印刷

Appendix

Enterprise-Level Orchestrator Alerts and Events

This topic provides a summary of alerts and events generated within the Orchestrator at the Enterprise level. It provides details about all Enterprise-level Orchestrator events.

While the Orchestrator stores and displays these events on its UI, Edges, Gateways, or specific internal components (such as MGD, EDGED, or PROCMON) generate the majority of the data. Orchestrator serves as the sole platform for configuring event notifications and alerts.

The following table provides an explanation for each of the columns in the "Enterprise-level Orchestrator Events" table:
Table 1. Column Explanations
Column name Details
EVENT Unique name of the event
DISPLAYED ON ORCHESTRATOR UI AS Defines the event’s appearance within the Orchestrator.
SEVERITY Defines the typical severity level for the generated event.
GENERATED BY The VeloCloud SD-WAN component generating the notification can be one of the following:
  • Orchestrator
  • Edge (MGD)
  • Edge (EDGED)
  • Edge (PROCMON)
GENERATED WHEN Details the technical reasons and circumstances that trigger this event.
RELEASE ADDED IN Identifies the release that introduced the event. If not specified, this event existed before release 2.5.
DEPRECATED Identifies the specific release that deprecates the event.

 

Table 2. Enterprise-level Orchestrator Events
EVENT DISPLAYED ON ORCHESTRATOR UI AS SEVERITY GENERATED BY GENERATED WHEN RELEASE DEPRECATED
EDGE_UP Edge Up ALERT Orchestrator Edge comes back after losing connectivity with the Orchestrator through heartbeats. 2 consecutive heartbeats by an Edge causes the Orchestrator to change its status to EDGE_UP. The Orchestrator runs a monitor every 15 seconds that updates the status of all Edges.    
EDGE_DOWN Edge Down ALERT Orchestrator Edge loses connectivity with the Orchestrator and fails performing 2 or more consecutive heartbeats. The Orchestrator runs a monitor every 15 seconds that updates the status of all Edges.    
LINK_UP Link Up ALERT Orchestrator A WAN Link returns to a normal functioning state.    
LINK_DOWN Link Down ALERT Orchestrator A WAN Link drops its connection to the Edge or when the Link cannot communicate with the Edge service.    
VPN_TUNNEL_DOWN VPN Tunnel Down ALERT Orchestrator The IPsec tunnel between the Edge service and the VPN Gateway fails to establish or remains down after a disconnection.    
EDGE_HA_FAILOVER Edge HA Failover ALERT Orchestrator An HA Edge fails-over to its standby.    
EDGE_SERVICE_DOWN Edge Service Down ALERT Orchestrator The Edge service running on the Edge may be down. This may indicate Edge device failure or failure of network connectivity.    
EDGE_CSS_TUNNEL_UP Edge CSS Tunnel Up ALERT Orchestrator A Cloud Security Service tunnel from Edge is UP.    
EDGE_CSS_TUNNEL _DOWN Edge CSS Tunnel Down ALERT Orchestrator A Cloud Security Service tunnel from Edge is DOWN.    
NVS_FROM _EDGE_TUNNEL_DOWN NVS From Edge Tunnel Down ALERT Orchestrator An NSD via Edge tunnel is DOWN.    
NVS_FROM _EDGE_TUNNEL_UP NVS From Edge Tunnel Up ALERT Orchestrator An NSD via Edge tunnel is UP.    
VNF_VM_DEPLOYED VNF VM Deployed ALERT Orchestrator The Edge deploys an Edge VNF virtual machine.    
VNF_VM_ POWERED_ON VNF VM Powered ON ALERT Orchestrator The Edge deploys an Edge VNF virtual machine and powers it on.    
VNF_VM_ POWERED_OFF VNF VM Powered OFF ALERT Orchestrator The Edge powers off an Edge VNF virtual machine.    
VNF_VM_ DEPLOYED_AND _POWERED_OFF VNF VM Deployed and Powered OFF ALERT Orchestrator The Edge deploys an Edge VNF virtual machine and immediately powers it off.    
VNF_VM _DELETED VNF VM Deleted ALERT Orchestrator The Edge removes an Edge VNF virtual machine.    
VNF_VM _ERROR VNF VM error ALERT Orchestrator An error occurs during deployment of an Edge VNF virtual machine.    
VNF_INSERTION _ENABLED VNF insertion enabled ALERT Orchestrator The Edge enables the insertion of an Edge VNF virtual machine.    
VNF_INSERTION _DISABLED VNF insertion disabled ALERT Orchestrator The Edge disables the insertion of an Edge VNF virtual machine.    
VNF_IMAGE _DOWNLOAD_IN _PROGRESS VNF Image Download In Progress ALERT Orchestrator An Edge VNF virtual machine image download is in progress.    
VNF_IMAGE _DOWNLOAD _COMPLETED VNF Image Download Completed ALERT Orchestrator An Edge VNF virtual machine image download is complete.    
VNF_IMAGE _DOWNLOAD _FAILED VNF Image Download Failed ALERT Orchestrator The Edge failed to download an Edge VNF virtual machine image.    
EDGE_BFD _NEIGHBOR_UP BFD session established to Edge neighbor INFO Orchestrator The Edge neighbor establishes a BFD session.    
EDGE_BFD _NEIGHBOR_DOWN Edge BFD neighbor unavailable INFO Orchestrator The Edge neighbor cannot establish a BFD session.    
EDGE_BFDV6 _NEIGHBOR_UP BFDv6 session established to Edge neighbor INFO Orchestrator The Edge neighbor establishes a BFDv6 session. 4.5  
EDGE_BFDV6 _NEIGHBOR_DOWN Edge BFDv6 neighbor unavailable INFO Orchestrator The Edge neighbor cannot establish a BFDv6 session. 4.5  
EDGE_BGP _NEIGHBOR_UP BGP session established to Edge neighbor INFO Edge A BGP peer establishes tunnel with an Edge.    
EDGE_BGP _NEIGHBOR_DOWN Edge BGP neighbor unavailable INFO Edge The Edge's BGP peer loses tunnel with the Edge.    
EDGE_BGPV6 _NEIGHBOR_UP BGPv6 session established to Edge neighbor INFO Orchestrator The Edge neighbor establishes a BGPv6 session. 4.5  
EDGE_BGPV6 _NEIGHBOR_DOWN BGPv6 session established to Edge neighbor INFO Orchestrator The Edge neighbor cannot establish a BGPv6 session. 4.5  
GATEWAY _MIGRATION_CREATE Gateway Migration Created INFO Orchestrator The self-service migration is active. 4.5.0  
GATEWAY _MIGRATION_REMOVE Gateway Migration Removed INFO Orchestrator The self-service migration is not active. 4.5.0  
GATEWAY _MIGRATION_STATE _CHANGE Gateway Migration State Changed INFO Orchestrator The Gateway migration process transitions from one state to another. 4.5.0  
PKI_PROMOTION Endpoint PKI mode promoted INFO Orchestrator An Edge's PKI mode changes from optional to required.    
CERTIFICATE _REVOCATION Certificate revoked INFO Orchestrator Edge certificate revocation occurs intentionally or due to an expired certificate. (The latter rarely happens because Edge certificates automatically renew after 30 days into the 90 day period.)    
CERTIFICATE _RENEWAL Certificate renewal request INFO Orchestrator Edge certificate automatically renews after 30 days into the 90 day period.    
UPDATE_EDGE _IMAGE_MANAGEMENT Update Edge image management INFO Orchestrator Activates/deactivates management of Edge software images for a customer.    
SET_EDGE _SOFTWARE Updated Edge software image INFO Orchestrator An Operator Profile reassignment or a change in the software image triggers a new software image assignment for the Edge.    
UNSET_EDGE _SOFTWARE Unset overridden Edge software image INFO Orchestrator The Orchestrator clears the software image override for the Edge and applies the default image from the Operator Profile.    
ADD_OPERATOR _PROFILE Added operator profile INFO Orchestrator The Enterprise utilizes a new Operator Profile.    
REMOVE_OPERATOR _PROFILE Removed operator profile INFO Orchestrator The Enterprise removes an existing Operator Profile.    
ADD_SOFTWARE _IMAGE Added software image INFO Orchestrator A new software image now links to the Operator Profile for this Enterprise.    
MODIFY_ASSIGNED _OPERATOR _PROFILE_LIST Modified the assigned operator profile list INFO Orchestrator The Orchestrator updated the list of Operator Profiles associated with the Enterprise.    
MODIFY_ASSIGNED _SOFTWARE _IMAGE_LIST Modified the assigned software image list INFO Orchestrator The Orchestrator updated the list of software images associated with the Enterprise.    
