Syslog Message Descriptions
This section lists all of the syslog messages.
- Message
- SYSLOG: <13> Feb 28 05:36:49 ROUTE MAC-Move: Rapid MAC movement observed for MAC:0000.0000.aaaa from Port:1/1/10 to Port:1/1/9 in VLAN 20
- Explanation
- Indicates there are two or more MAC movements across multiple ports of the system within a second, then it can be considered as rapid mac movement.
- Explanation
-
Indicates that the log entries reached the configured threshold value of logging buffer.
- Message
- Flexlink: Active link 1/1/3 failed, Backup link :2/1/5 transitioning to UP state by root user from console session
- Message
- Flexlink: Backup link 2/1/5 failed, Active link :1/1/3 transitioning to UP state by root user from console session
- Explanation
-
Indicates that the current forwarding link is preempted according to the preemption forced mode configuration.
- Message
- MAC Authentication failed for mac-address on portnum (No VLAN Info received from RADIUS server)
- Explanation
RADIUS authentication was successful for the specified mac-address on the specified portnum; however, dynamic VLAN assignment was enabled for the port, but the RADIUS Access-Accept message did not include VLAN information. This is treated as an authentication failure.
- Message
- MAC Authentication failed for mac-address on portnum (Port is already in another radius given vlan)
- Explanation
RADIUS authentication was successful for the specified mac-address on the specified portnum; however, the RADIUS Access-Accept message specified a VLAN ID, although the port had previously been moved to a different RADIUS-assigned VLAN. This is treated as an authentication failure.
- Message
- MAC Authentication failed for mac-address on portnum (RADIUS given VLAN does not match with TAGGED vlan)
- Explanation
Multi-device port authentication failed for the mac-address on a tagged port because the packet with this MAC address as the source was tagged with a VLAN ID different from the RADIUS-supplied VLAN ID.
- Message
- Temperature degrees C degrees, warning level warn-degrees C degrees, shutdown level shutdown-degrees C degrees
- Explanation
Indicates an over temperature condition on the active module.
The degrees value indicates the temperature of the module.
The warn-degrees value is the warning threshold temperature configured for the module.
The shutdown-degrees value is the shutdown temperature configured for the module.
- Explanation
Denial of Service (DoS) attack protection was enabled for multi-device port authentication on the specified portnum, and the per-second rate of RADIUS authentication attempts for the port exceeded the configured limit. The RUCKUS device considers this to be a DoS attack and disables the port.
- Message
- DOT1X: port portnum - MAC mac address is unauthorized because system resource is not enough or the invalid information to set the dynamic assigned IP ACLs or MAC ACLs
- Explanation
802.1X authentication failed for the client with the specified MAC address on the specified portnum either due to insufficient system resources on the device or due to invalid IP ACL or MAC ACL information returned by the RADIUS server.
- Message
- DOT1X: Port portnum is unauthorized because system resource is not enough or the invalid information to set the dynamic assigned IP ACLs or MAC ACLs
- Explanation
802.1X authentication could not take place on the port. This happened because strict security mode was enabled and one of the following occurred:
- Message
- DOT1X: Port portnum currently used vlan-id changes to vlan-id due to dot1x-RADIUS vlan assignment
- Explanation
A user has completed 802.1X authentication. The profile received from the RADIUS server specifies a VLAN ID for the user. The port to which the user is connected has been moved to the specified VLAN ID.
- Message
- Enable super | port-config | read-only password deleted | added | modified from console | telnet | ssh| snmp OR Line password deleted | added | modified from console | telnet | ssh| snmp
- Explanation
A user created, re-configured, or deleted an Enable or Line password through the SNMP, console, SSH, or Telnet session.
- Message
- MAC ACL added | deleted | modified from console | telnet | ssh| snmp session filter id = MAC ACL ID , src MAC = Source MAC address | any, dst MAC = Destination MAC address | any
- Explanation
A user created, modified, deleted, or applied this MAC ACL through the SNMP, console, SSH, or Telnet session.
- Message
- Security: telnet | SSH login by username from src IP ip-address , src MAC mac-address to USER | PRIVILEGE EXEC mode
- Explanation
The specified user logged into the device using Telnet or SSH from the specified IP address, the specified MAC address, or both. The user logged into the specified exec mode.
- Message
- Security: telnet | SSH logout by username from src IP ip-address, src MAC mac-address to USER | PRIVILEGE EXEC mode
- Explanation
The specified user logged out of the device. The user was using Telnet or SSH to access the device the specified IP address, the specified MAC address, or both. The user logged out of the specified exec mode.
- Message
- SNMP read-only community | read-write community | contact | location | user | group | view | engineid | trap [host] [ value -str ] deleted | added | modified from console | telnet | ssh| snmp session
- Explanation
A user made SNMP configuration changes through the SNMP, console, SSH, or Telnet session.
