with a Smart Virtual Account. | ||||||
General | ciscoSseUnregistrationSuccessful | Cisco cloud deregistration is successful. | ||||||
General | unauthorizedUserCustomTokenCreation | Unauthorized to create custom token. Custom Token can be created by local Admin users only. | ||||||
General | generalErrorMessageHandlingRequest | Unable to handle request | ||||||
General | accessDeniedImportFromCfgFileInProgress | The device is importing objects from a configuration file. After the import completes, you might need to log in again. | ||||||
General | failedToConnect | Unable to ping {0}. Please verify that the interface is connected to a gateway that can reach the internet. | ||||||
General | cloudServiceEnablingJobWasCreated | {0} enabling job was successfully created. | ||||||
General | HitcountDBUpdateFailure | Failed to update hit count values in database tables | ||||||
General | connectorDataDirectoryNotFound | The system failed to find the connector data directory path. | ||||||
General | cannotFindHTTPSAAASettingHA | The server is busy. Please try again later. | ||||||
General | badCredentials | Bad Credentials | ||||||
General | resourceMappingCyclicDependency | Cyclical Resource dependency is detected. Resource Mappings process is incomplete. | ||||||
General | deviceRegistrationContextCreationInprogress | Device registration context creation in progress. | ||||||
General | cloudServiceEnablingInProgress | Enrollment in {0} in progress. | ||||||
General | incorrectUploadFileExtensionError | You can upload supported files (extensions .pkg, xml, json, fsp, asp, isp, nvmsp, nsp, wsp, wso) only. | ||||||
General | cloudServicesReRegistrationActivateFailed | Failed to re-register device to cloud: Unable to register the device to cloud tenant. Check network connectivity with cloud and retry. | ||||||
General | accessDeniedDeploymentConfigGenerationsInProgress | The device is generating deployment data. After the generation completes, you might need to log in again. | ||||||
General | changePasswordInvalidBlank | Invalid password: A blank password is not allowed. | ||||||
General | unknownError | An unexpected error occurred. | ||||||
General | ltpSudiProxySupportNotAvailable | Cloud Auto Enrollment is not supported with HTTP Proxy. To use the Cloud Auto Enrollment process, disable HTTP Proxy and try again. | ||||||
General | unableToResolveRadiusServerIdentitySource | Could not resolve RADIUS identity source address | ||||||
General | deviceEnrollmentInitialized | The device enrollment with the Cisco cloud initialized. | ||||||
General | cloudUnregistrationConnectionForbidden | Connection to cloud service forbidden. | ||||||
General | cloudServicesReRegistrationParseFailed | Failed to re-register the device to cloud due to a message parsing issue. Check network connectivity with cloud and retry. If problem persists, contact Cisco TAC. | ||||||
General | deviceSuccessfullyEnrolledInCloud | The device was successfully enrolled with the Cisco cloud in region {0}. | ||||||
General | registrationFail | The registration could not be completed. The system will automatically try registration again. | ||||||
General | cloudRegistrationRefreshConnectionForbidden | Connection to cloud service forbidden. | ||||||
General | cloudEnrollmentConnectionFqdn | Failed to resolve cloud service FQDN. Check network connectivity or DNS configuration and retry. | ||||||
General | smartAgentAlreadyEnabled | Smart Licence Agent is already enabled. | ||||||
General | ampConnectionBadKeys | Bad keys for cloud communication | ||||||
General | cloudUnregistrationConnectionFailed | Failed to connect to a cloud service. Check network connectivity and retry. | ||||||
General | cloudEnrollmentDeleteIsStarted | Cloud un-enrollment has started and will be finished as a result of the corresponding job. | ||||||
General | ciscoSseUnregistrationFailed | Cisco cloud deregistration failed. | ||||||
General | cloudRegionCertificatePathNotFound | The system failed to find the certificate for validating the cloud regions domain. | ||||||
General | cancellingFMCRegistrationJob | Cancelling FMC registration job. | ||||||