CLOUD_SECURITY _ENABLE Cloud Security enabled INFO Orchestrator The Enterprise or Edge-specific Profile enables Cloud Security services.    
CLOUD_SECURITY _DISABLE Cloud Security disabled INFO Orchestrator The Enterprise Profile deactivates Cloud Security.    
CLOUD_SECURITY _PROVIDER _DELETED Cloud security provider deleted INFO Orchestrator The Orchestrator deletes the Cloud Security provider associated with an Enterprise's Profile.    
CLOUD_SECURITY _TUNNELING _ PROTOCOL_CHANGEACTOR_PORT_STATE_CHANGED Cloud Security Tunneling Protocol Change INFO Orchestrator Cloud Security tunneling protocol changes (from IPSEC to GRE or vice versa) in an Enterprise's Profile.    
CLOUD_SECURITY _PROVIDER_ADDED CLOUD_SECURITY_ PROVIDER_ADDED INFO Orchestrator The Orchestrator adds a Cloud Security provider associated with an Edge-specific Profile.    
CLOUD_SECURITY _PROVIDER_REMOVED CLOUD_SECURITY_ PROVIDER_REMOVED INFO Orchestrator The Orchestrator removes a Cloud Security provider associated with an Edge-specific Profile.    
CLOUD_SECURITY _OVERRIDE_ENABLED CLOUD_SECURITY_ OVERRIDE_ENABLED INFO Orchestrator The Orchestrator activates Cloud Security override in an Edge-specific Profile.    
CLOUD_SECURITY _OVERRIDE_DISABLED CLOUD_SECURITY_ OVERRIDE_DISABLED INFO Orchestrator The Orchestrator deactivates Cloud Security override in an Edge-specific Profile.    
CREATE_CLOUD _SERVICE_SITE Cloud Security Service site creation enqueued INFO Orchestrator An API automation job enters the queue to establish a Cloud Security Service tunnel for the Edge.    
UPDATE_CLOUD _SERVICE_SITE Cloud Security Service site update enqueued INFO Orchestrator An API automation job enters the queue to update a Cloud Security Service tunnel from the Edge.    
DELETE_CLOUD _SERVICE_SITE Cloud Security Service site deletion enqueued INFO Orchestrator An API automation job enters the queue to delete a Cloud Security Service tunnel from the Edge.    
ZSCALER_SUBLOCATION _ACTION_ENQUEUED Zscaler Sub Location Edge action enqueued INFO Orchestrator An API automation job enters the queue for Cloud Security Service Zscaler Sub Location.    
EDGE_NVS _TUNNEL_UP Edge Direct IPsec tunnel up INFO Orchestrator A Cloud Security Service tunnel or NSD via Edge tunnel is up.    
EDGE_NVS _TUNNEL_DOWN Edge Direct IPsec tunnel down INFO Orchestrator A Cloud Security Service tunnel or NSD via Edge tunnel is down.    
DIAGNOSTIC _REQUEST New diagnostic bundle request INFO Orchestrator An Enterprise or an Operator user requests a new Edge diagnostic bundle .    
EDGE_DIRECT _SITE_DELETED Edge direct site deleted INFO Orchestrator The user deletes an NSD via Edge tunnel.    
EDGE_DIRECT _TUNNELS_DISABLED Edge direct tunnels disabled INFO Orchestrator The user deactivates an NSD via Edge in Profile device settings.    
EDGE_DIRECT _TUNNELS_ENABLED Edge direct tunnels enabled INFO Orchestrator The user activates an NSD via Edge in Profile device settings.    
EDGE_DIRECT _TUNNEL_PROVIDER _DELETED Edge direct tunnel provider deleted INFO Orchestrator The user deletes an NSD via Edge provider associated with an Enterprise's Profile.    
CREATE_NVS _FROM_EDGE_SITE NSD via Edge site creation enqueued INFO Orchestrator An API automation job enters the queue to create an NSD via Edge tunnel.    
UPDATE_NVS _FROM_EDGE_SITE NSD via Edge site update enqueued INFO Orchestrator An API automation job enters the queue to update an NSD via Edge tunnel.    
DELETE_NVS _FROM_EDGE_SITE NSD via Edge site deletion enqueued INFO Orchestrator An API automation job enters the queue to delete an NSD via Edge tunnel.    
ENTERPRISE_ENABLE _VIEW_SENSITIVE _DATA View sensitive data privileges granted INFO Orchestrator An Enterprise grants privileges to its MSP or the Operator to view data (keys) information.    
ENTERPRISE_ENABLE _OPERATOR_USER _MGMT User management delegated to operator INFO Orchestrator An Enterprise successfully delegates access to the Operator to manager its users.    
ENTERPRISE_DISABLE _OPERATOR_ACCESS User management access revoked from operator INFO Orchestrator An Enterprise revokes the Operator's access to manage its entities.    
ENTERPRISE_ENABLE _OPERATOR_ACCESS Access delegated to operator INFO Orchestrator An Enterprise successfully delegates access to Operator to manage its entities.    
ENTERPRISE_ENABLE _PROXY_ACCESS Access revoked from operator INFO Orchestrator An Enterprise successfully delegates access to Partner to manage its entities.    
ENTERPRISE_DISABLE _PROXY_ACCESS Access delegated to partner INFO Orchestrator An Enterprise revokes Partner access to manage its entities.    
EDGE_TO_EDGE _VPN_DISABLE Edge to Edge VPN Disabled INFO Orchestrator The user deactivates the Edge to Edge VPN associated with an Edge device or its corresponding Profile.    
EDGE_TO_EDGE _VPN_ENABLE Edge to Edge VPN Enabled INFO Orchestrator The user activates the Edge to Edge VPN associated with an Edge device or its corresponding Profile.    
VPN_DISABLE Cloud VPN disabled INFO Orchestrator The user deactivates Cloud VPN settings associated with an Edge device or its corresponding Profile.    
VPN_ENABLE Cloud VPN enabled INFO Orchestrator The user activates Cloud VPN settings associated with an Edge device or its corresponding Profile.    
VPN_UPDATE Cloud VPN updated INFO Orchestrator The user updates Cloud VPN settings associated with an Edge device or its corresponding Profile.    
REMOTE_ACTION Edge remote action INFO Orchestrator The user performs a remote action on an online Edge.    
RECURRING _REPORT_ERROR Recurring report error ERROR Orchestrator Recurring report fails.    
CREATE_COMPOSITE _ROLE Composite Role Created INFO Orchestrator An Enterprise, Partner, or Operator create a composite role. 4.5  
UPDATE_COMPOSITE _ROLE Composite Role Updated INFO Orchestrator An Enterprise, Partner, or Operator update a composite role. 4.5  
DELETE_COMPOSITE _ROLE Composite Role Deleted INFO Orchestrator An Enterprise, Partner, or Operator delete a composite role. 4.5  
ENQUEUE_CREATE _ZSCALER _SUBLOCATION Zscaler Sub Location creation enqueued INFO Orchestrator The creation of the sub-location configuration for Edge device settings is in the queue. 4.5  
ENQUEUE_UPDATE _ZSCALER _SUBLOCATION Zscaler Sub Location update enqueued INFO Orchestrator The modification of the sub-location configuration for Edge device settings is in the queue. 4.5  
ENQUEUE_DELETE _ZSCALER _SUBLOCATION Zscaler Sub Location deletion enqueued INFO Orchestrator The deletion of the sub-location configuration for Edge device settings is in the queue. 4.5  
CREATE_ZSCALER _SUBLOCATION Zscaler Sub Location object created INFO Orchestrator A user creates a sub-location configuration for Edge device settings. 4.5  
UPDATE_ZSCALER _SUBLOCATION Zscaler Sub Location object updated INFO Orchestrator A user modifies a sub-location configuration for Edge device settings. 4.5  
DELETE_ZSCALER _SUBLOCATION Zscaler Sub Location object deleted INFO Orchestrator A user deletes a sub-location configuration for Edge device settings. 4.5  
ENQUEUE_UPDATE _ZSCALER_LOCATION Zscaler Location update enqueued INFO Orchestrator The modification of the location configuration for Edge device settings is in the queue. 4.5  
CREATE_ZSCALER _LOCATION Zscaler Location object created INFO Orchestrator A user creates a location configuration for Edge device settings. 4.5  
UPDATE_ZSCALER _LOCATION Zscaler Location object updated INFO Orchestrator A user modifies a sub-location configuration for Edge device settings. 4.5  
DELETE_ZSCALER _LOCATION Zscaler Location Object deleted INFO Orchestrator A user deletes a sub-location configuration for Edge device settings. 4.5  
GATEWAY_BGP _NEIGHBOR_UP BGP session established to Gateway neighbor INFO Gateway When a BGP peer establishes tunnel with a Gateway.    