The [ value-str ] does not appear in the message if SNMP community or engineid is specified.
- Message
- Syslog server IP-address deleted | added | modified from console | telnet | ssh| snmp OR Syslog operation enabled | disabled from console | telnet | ssh| snmp
- Explanation
A user made Syslog configuration changes to the specified Syslog server address or enabled or disabled a Syslog operation through the SNMP, console, SSH, or Telnet session.
- Explanation
The number of ICMP packets exceeds the burst-max threshold set by the ip icmp burst command. The RUCKUS device may be the victim of a Denial of Service (DoS) attack.
All ICMP packets will be dropped for the number of seconds specified by the lockup value. When the lockup period expires, the packet counter is reset, and measurement is restarted.
- Explanation
The number of TCP SYN packets exceeds the burst-max threshold set by the ip tcp burst command. The RUCKUS device may be the victim of a TCP SYN DoS attack.
All TCP SYN packets will be dropped for the number of seconds specified by the lockup value. When the lockup period expires, the packet counter is reset, and measurement is restarted.
- Explanation
Threshold parameters for local TCP traffic on the device have been configured, and the maximum burst size for TCP packets has been exceeded.
The first num is the maximum burst size (maximum number of packets allowed).
The second num is the number of seconds during which additional TCP packets will be blocked on the device.
Note: This message can occur in response to an attempted TCP SYN attack.
- Message
- OSPF intf authen failure, rid router-id , intf addr ip-addr , pkt src addr src-ip-addr , error type error-type , pkt type pkt-type
- Explanation
An OSPF interface authentication failure has occurred.
The router-id is the router ID of the RUCKUS device.
The ip-addr is the IP address of the interface on the RUCKUS device.
The src-ip-addr is the IP address of the interface from which the RUCKUS device received the authentication failure.
The error-type can be one of the following:
- bad version
- area mismatch
- unknown NBMA neighbor
- unknown virtual neighbor
- authentication type mismatch
- authentication failure
- network mask mismatch
- hello interval mismatch
- dead interval mismatch
- option mismatch
- unknown
The packet-type can be one of the following:
- Message
- OSPF intf config error, rid router-id , intf addr ip-addr , pkt src addr src-ip-addr , error type error-type , pkt type pkt-type
- Explanation
An OSPF interface configuration error has occurred.
The router-id is the router ID of the RUCKUS device.
The ip-addr is the IP address of the interface on the RUCKUS device.
The src-ip-addr is the IP address of the interface from which the RUCKUS device received the error packet.
The error-type can be one of the following:
- bad version
- area mismatch
- unknown NBMA neighbor
- unknown virtual neighbor
- authentication type mismatch
- authentication failure
- network mask mismatch
- hello interval mismatch
- dead interval mismatch
- option mismatch
- unknown
The packet-type can be one of the following:
- Message
- OSPF intf rcvd bad pkt, rid router-id , intf addr ip-addr , pkt src addr src-ip-add r, pkt type pkt-type
- Explanation
An OSPF interface received a bad packet.
The router-id is the router ID of the RUCKUS device.
The ip-addr is the IP address of the interface on the RUCKUS device.
The src-ip-addr is the IP address of the interface from which the RUCKUS device received the authentication failure.
The packet-type can be one of the following:
- Message
- OSPF intf rcvd bad pkt: Bad Checksum, rid ip-addr , intf addr ip-addr , pkt size num , checksum num , pkt src addr ip-addr , pkt type type
- Explanation
The device received an OSPF packet that had an invalid checksum.
The rid ip-addr is the RUCKUS router ID.
The intf addr ip-addr is the IP address of the RUCKUS interface that received the packet.
The pkt size num is the number of bytes in the packet.
The checksum num is the checksum value for the packet.
The pkt src addr ip-addr is the IP address of the neighbor that sent the packet.
The pkt type type is the OSPF packet type and can be one of the following:
- Message
- OSPF intf rcvd bad pkt: Bad Packet type, rid ip-addr, intf addr ip-addr , pkt size num , checksum num , pkt src addr ip-addr , pkt type type
- Explanation
The device received an OSPF packet with an invalid type.
The parameters are the same as for the Bad Checksum message. The pkt type type value is "unknown", indicating that the packet type is invalid.
- Message
- OSPF intf rcvd bad pkt: Unable to find associated neighbor, rid ip-addr, intf addr ip-addr, pkt size num , checksum num , pkt src addr ip-addr , pkt type type
- Explanation
The neighbor IP address in the packet is not in the list of OSPF neighbors in the RUCKUS device.
The parameters are the same as for the Bad Checksum message.
