sk109038 - Messages in /var/log/messages file that can be ignored
Messages in /var/log/messages file that can be ignored
This article consolidates all messages and warnings located in /var/log/messages files, that can be safely ignored.
FW-1: Warning: Interface <interface name> is defined but not currently present.
This is an informational message that not necessarily indicates a problem. When a Bond or Bridge interface is configured, this message may appear for the individual slave interfaces.
This is due to the way internal processes look at configuration data. If the ethX interface is part of a Bond or a Bridge, then these slave interfaces may appear to be "not present" when considered individually by internal processes.
[DATE TIME] firewall [LOG_WARNING] ipsrd[PID]: dvmrp_recv_prune: duplicate prune from <IP address 1> for (<IP address 2>, 192.168)/48, time remaining 900 seconds
This log indicates that the gateway has received a second DVMRP prune message from a downstream router before the previous prune message expired. The expiration timer is set by the downstream host in the initial DVMRP prune message. It is not expected that the downstream host would send more than one prune message.
If the downstream host tries to update the expiration timer for a particular pruned route, gateway will update the expiration timer with the information from the new message. Manipulation of the expiration timer, however, is not considered by the DVMRP standard to be a usual means by which multicast routing should be manipulated. Hence the gateway will issue this message if the time remaining on the expiration timer is significant.
If this message occurs frequently or otherwise become problematic, a network administrator should investigate why the downstream router is sending multiple prune messages for the same multicast group address.
Cluster:Failed to send packet on eth1c0: No buffer space available
This message does not signify lost packets, as the message may imply. It is simply a warning of an error state as packet data is passed between different portions of the Security gateway kernel code.
The following variables affected the generation of this message: - The greater the number of cluster members, the greater the likelihood of seeing the error - The greater the overall load on the units, the greater the likelihood of seeing the message - The weaker the hardware used in the cluster, the greater the likelihood of seeing the message - The greater the number of port connections on a per-destination IP address basis, the greater the likelihood of seeing the error
If the message is experienced continuously, consider upgrading your gateway to the most recent version or installing more powerful hardware.
[DATE TIME] cpmodule kernel: FW-1: Warning: The bond0 interface is not protected by the anti-spoofing feature
Policy install detects the root bond interface that is not configured with any IP address. It warns about it, although this interface is not participating in the network flow.
- /var/log/messages shows the following warnings from SNMPD daemon:
snmpd: snmpd startup succeeded snmpd[PID]: Turning on AgentX master support. snmpd[PID]: /etc/snmp/snmpd.conf: line X: Warning: Unknown token: cp_cleartrap. snmpd[PID]: /etc/snmp/snmpd.conf: line Y: Warning: Unknown token: cp_monitor. snmpd[PID]: /etc/snmp/snmpd.conf: line Z: Warning: Unknown token: cp_pcommunity. snmpd[PID]: NET-SNMP version 5...
The snmpd daemon does not recognize non-standard NET-SNMP configuration - in this case, it does not recognize the configuration of Check Point's daemon cpsnmpagentx (such as cp_pcommunity, cp_monitor, cp_cleartrap)
- /var/log/messages file shows:
routed[PID]: CLUSTER: Proto 7 enables sending in Clusterrouted[PID]: OspfClusterTransition(...): slave to slave event ignoring
These messages can be ignored.
- "Informatory: the current security gateway license allows for only N internal hosts"
This message is informatory only and is not indicative of the internal host limit being reached.
- "
gated[PID]: io_receive_packet: KRT recvmsg: No buffer space available" message on the cluster standby member during failover.
The message can be ignored.
- /var/log/messages file repeatedly shows messages similar to:
kernel: eth2.60: dev_set_promiscuity(master, -1)
When VRRP is enabled, the interface is put in promiscuous mode.
- Error messages related to ' fwloghandle_check_string' in /var/log/messages file:
fwloghandle_check_string: invalid char in string (ascii -127) fwloghandle_register_string_obfuscated: failed to obfuscate given string!
- _"
fwx_get_original_conn_key_ex: couldn't get conn key from chain" appears in /var/log/messages file
This is a legitimate and harmless message.
- "
fwconnoxid_msg_get_cliconn: warning - failed to get connoxid message" appears in kernel debug.
These messages can be ignored.
- /var/log/messages file repeatedly shows:
[ctipd][PID]: CIpRepCache::Save() - Saved to file /opt/CPsuite-R77/fw1/tmp/email_tmp/aspam_engine/ctipd.cache
- When routed syslog is enabled, the /var/log/messages file shows:
routed[PID]: routed_syslog_on: tracing to "/var/log/routed_messages" started
Message is printed in /var/log/messages:
xpand[pid]: error reading database requestNetflow logs appear in /var/log/messages, although netflow is not enabled.
Article Properties
Access Level: General Status: Approved Date Created: 2015-12-16 Last Modified: 2025-06-23