GATEWAY_BGP _NEIGHBOR_DOWN Gateway BGP neighbor unavailable INFO Gateway When a Gateway's BGP peer loses tunnel with a Gateway.    
VRF_MAX_LIMIT _EXCEEDED VeloCloud SD-WAN Partner Gateway: Maximum rules in a route map limit hit for enterprise <enterprise-name> WARN _ING Gateway Maximum inbound route map configuration reaches its limit.    
VRF_ROUTEMAP _RULES_MAX _LIMIT_HIT VeloCloud SD-WAN Partner Gateway: Maximum rules in a route map limit hit for enterprise <enterprise-name> WARN _ING Gateway Maximum outbound route map configuration reaches its limit.    
VRF_LIMIT _EXCEEDED VeloCloud SD-WAN gateway: Maximum VRF limit(1000) reached ALERT Gateway Maximum VRF reaches its limit for Partner Gateway.    
GATEWAY_STARTUP VeloCloud SD-WAN gateway service started INFO Gateway Gateway daemon starts.    
ZSCALER _MONITOR_DISABLED Zscaler monitor disabled CRITI _CAL Edge/Gateway (PROCMON) Unable to launch L7 health check daemon for CSS tunnels on Edge/Gateway. This event can also occur when the Orchestrator disables this feature due to too many failures. 4.4  
ZSCALER _MONITOR_FAILED Zscaler monitor failed ERROR Edge/Gateway (PROCMON) When L7 health check daemon fails with a return code. 4.4  
MGD_EMERG _REBOOT Rebooting system to recover from stuck process(es): <process name> CRITI _CAL Edge/Gateway (PROCMON) Edge/Gateway reboots to recover from stuck processes using vc_procmon. 4.4  
EDGE_SERVICES _STARTED/GATEWAY _SERVICES_STARTED Edge/Gateway Services Started INFO Edge/Gateway (PROCMON) procmon starts all the services. 4.5  
EDGE_SERVICES _STOPPED/GATEWAY _SERVICES_STOPPED Edge/Gateway Services Stopped INFO Edge/Gateway (PROCMON) procmon stops all the services. 4.5  
EDGE_SERVICES _RESTARTED/GATEWAY _SERVICES_RESTARTED Edge/Gateway Services Restarted INFO Edge/Gateway (PROCMON procmon restarts all the services. 4.5  
EDGE_SERVICES_ TERMINATED/GATEWAY _SERVICES _TERMINATED Edge/Gateway Services terminated INFO Edge/Gateway (PROCMON) procmon terminates all the services. 4.5  
GATEWAY_SERVICE _DUMPED Service gwd stopped for diagnostic memory dump WARN _ING Gateway (PROCMON) gwd stops using SIGQUIT to generate core dump by user. 4.4  
GATEWAY_MGD _SERVICE_FAILED service mgd failed with error...., restarting ERROR Gateway (PROCMON) vc_procmon triggers this event on Gateway when MGD stops. 4.4  
GATEWAY_NAT _SERVICE_FAILED Service natd failed with error..., restarting ERROR Gateway (PROCMON) vc_procmon triggers this event on Gateway when nated daemon stops. 4.4  
EDGE_DNSMASQ _FAILED dnsmasq FAILED to start up ERROR Edge (PROCMON) dnsmasq daemon fails to start up. 4.4  
EDGE_SSH _LOGIN sshd accepted connection INFO Edge (PROCMON) A user accesses the Edge using an ssh login. 4.4  
EDGE_SERVICE _DUMPED Service edged stopped for diagnostic memory dump WARN _ING Edge (PROCMON) Edge stops using SIGQUIT to generate core dump by user. 4.4  
EDGE_LED_SERVICE _DISABLED Edge front-panel LED service disabled WARN _ING, CRITI _CAL Edge (PROCMON) The user deactivates the LED service.    
EDGE_LED_SERVICE _FAILED Edge front-panel LED service failed ERROR Edge (PROCMON) LED service fails.    
EDGE_MGD _SERVICE_DISABLED Management service disabled CRITI _CAL Edge (PROCMON) Management service is unable to activate for too many failures.    
EDGE_MGD _SERVICE_FAILED Management service failed ERROR Edge (PROCMON) Management service fails.    
EDGE_SERVICE _DISABLED Edge data plane service disabled WARN _ING/CRITI _CAL Edge (PROCMON) The user deactivates the Edge Data plane service.    
EDGE_SERVICE _ENABLED Edge data plane service enabled WARN _ING Edge (PROCMON) The user activates the Edge Data plane service from local UI.    
EDGE_SERVICE _FAILED Edge data plane service failed ERROR Edge (PROCMON) Edge Data plane service fails.    
EDGE_VNFD _SERVICE_DISABLED   WARN _ING Edge (PROCMON) The user deactivates the Edge VNFD service.    
EDGE_VNFD _SERVICE_FAILED   ERROR Edge (PROCMON) Edge VNFD service fails.    
EDGE_DOT1X _SERVICE_DISABLED Edge 802.1x service disabled WARN _ING, CRITI _CAL Edge (PROCMON) The user deactivates the Edge 802.1x service.    
EDGE_DOT1X _SERVICE_FAILED Edge 802.1x service failed ERROR Edge (PROCMON) Edge 802.1x service fails.    
EDGE_USB_PORTS _ENABLED/GATEWAY _USB_PORTS _ENABLED Edge/Gateway USB ports Enabled INFO Edge/Gateway (MGD) USB ports are active. 4.5  
EDGE_USB_PORTS _DISABLED/GATEWAY _USB_PORTS _DISABLED Edge/Gateway USB ports Disabled INFO Edge/Gateway (MGD) The user deactivates USB ports. 4.5  
EDGE_USB_PORTS _ENABLE_FAILURE/GATEWAY _USB_PORTS _ENABLE_FAILURE Edge/Gateway USB ports Enable Failure CRITI _CAL Edge/Gateway (MGD) procmon activates USB ports failure. 4.5  
EDGE_USB_PORTS _DISABLE_FAILURE/GATEWAY _USB_PORTS _DISABLE_FAILURE Edge/Gateway USB ports Disable Failure CRITI _CAL Edge/Gateway (MGD) procmon deactivates USB ports failure. 4.5  
VNF_VM_EVENT VNF VM Event INFO Edge (MGD) The user powers on, powers off, deletes, or deploys the VNF. Event detail helps distinguish the type.    
VNF_INSERTION _EVENT VNF insertion event ALERT Edge (MGD) The user activates or deactivates the VNF insertion. Event detail helps distinguish the type.    
VNF_IMAGE _DOWNLOAD_EVENT VNF image download event INFO Edge (MGD) VNF download is in progress, complete, or fails. Event detail helps distinguish the type.    
MGD_START Online INFO Edge (MGD) Management daemon on Edge starts.    
MGD_EXITING Shutting Down INFO Edge (MGD) Management service on an Edge is shutting down for a restart.    
MGD_SET _CERT_SUCCESS Set Certificate Successful INFO Edge (MGD) The user successfully installs a new PKI certificate for Orchestrator communication on an Edge.    
MGD_SET _CERT_FAIL Set Certificate Failed ERROR Edge (MGD) Installation of a new PKI certificate for Orchestrator communication on an Edge fails.    
MGD_CONF _APPLIED Configuration Applied INFO Edge (MGD) The Orchestrator pushed the configuration change to the Edge, which successfully applied the update.    
MGD_CONF _PENDING New configuration pending INFO Edge (MGD) New configuration is pending application. (This event is currently NOT generated anywhere.)    
MGD_CONF _ROLLBACK Bad configuration rolled back CRITI _CAL Edge (MGD) The Orchestrator automatically rolled back the configuration policy after the Edge became unstable.    
MGD_CONF _FAILED Failed to apply configuration ERROR Edge (MGD) Edge failed to apply a configuration change made on the Orchestrator.    
MGD_CONF _UPDATE_INVALID Invalid software update configuration WARN _ING Edge (MGD) The Orchestrator assigned the Edge an Operator Profile with an invalid software image that the Edge cannot use.    
MGD_DEVICE _CONFIG_WARNING   WARN _ING Edge (MGD) The Edge detects inconsistent device settings. MGD continues with warnings.    
MGD_DEVICE _CONFIG_ERROR   ERROR Edge (MGD) The Edge detects invalid device settings.    
MGD_SWUP _IGNORED_UPDATE Software update ignored INFO Edge (MGD) The Edge ignores the software update at the activation time, because Edge is already running that version.    