- Message
- OSPF intf retransmit, rid router-id, intf addr ip-addr, nbr rid nbr-router-id , pkt type is pkt-type, LSA type lsa-type , LSA id lsa-id, LSA rid lsa-router-id
- Explanation
An OSPF interface on the RUCKUS device has retransmitted a Link State Advertisement (LSA).
The router-id is the router ID of the RUCKUS device.
The ip-addr is the IP address of the interface on the RUCKUS device.
The nbr-router-id is the router ID of the neighbor router.
The packet-type can be one of the following:
The lsa-type is the type of LSA.
The lsa-id is the LSA ID.
The lsa-router-id is the LSA router ID.
- Message
- OSPF max age LSA, rid router-id , area area-id , LSA type lsa-type , LSA id lsa-id , LSA rid lsa-router-id
- Explanation
An LSA has reached its maximum age.
The router-id is the router ID of the RUCKUS device.
The area-id is the OSPF area.
The lsa-type is the type of LSA.
The lsa-id is the LSA ID.
The lsa-router-id is the LSA router ID.
- Message
- OSPF nbr state changed, rid router-id , nbr addr ip-addr , nbr rid nbr-router-Id , state ospf-state
- Explanation
The state of an OSPF neighbor has changed.
The router-id is the router ID of the RUCKUS device.
The ip-addr is the IP address of the neighbor.
The nbr-router-id is the router ID of the neighbor.
The ospf-state indicates the state to which the interface has changed and can be one of the following:
- Message
- OSPF originate LSA, rid router-id , area area-id , LSA type lsa-type , LSA id lsa-id , LSA router id lsa-router-id
- Explanation
An OSPF interface has originated an LSA.
The router-id is the router ID of the RUCKUS device.
The area-id is the OSPF area.
The lsa-type is the type of LSA.
The lsa-id is the LSA ID.
The lsa-router-id is the LSA router ID.
- Message
- OSPF virtual intf authen failure, rid router-id , intf addr ip-addr , pkt src addr src-ip-addr , error type error-type , pkt type pkt-type
- Explanation
An OSPF virtual routing interface authentication failure has occurred.
The router-id is the router ID of the RUCKUS device.
The ip-addr is the IP address of the interface on the RUCKUS device.
The src-ip-addr is the IP address of the interface from which the RUCKUS device received the authentication failure.
The error-type can be one of the following:
- bad version
- area mismatch
- unknown NBMA neighbor
- unknown virtual neighbor
- authentication type mismatch
- authentication failure
- network mask mismatch
- hello interval mismatch
- dead interval mismatch
- option mismatch
- unknown
The packet-type can be one of the following:
- Message
- OSPF virtual intf config error, rid router-id , intf addr ip-addr , pkt src addr src-ip-addr , error type error-type , pkt type pkt-type
- Explanation
An OSPF virtual routing interface configuration error has occurred.
The router-id is the router ID of the RUCKUS device.
The ip-addr is the IP address of the interface on the RUCKUS device.
The src-ip-addr is the IP address of the interface from which the RUCKUS device received the error packet.
The error-type can be one of the following:
- bad version
- area mismatch
- unknown NBMA neighbor
- unknown virtual neighbor
- authentication type mismatch
- authentication failure
- network mask mismatch
- hello interval mismatch
- dead interval mismatch
- option mismatch
- unknown
The packet-type can be one of the following:
- Message
- OSPF virtual intf rcvd bad pkt, rid router-id , intf addr ip-addr , pkt src addr src-ip-addr , pkt type pkt-type
- Explanation
An OSPF interface received a bad packet.
The router-id is the router ID of the RUCKUS device.
The ip-addr is the IP address of the interface on the RUCKUS device.
The src-ip-addr is the IP address of the interface from which the RUCKUS device received the authentication failure.
The packet-type can be one of the following:
- Message
- OSPF virtual intf retransmit, rid router-id , intf addr ip-addr , nbr rid nbr-router-id , pkt type is pkt-type , LSA type lsa-type , LSA id lsa-id , LSA rid lsa-router-id
- Explanation
An OSPF interface on the RUCKUS device has retransmitted a Link State Advertisement (LSA).
The router-id is the router ID of the RUCKUS device.
The ip-addr is the IP address of the interface on the RUCKUS device.
The nbr-router-id is the router ID of the neighbor router.
The packet-type can be one of the following:
The lsa-type is the type of LSA.
The lsa-id is the LSA ID.
The lsa-router-id is the LSA router ID.
- Message
- OSPF virtual intf state changed, rid router-id , area area-id , nbr ip-addr , state ospf-state
- Explanation
The state of an OSPF virtual routing interface has changed.
The router-id is the router ID of the router the interface is on.
The area-id is the area the interface is in.
The ip-addr is the IP address of the OSPF neighbor.
The ospf-state indicates the state to which the interface has changed and can be one of the following:
- Message
- OSPF virtual nbr state changed, rid router-id , nbr addr ip-addr , nbr rid nbr-router-id , state ospf-state
- Explanation
The state of an OSPF virtual neighbor has changed.