General | cloudEnrollmentNotStartedDueToFailedSmartLicense | The device enrollment with the Cisco cloud was not started due to Smart License registration failure. | ||||||
General | AdapterLoadingFailed | Failed to load the encoder/decoder {0} for the model {1} | ||||||
General | AdapterTemplateMappingNotFound | Smart CLI Template mapping not found for the model {0} | ||||||
General | ltpProxyConnectFailure | Failed to connect to the Cisco Cloud due to a HTTP Proxy configuration. Check the HTTP Proxy configuration and retry. | ||||||
General | cloudRegistrationFailedDueToInvalidToken | The device enrollment with the Cisco cloud failed because of invalid token. Retry with a new valid token. | ||||||
General | unableToResolveSourceIP | Unable to resolve source IP of the incoming HTTP request | ||||||
General | externalSmartLicenseDeRegistrationJobCompleteSuccessfully | Smart License successfully deregistered by CSSM. | ||||||
General | capturedFileDoesNotExist | The requested file with SHA256 does not exist. It might have been deleted. | ||||||
General | exportConfigFailed | Failed to export intrusion config. | ||||||
General | cloudRegionInvalidCertificate | The certificate for the cloud regions domain is invalid. | ||||||
General | cloudServiceWasNotFoundInDatabase | CloudService object {0} was not found in the database. | ||||||
General | ltpInvalidSudiSseRequest | Registration request to Cisco Cloud failed due to invalid request from platform. Please retry and if the problem persists, contact Cisco TAC. | ||||||
General | SecurityIntelligenceFeedsUpdateFailed | Security Intelligence feeds download failed. | ||||||
General | invalidDynamicAuthorizationPort | Dynamic authorization port must be between 1024 and 65535 | ||||||
General | SecurityIntelligenceFeedsUpdateInProgress | Security Intelligence feeds is in progress. | ||||||
General | tokenExpiredUnAuthorizedAccess | The access token has expired. You are no longer authorized. Please refresh the token or authenticate again. | ||||||
General | cloudEnrollmentConnectionFailed | Failed to connect to a cloud service. Check network connectivity and retry. | ||||||
General | smartLicensePerformanceTierUpdateJobFailed | Performance Tier update job cannot be completed. | ||||||
General | instanceExist | An object of this type already exists. You have only one object of this type. | ||||||
General | timedOutConnectingToRadiusIdentitySource | Timed out connecting to RADIUS identity source | ||||||
General | deviceFailedToEnrollInCloudService | The device enrollment with the Cisco cloud failed. | ||||||
General | cannotFindAAASetting | Unable to authenticate, please contact your system administrator. | ||||||
General | userRoleInvalid | The user role is invalid. Please specify a valid user role. | ||||||
General | smartLicenseDeRegistrationNeslaFailure | Failed to deregister Smart License in Cisco Smart Software Manager (CSSM). The device is now in an unregistered state, but you need to go to CSSM and deregister the device manually to complete the process. | ||||||
General | testConnectionSucceeded | The connection test succeeded | ||||||
General | deviceContextActivationFailed | Could not activate context. Please try again. | ||||||
General | ltpSudiBadRequestFailure | Failed to connect to the Cisco Cloud due to a bad request from the platform. Please reboot and try again. If the problem persists, contact Cisco TAC. | ||||||
General | cloudUnregistrationConnectionUnauthorized | Connection to cloud service unauthorized. Re-register with a new valid token. | ||||||
General | sseConfigurationNotFound | Configuration for SSE has not been found. | ||||||
General | performanceTierUpdateFailedDueReboot | Performance Tier update job has failed as a result of a reboot, please try again. | ||||||
General | ltpSudiToolException | Exception occurred when connecting to cloud. Please retry and if the problem persists, contact Cisco TAC. | ||||||
General | exportDeploymentOngoing | Deployment in progress. Cannot export: {0}. | ||||||
General | cloudRegistrationFailedResolveFqdn | Failed to resolve cloud service FQDN. Check network connectivity or DNS configuration and retry. |