MGD_SWUP _INVALID_SWUPDATE Invalid software update WARN _ING Edge (MGD) Software update package received from the Orchestrator is invalid.    
MGD_SWUP _DOWNLOAD_FAILED Software download failed ERROR Edge (MGD) An Edge software update image download fails.    
MGD_SWUP _UNPACK_FAILED Software update unpack failed ERROR Edge (MGD) Edge has failed to unpack the downloaded software update package.    
MGD_SWUP _INSTALL_FAILED Software update install failed ERROR Edge (MGD) Edge software update installation fails.    
MGD_SWUP _INSTALLED Software update INFO Edge (MGD) The Edge successfully downloaded and installed the software update.    
MGD_SWUP _REBOOT Restart after software update INFO Edge (MGD) The Orchestrator reboots the Edge after a software update.    
MGD_SWUP _STANDBY _UPDATE_START Standby device software update started INFO Edge (MGD) The Active Edge sends an upgrade message to the Standby peer upon detecting a software version mismatch or receiving an upgrade command from the Orchestrator.    
MGD_SWUP _STANDBY _UPDATE_FAILED Standby device software update failed ERROR Edge (MGD) Active Edge reports Standby upgrade failure if it fails to send upgrade command to peer or Standby fails to upgrade for more than 5 minutes.    
MGD_SWUP _STANDBY_UPDATED Standby device software update completed INFO Edge (MGD) Active Edge detects Standby as it comes up with the expected image version.    
MGD_VCO _ADDR_RESOLV_FAILED Cannot resolve Orchestrator address WARN _ING Edge (MGD) DNS resolution of the Orchestrator address fails.    
MGD_DIAG _REBOOT User-initiated restart INFO Edge (MGD) A remote action from the Orchestrator reboots the Edge.    
MGD_DIAG _RESTART Services restarted INFO Edge (MGD) A remote action from the Orchestrator restarts the Data plane service on the Edge.    
MGD_SHUTDOWN Powered off INFO Edge (MGD) Edge diagnostic shutdown based on user request.    
MGD_HARD_RESET Reset to factory defaults INFO Edge (MGD) The Orchestrator restores the Edge to its factory-default software and configuration.    
MGD_DEACTIVATED Deactivated INFO Edge (MGD) The Orchestrator detects the Edge based on user request by mgd.    
MGD_NETWORK _SETTINGS_UPDATED Network settings updated INFO Edge (MGD) The Orchestrator applies the network settings to an Edge.    
MGD_NETWORK _MGMT_IF_BROKEN Management Network incorrectly set up ALERT Edge (MGD) The Orchestrator sets up the management network incorrectly.    
MGD_NETWORK _MGMT_IF_FIXED Network was restarted twice to fix Management Network inconsistency WARN _ING Edge (MGD) The Orchestrator restarts the network twice to fix the Management Network inconsistency.    
MGD_INVALID _VCO_ADDRESS Unable to heartbeat to new VCO %(newprimary)s, keep talking to old VCO %(oldprimary)s WARN _ING Edge (MGD) The Edge ignored the invalid Orchestrator address contained within the management plane policy update.    
MGD_ACTIVATION _PARTIAL Activation incomplete INFO Edge (MGD) The Edge completed partial activation, but a software update failed.    
MGD_REBOOT _DIAG_BUNDLE Generating diagnostic bundle before reboot INFO Edge (MGD) The Orchestrator generates the diagnostic bundle before reboot. 5.0  
MGD_ACTIVATION _SUCCESS Activated INFO Edge (MGD) The Orchestrator successfully activated the Edge.    
MGD_ACTIVATION _ERROR Activation failed ERROR Edge (MGD) Edge activation failed. Either the activation link was incorrect, or the Orchestrator failed to download the configuration to the Edge.    
MGD_HA_TERMINATED HA disabled on Edge INFO Edge (MGD) Standby Edge sends this event when the Orchestrator deactivates the HA.    
EDGE_INTERFACE _DOWN Edge Interface Down INFO Edge (MGD) hotplug scripts generate this event when the interface is down.    
EDGE_INTERFACE_UP Edge Interface Up INFO Edge (MGD) hotplug scripts generate this event when the interface is up.    
EDGE_KERNEL _PANIC   ALERT Edge (MGD) Edge operating system has encountered a critical exception and must reboot the Edge to recover. An Edge reboot is disruptive to customer traffic for 2-3 minutes while the Edge completes the reboot.    
MGD_MFRMUP _IGNORED_UPDATE Modem Firmware update ignored: <error message> ALERT Edge (MGD) The Edge ignores the modem firmware update. 5.0  
MGD_MFRMUP _INVALID _MFRMUPDATE Invalid Modem Firmware update applied: <error message> INFO Edge (MGD) The Edge applies an invalid modem firmware update. 5.0  
MGD_MFRMUP _INCOMPATIBLE _UPDATE In compatible Device or Factory Image: <error message> WARN _ING Edge (MGD) The device is incompatible for modem firmware update. 5.0  
MGD_MFRMUP _DOWNLOAD_FAILED Error downloading MFW ver <version> <build> WARN _ING Edge (MGD) Error occurs when downloading the modem firmware update version. 5.0  
MGD_MFRMUP _UNPACK_FAILED Error unpacking MFW ver <version> bu <build> ERROR Edge (MGD) The modem firmware update unpacking fails. 5.0  
MGD_MFRMUP _INSTALL_FAILED Error installing MFW ver <version> bu <build> ERROR Edge (MGD) The modem firmware update installation fails. 5.0  
MGD_MFRMUP _INSTALLED Installed downloaded MFW ver <version> bu <build> ERROR Edge (MGD) The Edge installs the modem firmware update version. 5.0  
MGD_MFRMUP _UPGRADE_PROGRESS MFW update in progress ver <version> bu <build> INFO Edge (MGD) The modem firmware upgrade is in progress. 5.0  
MGD_MFRMUP _REBOOT Edge is restarting into new MFW version <version> build <build> INFO Edge (MGD) The Edge restarts with new modem firmware update version. 5.0  
MGD_MFRMUP _STANDBY_UPDATE _START Begin HA Standby update with new MFW INFO Edge (MGD) The HA Standby update with new modem firmware version starts. 5.0  
MGD_MFRMUP _STANDBY_UPDATE _FAILED Failed HA Standby update with new MFW ERROR Edge (MGD) The HA Standby update with new modem firmware version fails. 5.0  
MGD_MFRMUP _STANDBY_UPDATED Succeeded HA Standby update with new MFW INFO Edge (MGD) The HA Standby update with new modem firmware version succeeds. 5.0  
EDGE_OSPF_NSM Edge OSPF NSM Event INFO Edge (EDGED) OSPF neighbor state changes.    
IP_SLA_PROBE IP SLA Probe INFO Edge (EDGED) IPSLA state changes.    
IP_SLA_RESPONDER IP SLA Responder ALERT, INFO Edge (EDGED) IPSLA responder state changes from up to down and vice versa.    
ALL_CSS_DOWN ALL_CSS_DOWN ALERT Edge (EDGED) All CSS paths go down.    
CSS_UP CSS_UP ALERT Edge (EDGED) At least one CSS path is up.    
LINK_MTU Link MTU detected INFO Edge (EDGED) The Edge detects a Link MTU. The Gateway detects the MTU for this WAN link and restricts all outgoing traffic to that specific MTU reading. For Release 3.2.x and earlier, VeloCloud software uses RFC 1191 Path MTU Discovery, which relies on receiving an ICMP error (fragmentation needed) from an upstream device to discover the MTU. Release 3.3.x and later enhances Path MTU Discovery by implementing Packet Layer Path MTU Discovery (RFC 4821).    
PORT_SCAN _DETECTED Port scan detected INFO Edge (EDGED) If Stateful firewall detects host scanning then this event will be logged along with the IP address and port number.    
PEER_UNUSABLE Peer unusable ALERT Edge (EDGED) Peer is unusable.   Deprecated
PEER_USABLE Peer usable INFO Edge (EDGED) Peer is usable.   Deprecated
BW_UNMEASURABLE Error measuring bandwidth ALERT Edge (EDGED) Bandwidth measurement failed on the Primary Gateway. Reattempt the measurement in 30 minutes. Reasons include a link experiencing a quality issue, such as excessive loss or latency. This message should only be seen on Edges running Release 3.1.x or lower, as the Orchestrator removed it beginning with Edge Release 3.2.0.    
SLOW_START_CAP_MET Bandwidth measured exceeds the slow start cap. Moving to burst mode. NOTICE Edge (EDGED) Bandwidth measurement Slow-start limit of 175 Mbps exceeded. The Edge will remeasure the link in Burst mode to ensure the correct measurement of a 175+ Mbps WAN link.    