The router-id is the router ID of the RUCKUS device.
The ip-addr is the IP address of the neighbor.
The nbr-router-id is the router ID of the neighbor.
The ospf-state indicates the state to which the interface has changed and can be one of the following:
- Explanation
Threshold parameters for ICMP transit (through) traffic have been configured on an interface, and the maximum burst size for ICMP packets on the interface has been exceeded.
The portnum is the port number.
The first num is the maximum burst size (maximum number of packets allowed).
The second num is the number of seconds during which additional ICMP packets will be blocked on the interface.
Note: This message can occur in response to an attempted Smurf attack.
- Explanation
Threshold parameters for TCP transit (through) traffic have been configured on an interface, and the maximum burst size for TCP packets on the interface has been exceeded.
The portnum is the port number.
The first num is the maximum burst size (maximum number of packets allowed).
The second num is the number of seconds during which additional TCP packets will be blocked on the interface.
Note: This message can occur in response to an attempted TCP SYN attack.
- Message
- VRRP intf state changed, intf portnum , vrid virtual-router-id , state vrrp-state VRRP (IPv6) intf state changed, intf portnum , vrid virtual-router-id , state vrrp-state
- Explanation
A state change has occurred in a Virtual Router Redundancy Protocol (VRRP) or VRRP-E IPv4 or IPv6 interface.
The portnum is the port or interface where VRRP or VRRP-E is configured.
The virtual-router-id is the virtual router ID (VRID) configured on the interface.
The vrrp-state can be one of the following:
- Explanation
The RUCKUS device received a packet from another device on the network with an IP address that is also configured on the RUCKUS device.
The ip-addr is the duplicate IP address.
The mac-addr is the MAC address of the device with the duplicate IP address.
The portnum is the RUCKUS port that received the packet with the duplicate IP address. The address is the packet source IP address.
- Explanation
IGMP or MLD snooping has run out of hardware application VLANs. There are 4096 application VLANs per device. Traffic streams for snooping entries without an application VLAN are switched to the entire VLAN and to the CPU to be dropped. This message is rate-limited to appear a maximum of once every 10 minutes. The rate-limited number shows the number on non-printed warnings.
- Message
- list ACL-num denied ip-proto src-ip-addr ( src-tcp / udp-port ) (Ethernet portnum mac-addr ) - dst-ip-addr ( dst-tcp / udp-port ), 1 event(s)
- Explanation
Indicates that an Access Control List (ACL) denied (dropped) packets.
The ACL-num indicates the ACL number. Numbers 1 - 99 indicate standard ACLs. Numbers 100 - 199 indicate extended ACLs.
The ip-proto indicates the IP protocol of the denied packets.
The src-ip-addr is the source IP address of the denied packets.
The src-tcp / udp-port is the source TCP or UDP port, if applicable, of the denied packets.
The portnum indicates the port number on which the packet was denied.
The mac-addr indicates the source MAC address of the denied packets.
The dst-ip-addr indicates the destination IP address of the denied packets.
The dst-tcp / udp-port indicates the destination TCP or UDP port number, if applicable, of the denied packets.
- Explanation
A MAC address filtergroup configured on a port has denied packets.
The portnum is the port on which the packets were denied.
The mac-addr is the source MAC address of the denied packets.
The num variable indicates how many packets matching the values above were dropped during the five-minute interval represented by the log entry.
- Explanation
The ICX switch has received more than the allowed percentage of prefixes from the neighbor.
The ip-addr is the IP address of the neighbor.
The num is the number of prefixes that match the percentage you specified. For example, if you specified a threshold of 100 prefixes and 75 percent as the warning threshold, this message is generated if the ICX switch receives a 76th prefix from the neighbor.
- Explanation
A RIP route filter denied (dropped) packets.
The list-num is the ID of the filter list.
The direction indicates whether the filter was applied to incoming packets or outgoing packets. The value can be one of the following:
The V1 or V2 value specifies the RIP version (RIPv1 or RIPv2).
The ip-addr indicates the network number in the denied updates.
The num indicates how many packets matching the values above were dropped during the five-minute interval represented by the log entry.
- Message
ZTP: zero-touch-enable detects total <num of chains> chains (<num of units> units). unstable=<num of units>
- Explanation
Zero-touch-enable detects units.
The num of chains is the total number of detected chains
The num of units is the total number of detected units
The num of units is the total number of unstable units
- Message
- PoE Severe Error: Internal Device supplying power to port <number> is hot. "Distribute the load so that each of the 8 ports group (ports 1-8, 9-16 etc) have equal power consumption."
- Explanation
If high power consuming PDs are connected in consecutive ports and the ambient temperature is high, the device gets heated up.