Messages 500001 to 504002
This chapter includes messages from 500001 to 504002.
500001
Error Message %ASA-5-500001: ActiveX content in java script is modified: src src ip dest dest ip on interface interface name
Explanation Ensure the blocking of Java/ActiveX content present in Java script when the policy (filter Java (or) filter ActiveX) is enabled on the ASA.
Recommended Action None required.
500002
Error Message
%ASA-5-500002: Java content in java script is modified: src src ip dest dest ip on interface interface name
Explanation Ensure the blocking of Java/ActiveX content present in Java script when the policy (filter Java (or) filter ActiveX) is enabled on the ASA.
Recommended Action None required.
500003
Error Message %ASA-5-500003: Bad TCP hdr length (hdrlen=bytes , pktlen=bytes ) from source_address /source_port to dest_address /dest_port , flags: tcp_flags , on interface interface_name
Explanation A header length in TCP was incorrect. Some operating systems do not handle TCP resets (RSTs) correctly when responding to a connection request to a disabled socket. If a client tries to connect to an FTP server outside the ASA and the FTP server is not listening, then it sends an RST. Some operating systems send incorrect TCP header lengths, which causes this problem. UDP uses ICMP port unreachable messages.
The TCP header length may indicate that it is larger than the packet length, which results in a negative number of bytes being transferred. A negative number appears by a message as an unsigned number, which makes it appear much larger than it would be normally; for example, it may show 4 GB transferred in one second. This message should occur infrequently.
Recommended Action None required.
500004
Error Message %ASA-4-500004: Invalid transport field for protocol=protocol , from source_address /source_port to dest_address /dest_port
Explanation An invalid transport number was used, in which the source or destination port number for a protocol is zero. The protocol value is 6 for TCP and 17 for UDP.
Recommended Action If these messages persist, contact the administrator of the peer.
500005
Error Message
%ASA-3-500005: connection terminated for protocol from in_ifc_name :src_adddress /src_port to out_ifc_name :dest_address /dest_port due to invalid combination of inspections on same flow. Inspect inspect_name is not compatible with filter filter_name .
Explanation A connection matched with single or multiple inspection and/or single or multiple filter features that are not allowed to be applied to the same connection.
- protocol— The protocol that the connection was using
- in_ifc_name —The input interface name
- src_address —The source IP address of the connection
- src_port —The source port of the connection
- out_ifc_name —The output interface name
- dest_address —The destination IP address of the connection
- dest_port —The destination port of the packet
- inspect_name —The inspect or filter feature name
- filter_name —The filter feature name
Recommended Action Review the class-map, policy-map, service-policy, and/or filter command configurations that are causing the referenced inspection and/or filter features that are matched for the connection. The rules for inspection and filter feature combinations for a connection are as follows:
-
- The inspect http [http-policy-map] and/or filter url and/or filter java and/or filter activex commands are valid.
- The inspect ftp [ftp-policy-map] and/or filter ftp commands are valid.
- The filter https command with any other inspect command or filter command is not valid.
Besides these listed combinations, any other inspection and/or filter feature combinations are not valid.
501101
Error Message %ASA-5-501101: User transitioning priv level
Explanation The privilege level of a command was changed.
Recommended Action None required.
502101
Error Message %ASA-5-502101: New user added to local dbase: Uname: user Priv: privilege_level Encpass: string
Explanation A new username record was created, which included the username, privilege level, and encrypted password.
Recommended Action None required.
502102
Error Message %ASA-5-502102: User deleted from local dbase: Uname: user Priv: privilege_level Encpass: string
Explanation A username record was deleted, which included the username, privilege level, and encrypted password.
Recommended Action None required.
502103
Error Message
%ASA-5-502103: User priv level changed: Uname: user From: privilege_level To: privilege_level
Explanation The privilege level of a user changed.
Recommended Action None required.
502111
Error Message
%ASA-5-502111: New group policy added: name: policy_name Type: policy_type
Explanation A group policy was configured using the group-policy CLI command.
- policy_name—The name of the group policy
- policy_type—Either internal or external
Recommended Action None required.
502112
Error Message %ASA-5-502112: Group policy deleted: name: policy_name Type: policy_type
Explanation A group policy has been removed using the group-policy CLI command.
- policy_name—The name of the group policy
- policy_type—Either internal or external
Recommended Action None required.
503001
Error Message %ASA-5-503001: Process number, Nbr IP_address on interface_name from string to string , reason
Explanation An OSPFv2 neighbor has changed its state. The message describes the change and the reason for it. This message appears only if the log-adjacency-changes command is configured for the OSPF process.
Recommended Action Copy the message exactly as it appears, and report it to the Cisco TAC.
503002
Error Message
%ASA-5-503002: The last key has expired for interface nameif, packets sent using last valid key.
Explanation None of the security associations have a lifetime that include the current system time.
Recommended Action Configure a new security association or alter the lifetime of a current security association.
503003
Error Message
%ASA-5-503003: Packet sent | received on interface nameif with expired Key ID key-id.
Explanation The Key ID configured on the interface expired.
Recommended Action Configure a new key.
503004
Error Message
%ASA-5-503004: Key ID key-id in key chain key-chain-name does not have a key.
Explanation OSPF has been configured to use cryptographic authentication, however a key or password has not been configured.
Recommended Action Configure a new security association or alter the lifetime of a current security association.
503005
Error Message
%ASA-5-503005: Key ID key-id in key chain key-chain-name does not have a cryptographic algorithm.
Explanation OSPF has been configured to use cryptographic authentication, however an algorithm has not been configured.
Recommended Action Configure a cryptographic-algorithm for the security association.
503101
Error Message %ASA-5-503101: Process d , Nbr i on s from s to s , s
Explanation An OSPFv3 neighbor has changed its state. The message describes the change and the reason for it. This message appears only if the log-adjacency-changes command is configured for the OSPF process.
Recommended Action None required.
504001
Error Message %ASA-5-504001: Security context context_name was added to the system
Explanation A security context was successfully added to the ASA.
Recommended Action None required.
504002
Error Message
%ASA-5-504002: Security context context_name was removed from the system
Explanation A security context was successfully removed from the ASA.
Recommended Action None required.