EDGE_BFD_CONFIG   INFO Edge (EDGED) A user configures the BFD with incorrect local address.    
FLOOD_ATTACK _DETECTED   INFO Edge (EDGED) A malicious host floods the Edge with new connections.    
LINK_ALIVE Link alive INFO Edge (EDGED) Link state (link_fsm) becomes alive.    
LINK_DEAD Link dead ALERT Edge (EDGED) Link state (link_fsm) becomes dead.    
LINK_USABLE Link usable INFO Edge (EDGED) Link state (link_fsm) becomes usable.    
LINK_UNUSABLE Link unusable ALERT Edge (EDGED) Link state (link_fsm) becomes unusable.    
VPN_DATACENTER _STATUS VPN Tunnel state change INFO, ERROR Edge (EDGED) VPN Tunnel state changes.    
INTERFACE_CONFIG _ERROR Interface config error ALERT Edge (EDGED) Orchestrator detects an interface configuration error.    
HA_STANDBY _ACTIVATED HA Standby Activated INFO Edge (EDGED) Active Edge detects the Standby peer sending this event to Orchestrator to activate the Standby Edge.    
HA_INTF_STATE _CHANGED HA Interface State Changed ALERT Edge (EDGED) HA interface went down/up.    
HA_GOING_ACTIVE High Availability Going Active INFO Edge (EDGED) Standby Edge transition to Active Edge after detecting no heartbeat for more than 700 milliseconds.    
HA_FAILED High Availability Peer State Unknown INFO Edge (EDGED) Active Edge detects no heartbeat or activity from the Standby Edge for more than 700 milliseconds.    
HA_READY High Availability Ready INFO Edge (EDGED) Active Edge detects an activate Standby peer.    
VCO_IDENTIFIED _HA_FAILOVER Edge HA Failover Identified ALERT Orchestrator Orchestrator detects a High Availability failover on the Edge. 5.2  
VCO_IDENTIFIED _HA_FAILURE Edge HA Failure Identified ALERT Orchestrator Orchestrator detects that the Standby Edge has gone down. 5.2  
HA_UPDATE _FAILOVER_TIME Updating HA Failover time from ####ms to ####ms INFO Orchestrator User changed the failover time for when an HA Edge will failover due to a lack of heartbeat response. This time is measured in milliseconds (ms). 5.2  
HA_RESET _FAILOVER_TIME Failover time reset from ####ms to ####ms. INFO Edge (EDGED) When an HA Edge's system has been stable for 60 seconds, the process reduces the failover time by 50%. 5.2  
HA_WAN_LINK _ACTIVE <Edge-Name> <Active Serial Number> configured with <Standard, Enhanced, or Mixed-Mode> HA, with WAN <Link ID> is <Down or Up> ALERT Edge (EDGED) For all HA topologies (Standard, Enhanced, and Mixed-Mode) when the WAN interface goes Up or Down on the Active Edge. 5.2  
HA_WAN_LINK _STANDBY <Edge-Name> <Standby Serial Number> configured with <Standard, Enhanced, or Mixed-Mode> HA, with WAN <Link ID> is <Down or Up> ALERT Edge (EDGED) For all HA topologies (Standard, Enhanced, and Mixed-Mode) when the WAN interface goes Up or Down on the Standby Edge. 5.2  
HA_LAN_LINK _ACTIVE <Edge-Name> <Active Serial Number> configured with <Standard, Enhanced, or Mixed-Mode> HA, with WAN <Link ID> is <Down or Up> ALERT Edge (EDGED) For all HA topologies (Standard, Enhanced, and Mixed) when the LAN interface goes Up or Down on the Active Edge. 5.2  
HA_LAN_LINK _STANDBY <Edge-Name> <Standby Serial Number> configured with <Standard, Enhanced, or Mixed-Mode> HA, with LAN <Link ID> is <Down or Up> ALERT Edge (EDGED) For all HA topologies (Standard, Enhanced, and Mixed) when the LAN interface goes Up or Down on the Standby Edge. 5.2  
FW_UPGRADE _PENDING- CPLD CPLD Firmware being updated during software upgrade- edge may be offline for 3- 5 minutes. INFO Orchestrator The Orchestrator initiated and sent a firmware upgrade action to the Edge. 5.2  
FW_UPGRADE _SUCCESS
Note: A physical Edge reboot resolved the Edge's failure to respond after the PENDING message.
INFO Edge (EDGED) The Edge firmware upgrade was successful and required Edge reboots to complete. 5.2  
HA_SPLIT_BRAIN _DETECTED HA split-brain detected, peer will restart ALERT Orchestrator The Orchestrator has detected that both HA Edges are in an Active state. This is known as an Active-Active or Split Brain state. If other methods of preventing a Split-Brain state are not successful, the Orchestrator resolves this by triggering a restart of the Standby Edge (listed here as "peer") that is erroneously functioning as Active. 5.2  
HA_SPLITBRAIN _RESOLVED HA split-brain resolved, peer will move to standby state NOTICE Orchestrator After completing its restart, the Standby Edge (the 'peer') transitions from an Active state back to its assigned Standby role. This transition resolves the Active-Active or Split Brain state. 5.2  
MGD_UNREACHABLE Management Proxy unreachable EMER _GENCY Edge (EDGED) Data plane process cannot communicate to the management plane proxy.    
VRRP_INTO _MASTER_STATE VRRP HA updated to Primary state INFO Edge (EDGED) VRRP gets into Primary state.    
VRRP_OUT_OF _MASTER_STATE VRRP HA updated out of Primary state INFO Edge (EDGED) VRRP gets out of Primary state.    
VRRP_FAIL_INFO VRRP failed INFO Edge (EDGED) VRRP fails.    
EDGE_HEALTH _ALERT Edge Health Alert EMER _GENCY Edge (EDGED) Data plane is unable to allocate necessary resources for packet processing.    
EDGE_STARTUP Edge service startup INFO Edge (EDGED) Edge is running in mgmt-only mode.    
EDGE_DHCP _BAD_OPTION Invalid DHCP Option WARN _ING Edge (EDGED) The user configures the Edge with an invalid DHCP option.    
EDGE_NEW_USER New client user seen INFO Edge (EDGED) The Edge detects a new or updated client user on a given MAC address.    
EDGE_NEW_DEVICE New client device seen INFO Edge (EDGED) The Edge detects a new device during DHCP.    
INVALID_JSON   CRITI _CAL Edge (EDGED) The Edged receives invalid JSON data from the mgd.    
QOS_OVERRIDE QoS override INFO Edge (EDGED) Remote diagnostics is performed to flip cloud traffic to be routed according to business policy OR sent to the Gateway OR or bypass the Gateway.    
EDGE_L2_LOOP _DETECTED Edge L2 loop detected ERROR Edge (EDGED) The system detects an Edge L2 loop.    
EDGE_TUNNEL _CAP_WARNING Edge Tunnel CAP warning WARN _ING Edge (EDGED) An Edge reaches its maximum tunnel capacity.    
Interface LoS LoS no longer seen on interface <iface-name>/LoS detected on interface <iface-name> ALERT Edge (EDGED) Loss of Signal state changed on the interface in HA setup. 4.4  
EDGE_LOCALUI _LOGIN Edge Local UI Login INFO Edge LOCAL UI login is successful for a user.    
EDGE_MEMORY _USAGE_ERROR Memory Usage Critical ERROR Edge Resource Monitor process detects when the Edge memory utilization exceeds defined thresholds and reaches 70% threshold. The Resource Monitor waits for 90 seconds to allow the Edged process to recover from a possible temporary spike in memory usage. If memory usage persists at a 70% or higher level for more than 90 seconds, the Edge generates an error message and sends this event to the Orchestrator.    
EDGE_MEMORY _USAGE_WARNING Memory Usage Warning WARN _ING Edge Resource Monitor process detects Edge memory utilization is 50% or more than the available memory. This event will be sent to the Orchestrator every 60 minutes until the memory usage drops under the 50% threshold.    
EDGE_RESTARTING User-initiated Edge service restart WARN _ING Edge User initiates an Edge service restart.    
EDGE_REBOOTING User-initiated Edge reboot WARN _ING Edge User initiates an Edge reboot.    
EDGE_HARD_RESET User-initiated Edge hard reset WARN _ING Edge Edge hard reset.    
EDGE_DEACTIVATED Edge deactivated WARN _ING Edge Edge clears all its configuration and is not associated with a customer site. The software build remains unchanged.    
EDGE_CONSOLE_LOGIN Edge console login INFO Edge Edge login via console port.    
EDGE_COMMAND Edge Command INFO Edge The Edge generates this event during remote diagnostics when executing Edge commands.    
EDGE_BIOS_UPDATED Edge BIOS updated INFO Edge 12-upgrade-bios.sh script generates this event when Edge BIOS update is successful.    
EDGE_BIOS _UPDATE_FAILED Edge BIOS update failed ERROR Edge 12-upgrade-bios.sh script generates this event when Edge BIOS update fails.    
IPV6_ADDR_DELETED Deleted IPv6 address <v6addr> on interface/sub-interface <iface/subiface name> INFO Edge/Gateway The user deletes the IPv6 address on the interface or the sub-interface. 4.4  
IPV6_NEW _ADDR_ADDED Added new IPv6 address <v6-addr> on interface <ifacename> INFO Edge The user adds IPv6 address to the interface. 4.4  
IPV6_ADDR _DEPRECATED Deprecated IPv6 address <v6-addr> on interface <iface-name> INFO Edge The IPv6 address on the interface transitions to the Deprecated state. 4.4  
IPV6_ADDR _PREFERRED Preferred IPv6 address <v6-addr> on interface <iface-name> INFO Edge IPv6 address moves from Deprecated state to Preferred state. 4.4  
NDP_MAC_ADDR _CHANGE Neighbor MAC address change detected in interface <iface-name> INFO Edge The Edge detects IPv6 neighbor MAC address change. 4.4  
EDGE_INTF_CONFIG DAD Failed for IPv6 Address <v6-addr> in interface <iface-name> INFO Edge IPv6 NDP DAD fails. 4.4  
EDGE_SHUTTING _DOWN Edge is shutting down- must be restarted by power-cycling WARN _ING Edge (LUA Backend) Edge is shutting down. 4.4  
BIOS_PHY _RESET_CMOS_SET BIOS- Phy reset CMOS bit is set/BIOS- Phy reset CMOS bit cannot be set WARN _ING Edge CMOS (BIOS) is reset to its factory default settings. 4.4  
FW_UPGRADE _PENDING CPLD Firmware being updated during software upgrade- edge may go offline for 3-5 minutes WARN _ING Edge CPLD Firmware updates during software upgrade. 4.4  
EVDSL_IFACE _UP_EVENT Contains JSON string with evdsl Modem name, status, serial number INFO Edge EVDSL interface moves to Up state. 4.5  
EVDSL_IFACE _DOWN_EVENT contains JSON string with evdsl Modem name, status, serial number INFO Edge EVDSL interface moves to Down state. 4.5  
NAT_PORT _ASSIGN_FAIL NAT Ports exhausted from <src_ip> to <dst_ip>:<dport> WARN _ING Edge/Gateway NAT port allocation range reaches exhaustion. 4.5  
IPV6_MAX _DAD_FAILED IPv6 < link local / RA > stable secret address generation failed on interface <iface name> after multiple DAD failures ALERT Edge Users fail to generate stateless IPv6 address after multiple DAD failures. 4.5  
IPV6_ADDR _GEN_FAILED IPv6 <link local / RA> stable secret address generation failed on interface <iface name> after generating multiple invalid addresses ALERT Edge IPv6 stable secret address generation fails on the interface after generating multiple invalid addresses. 4.5  
INVALID_STATIC _ROUTE Rejected invalid routes <route-prefix>/0 flag <route flags in hex> ALERT Edge Invalid static route. 4.5  
INVALID_OSPF _ROUTE Rejected invalid routes <route-prefix>/0 flag <route flags in hex> ALERT Edge Invalid OSPF routes. 4.5  
INVALID_BGP _ROUTE Rejected invalid routes <route-prefix>/0 flag <route flags in hex> ALERT Edge Invalid BGP routes. 4.5  
INVALID_REMOTE _OSPF_ROUTE Rejected invalid routes <route-prefix>/0 flag <route flags in hex> ALERT Edge Invalid remote OSPF route. 4.5  
INVALID_REMOTE _BGP_ROUTE Rejected invalid routes <route-prefix>/0 flag <route flags in hex> ALERT Edge Invalid remote BGP route. 4.5  
INVALID_OVERLAY _ROUTE Rejected invalid routes <route-prefix>/0 flag <route flags in hex> ALERT Edge Invalid Overlay route. 4.5  
INVALID_ROUTE Rejected invalid routes <route-prefix>/0 flag <route flags in hex> ALERT Edge Invalid routes. 4.5  
EDGE_BFDv6_CONFIG Incorrect local address <IP address>. IP Address not present INFO Edge When the Edge receives invalid IPv6 BFD configuration. 4.5  
EDGE_USB _DEVICE_INSERTED Edge USB device inserted ALERT Edge The user inserts the USB device. 4.5  
EDGE_USB _DEVICE_REMOVED Edge USB device removed ALERT Edge The user removes the USB device. 4.5  
WIFI_CARD_DEAD Wificard <device name> at <port> is no longer usable, reboot required to recover EMER _GENCY Edge WiFi card at a port is no longer usable. 4.5  
DNS_CACHE _LIMIT_REACHED DNS Cache Max Limit (<cache limit of the edge>) Reached ALERT Edge DNS cache reaches its limit on the Edge. 4.5.1, 5.0  
PEER_MISMATCH PEER_MISMATCH ALERT Edge (EDGED) There is a peer name mismatch between MP_INIT_REQ and MP_INIT_ACK during Edge and Gateway tunnel creation. 5.1  
EDGE_CONGESTED Congestion alert due to either a high number of packet drops/scheduler drops WARN _ING Edge (EDGED)
  • The number of packet drops (xxxx) is above the congestion threshold (1000)
  • The number of scheduler drops (xxxx) is above the congestion threshold (1000)
Also occurs if there are either:
  • Continuous packet drops above a threshold of 1000 for more than 30 seconds due to over capacity.
  • Continuous packet drops above a threshold of 1000 for more than 30 seconds at the schedulers.
5.1  
EDGE_STABLE Congestion due to a high number of packet drops/scheduler drops subsided NOTICE Edge (EDGED)
  • The number of packet drops (xxx) is within the acceptable threshold (1000)
  • The number of scheduler drops (xxx) is within the acceptable threshold (1000)
Follow up to the EDGE_CONGESTED event indicates that the triggering criteria has subsided and the Edge is operating within acceptable parameters.
5.1  
MGD_ATPUP _INVALID_IDPS _SIGNATURE MGD_ATPUP _INVALID_IDPS _SIGNATURE ERROR Edge (MGD) There is an invalid Suricata package. 5.2  
MGD_ATPUP_DOWNLOAD _IDPS_SIGNATURE _FAILED MGD_ATPUP_DOWNLOAD _IDPS_SIGNATURE _FAILED ERROR Edge (MGD) Downloading of Suricata package fails. 5.2  
MGD_ATPUP_DECRYPT _IDPS_SIGNATURE _FAILED MGD_ATPUP_DECRYPT _IDPS_SIGNATURE _FAILED ERROR Edge (MGD) Unpacking of Suricata package fails. 5.2  
MGD_ATPUP_APPLY _IDPS_SIGNATURE_FAILED MGD_ATPUP_APPLY _IDPS_SIGNATURE _FAILED ERROR Edge (MGD) There is an error in applying Suricata files. 5.2  
MGD_ATPUP_APPLY _IDPS_SIGNATURE _SUCCEEDED MGD_ATPUP_APPLY_IDPS _SIGNATURE _SUCCEEDED INFO Edge (MGD) Suricata files successfully apply. 5.2  
MGD_ATPUP _STANDBY_UPDATE _START MGD_ATPUP _STANDBY_UPDATE _START INFO Edge (MGD) HA Standby update with new EFS IDPS Signature version starts. 5.2  
MGD_ATPUP _STANDBY_UPDATE _FAILED MGD_ATPUP _STANDBY_UPDATE _FAILED ERROR Edge (MGD) HA Standby update with new EFS IDP Signature version fails. 5.2  
MGD_ATPUP _STANDBY_UPDATED MGD_ATPUP _STANDBY_UPDATED INFO Edge (MGD) HA Standby update with new EFS IDPS Signature version successfully applies. 5.2  
HA_SET_PEER _KEYS_SUCCESSFUL HA_SET_PEER _KEYS_SUCCESSFUL NOTICE Edge (MGD) An Edge deployed in a cluster confirms that it has successfully saved the HA Peer keys for that cluster. 5.4  
EFS_IDPS_NOT _READY EFS_IDPS_NOT _READY ALERT Edge (MGD) The Edge drops the packets while on-prem Orchestrator does not connect to the GSM and so IDPS signatures are not ready. 6.0  
EFS_IP_DB _VERSION_UPDATE EFS_IP_DB _VERSION_UPDATE INFO Edge (MGD) Loading of IP database succeeds or fails. 6.0  
EFS_IP_RTU _DB_VERSION_UPDATE EFS_IP_RTU_DB _VERSION_UPDATE INFO Edge (MGD) Loading of IP RTU database succeeds or fails. 6.0  
EFS_URL_DB _VERSION_UPDATE EFS_URL_DB_ VERSION_UPDATE INFO Edge (MGD) Loading of URL database succeeds or fails. 6.0  
EFS_URLF_MAL _IP_NOT_READY EFS_URLF_MAL_ IP_NOT_READY ALERT Edge (MGD) The Edge drops the packets while activating EFS, but URLF/MAL-IP filtering is not ready. 6.0  
EFS_URL_RTU _DB_VERSION_UPDATE EFS_URL_RTU_DB _VERSION_UPDATE INFO Edge (MGD) Loading of URL RTU database succeeds or fails. 6.0  
MGD_EFS_NTICS _REGISTRATION _SUCCEEDED MGD_EFS_NTICS _REGISTRATION _SUCCEEDED INFO Edge (MGD) NTICS registration with Client ID succeeds. 6.0  
MGD_EFS_NTICS _REGISTRATION _FAILED MGD_EFS_NTICS _REGISTRATION _FAILED ERROR Edge (MGD) NTICS registration fails with retry count. 6.0  
MGD_EFS_NTICS _AUTHENTICATION _SUCCEEDED MGD_EFS_NTICS _AUTHENTICATION _SUCCEEDED INFO Edge (MGD) NTICS authentication succeeds. 6.0  
MGD_EFS_NTICS _AUTHENTICATION _FAILED MGD_EFS_NTICS _AUTHENTICATION _FAILED ERROR Edge (MGD) NTICS authentication fails. 6.0  
ACTOR_PORT_STATE_CHANGED ACTOR_PORT_STATE_CHANGED NOTICE Orchestrator The LACP state of a member port of the bond changes. Disconnecting the link between the member ports on both devices also triggers this event. 6.4  
PARTNER_PORT_STATE_CHANGED PARTNER_PORT_STATE_CHANGED NOTICE Orchestrator The LACP state of a member port of the bond changes. Disconnecting the link between the member ports on both devices also triggers this event. 6.4  
EDGE_PHYSICAL_LINK_DOWN Edge Physical Link Down INFO Orchestrator Removing the physical cable from the Edge triggers this event. The event EDGE_INTERFACE_DOWN follows the event EDGE_PHYSICAL_LINK_DOWN because there is a netifd change.    
EDGE_PHYSICAL_LINK_UP Edge Physical Link Up INFO Orchestrator Attaching the physical cable to the Edge triggers this event.    

Supported Events for Syslogs

The following table describes every VeloCloud Edge Event available for export to Syslog collectors.
Table 3. Supported Events for Syslogs
Events Severity Description
BW_UNMEASURABLE ALERT Occurs when the path bandwidth is unmeasurable.
BGP_NEIGHBOUR_UP INFO Occurs when the BGP Neighbor is up. The following is the sample syslog message for this event:
2024-05-27T14:30:50.990 INFO   local0 HUB1.segment1: BGP_NEIGHBOUR_UP: segment:Global Segment peer addr:x.x.x.x
The message has the following parts:
  • Date - 2024-05-27
  • Time - 14:30:50.990
  • Syslog Severity Level - INFO
  • Facility Code - Local0
  • Syslog Tag - HUB1.segment1
  • Message - BGP_NEIGHBOUR_UP
  • Segment name - Global Segment
  • Peer IP Address - x.x.x.x
BGP_NEIGHBOUR_DOWN ALERT Occurs when the BGP Neighbor is down. The following is the sample syslog message for this event:
2024-05-27T14:30:50.990 ALERT  local0 HUB1.segment1: BGP_NEIGHBOUR_DOWN: segment:Global Segment peer addr:x.x.x.x
The message has the following parts:
  • Date - 2024-05-27
  • Time - 14:30:50.990
  • Syslog Severity Level - ALERT
  • Facility Code - Local0
  • Syslog Tag - HUB1.segment1
  • Message - BGP_NEIGHBOUR_DOWN
  • Segment name - Global Segment
  • Peer IP Address - x.x.x.x
EDGE_BIOS_UPDATE_FAILED ERROR Occurs when the Edge BIOS update fails.
EDGE_BIOS_UPDATED INFO A 12-upgrade-bios.sh script generates this event when Edge BIOS updates.
EDGE_CONSOLE_LOGIN INFO Occurs during login via console port.
EDGE_DEACTIVATED WARNING Occurs when an Edge clears all its configuration and disassociates from a customer site. The software build stays the same.
EDGE_DHCP_BAD_OPTION WARNING Occurs when the user configures the Edge with an invalid DHCP option.
EDGE_DISK_IO_ERROR WARNING Occurs when a Disk I/O error interrupts an upgrade or downgrade.
EDGE_DISK_READONLY CRITICAL Occurs when a Disk turns to read-only mode.
EDGE_DNSMASQ_FAILED ERROR Occurs when Dnsmasq service fails.
EDGE_DOT1X_SERVICE_DISABLED WARNING, CRITICAL vc_procmon generates this event when the Edge 802.1x service is shut down.
EDGE_DOT1X_SERVICE_FAILED ERROR vc_procmon generates this event when the Edge 802.1x service fails.
EDGE_HARD_RESET WARNING Occurs when user initiates an Edge hard reset.
EDGE_HEALTH_ALERT EMERGENCY Occurs when the data plane is unable to allocate necessary resources for packet processing.
EDGE_INTERFACE_DOWN INFO hotplug scripts generate this event when the interface is down.
EDGE_INTERFACE_UP INFO hotplug scripts generate this event when the interface is up.
EDGE_KERNEL_PANIC ALERT Occurs when the Edge operating system encounters a critical exception and must reboot the Edge to recover. An Edge reboot is disruptive to customer traffic for 2-3 minutes while the Edge completes the reboot.
EDGE_L2_LOOP_DETECTED ERROR Occurs when the Orchestrator detects an Edge L2 loop.
EDGE_LED_SERVICE_DISABLED WARNING, CRITICAL vc_procmon generates this event when the Edge LED service shuts down.
EDGE_LED_SERVICE_FAILED ERROR vc_procmon generates this event when the Edge LED service fails.
EDGE_LOCALUI_LOGIN INFO Occurs when LOCAL UI login is successful for a user.
EDGE_MEMORY_USAGE_ERROR ERROR Occurs when the Resource Monitor process detects that Edge memory utilization has exceeded the defined thresholds and reached the 70% threshold. The Resource Monitor waits for 90 seconds to allow the edged process to recover from a possible temporary spike in memory usage. If memory usage remains at 70% or higher for more than 90 seconds, the Edge generates this error message and sends the event to the Orchestrator.
EDGE_MEMORY_USAGE_WARNING WARNING Occurs when the Resource Monitor process detects that Edge memory utilization is 50% or more of the available memory. This event is sent to the Orchestrator every 60 minutes until the memory usage drops under the 50% threshold.
EDGE_MGD_SERVICE_DISABLED CRITICAL, WARNING vc_procmon generates this event when the mgd fails to start or shuts down after too many failures.
EDGE_MGD_SERVICE_FAILED ERROR vc_procmon generates this event when the mgd service fails.
EDGE_NEW_DEVICE INFO Occurs when the Edge identifies a new DHCP client by processing the DHCP request.
EDGE_NEW_USER INFO Occurs when the Edge adds a new client user.
EDGE_OSPF_NSM INFO Occurs when the OSPF Neighbor state Machine (NSM) state occurs.
EDGE_REBOOTING WARNING Occurs when a user initiates Edge reboot.
EDGE_RESTARTING WARNING Occurs when a user initiates Edge service restart.
EDGE_SERVICE_DISABLED WARNING Occurs when the Edge deactivates the data plane service.
EDGE_SERVICE_ENABLED WARNING Occurs when the Edge activates the data plane service.
EDGE_SERVICE_FAILED ERROR Occurs when the Edge data plane service fails.
EDGE_SHUTTING_DOWN WARNING Occurs when an Edge shuts down.
EDGE_STARTUP INFO Occurs when an Edge runs in mgmt-only mode.
EDGE_SSH_LOGI INFO Occurs during login via SSH protocol.
EDGE_TUNNEL_CAP_WARNING WARNING Occurs when an Edge reaches its maximum tunnel capacity.
EDGE_USB_PORTS_ENABLED INFO Occurs when the Edge enables the USB ports.
EDGE_USB_PORTS_DISABLED INFO Occurs when the Edge deactivates the USB ports.
EDGE_USB_PORTS_ENABLE_FAILURE CRITICAL Occurs when the enable operation for its USB ports fails.
EDGE_USB_PORTS_DISABLE_FAILURE CRITICAL Occurs when the deactivate operation for its USB ports fails.
EDGE_USB_DEVICE_REMOVED ALERT Occurs when a user removes a device from its USB port.
EDGE_USB_DEVICE_INSERTED ALERT Occurs when a user inserts a device into its USB port.
EDGE_VNFD_SERVICE_DISABLED WARNING, CRITICAL vc_procmon generates this event when the Orchestrator deactivates Edge VNFD service.
EDGE_VNFD_SERVICE_FAILED ERROR vc_procmon generates this event when the Edge VNFD service fails.
FLOOD_ATTACK_DETECTED INFO Occurs when a malicious host floods the Edge with new connections.
GATEWAY_SERVICE_STATE_UPDATED   Occurs when the Operator changes the Service State of a Gateway.
HA_FAILED INFO HA Peer State Unknown - Occurs when the Standby Edge has not sent a heartbeat response, and only one of the two HA Edges is communicating with the Orchestrator and Gateways.
HA_GOING_ACTIVE INFO HA failover - Occurs when the Standby Edge takes over as Active after the Orchestrator identifies the primary Edge as down.
HA_INTF_STATE_CHANGED ALERT Occurs when the HA Interface state changes to Active.
HA_READY INFO Occurs when both the Active and Standby Edges start up and synchronize.
HA_STANDBY_ACTIVATED INFO Occurs after the HA Standby Edge accepts the activation key, downloads its configuration, and updates its software build.
HA_TERMINATED INFO Occurs when an Edge deactivates the HA.
INVALID_JSON CRITICAL Occurs when an Edge receives an invalid response from mgd.
IP_SLA_PROBE Up = INFO, Down = ALERT Occurs when an IP ICMP Probe state changes.
IP_SLA_RESPONDER Up = INFO, Down = ALERT Occurs when an IP ICMP Responder state changes.
LINK_ALIVE INFO Occurs when a WAN link is no longer DEAD.
LINK_DEAD ALERT Occurs when all tunnels on the WAN link fail to receive packets for at least seven seconds.
LINK_MTU INFO Occurs when the Edge discovers the WAN link MTU.
LINK_UNUSABLE ALERT Occurs when WAN link transitions to UNUSABLE state.
LINK_USABLE INFO Occurs when WAN link transitions to USABLE state.
MGD_ACTIVATION_ERROR ERROR Occurs when an Edge activation fails, typically due to an incorrect activation link or an unsuccessful download of the configuration to the Edge.
MGD_ACTIVATION_PARTIAL INFO Occurs when an Edge activates partially but fails a required software update.
MGD_ACTIVATION_SUCCESS INFO Occurs when the Edge completes its activation process successfully.
MGD_CONF_APPLIED INFO Occurs when the Edge successfully applies a configuration change pushed from the Orchestrator.
MGD_CONF_FAILED INFO Occurs when the Edge fails to apply a configuration change made on the Orchestrator.
MGD_CONF_ROLLBACK INFO Occurs when the Edge reverts to a previous configuration because an Orchestrator policy update caused instability.
MGD_CONF_UPDATE_INVALID INFO Occurs when the Orchestrator assigns an Operator Profile with an incompatible software image to an Edge.
MGD_DEACTIVATED INFO Occurs when mgd processes an Edge deactivation request from a user.
MGD_DEVICE_CONFIG_WARNING/ERROR WARNING, INFO Occurs when the Edge detects an inconsistent/invalid device setting.
MGD_DIAG_REBOOT INFO Occurs when the Edge reboots following a Remote Action request from the Orchestrator.
MGD_DIAG_RESTART INFO Occurs when the data plane service restarts following a Remote Action from the Orchestrator.
MGD_EMERG_REBOOT CRITICAL Occurs when vc_procmon detects stuck processes and restarts the Edge for recovery.
MGD_ENTER_LIVE_MODE DEBUG Occurs when the management service on an Edge is entering the LIVE mode.
MGD_EXIT_LIVE_MODE DEBUG Occurs when the management service on an Edge is exiting the LIVE mode.
MGD_EXITING INFO Occurs when the management service on an Edge is shutting down for a restart.
MGD_EXTEND_LIVE_MODE DEBUG Occurs when the system extends Live mode.
MGD_FLOW_STATS_PUSH_FAILED DEBUG Occurs when Flow stats transmission to the Orchestrator fails.
MGD_FLOW_STATS_PUSH_SUCCEEDED DEBUG Occurs when Flow stats transmission to the Orchestrator is successful.
MGD_FLOW_STATS_QUEUED INFO Occurs when the Edge queues Flow stats for transmission to the Orchestrator.
MGD_HARD_RESET INFO Occurs when an Edge restores to its factory-default software and configuration.
MGD_HEALTH_STATS_PUSH_FAILED DEBUG Occurs when Health stats transmission to the Orchestrator fails.
MGD_HEALTH_STATS_PUSH_SUCCEEDED DEBUG Occurs when Health stats transmission to the Orchestrator is successful.
MGD_HEALTH_STATS_QUEUED INFO Occurs when the Edge queues health statistics for transmission to the Orchestrator.
MGD_HEARTBEAT INFO Occurs whenever the Edge transmits a heartbeat to the Orchestrator.
MGD_HEARTBEAT_FAILURE INFO Occurs when generated Heartbeat to the Orchestrator fails.
MGD_HEARTBEAT_SUCCESS INFO Occurs when generated Heartbeat to the Orchestrator is successful.
MGD_INVALID_VCO_ADDRESS WARNING Occurs when the Edge ignores a management plane policy update containing an invalid Orchestrator address.
MGD_LINK_STATS_PUSH_FAILED DEBUG Occurs when Link stats transmission to the Orchestrator fails.
MGD_LINK_STATS_PUSH_SUCCEEDED DEBUG Occurs after successfully pushing link statistics to the Orchestrator.
MGD_LINK_STATS_QUEUED INFO Occurs when the Edge queues link statistics for transmission to the Orchestrator.
MGD_LIVE_ACTION_FAILED DEBUG Occurs when Live Action fails.
MGD_LIVE_ACTION_REQUEST DEBUG Occurs upon receiving a request for a Live Action.
MGD_LIVE_ACTION_SUCCEEDED DEBUG Occurs when Live Action is successful.
MGD_NETWORK_MGMT_IF_BROKEN ALERT Occurs due to an incorrect Management network.
MGD_NETWORK_MGMT_IF_FIXED WARNING Occurs when a Network restarts twice to resolve the Management Network inconsistency.
MGD_NETWORK_SETTINGS_UPDATED INFO Occurs when the Orchestrator applies new network settings to an Edge.
MGD_SET_CERT_FAIL ERROR Occurs when the installation of a new PKI certificate for Orchestrator communication on an Edge fails.
MGD_SET_CERT_SUCCESS INFO Occurs after successfully installing a new PKI certificate for Orchestrator communication on an Edge.
MGD_SHUTDOWN INFO Occurs when the Edge initiates a diagnostic shutdown per user request.
MGD_START INFO Occurs when the management daemon on the Edge starts.
MGD_SWUP_DOWNLOAD_FAILED ERROR Occurs when the download of an Edge software update image fails.
MGD_SWUP_DOWNLOAD_SUCCEEDED DEBUG Occurs when the download of an Edge software update image is successful.
MGD_SWUP_IGNORED_UPDATE INFO Occurs when the Edge ignores a software update because it already runs that version.
MGD_SWUP_INSTALL_FAILED ERROR Occurs when a software update installation fails.
MGD_SWUP_INSTALLED INFO Occurs when a user successfully downloads and installs a software update.
MGD_SWUP_INVALID_SWUPDATE WARNING Occurs when a software update package received from the Orchestrator is invalid.
MGD_SWUP_REBOOT INFO Occurs when the Edge reboots following a software update.
MGD_SWUP_STANDBY_UPDATE_FAILED ERROR Occurs when a software update of the standby HA Edge fails.
MGD_SWUP_STANDBY_UPDATE_START INFO Occurs when the HA standby software update starts.
MGD_SWUP_STANDBY_UPDATED INFO Occurs when a software update of the standby HA Edge starts.
MGD_SWUP_UNPACK_FAILED ERROR Occurs when an Edge fails to unpack the downloaded software update package.
MGD_SWUP_UNPACK_SUCCEEDED INFO Occurs when an Edge succeeds to unpack the downloaded software update package.
MGD_UNREACHABLE EMERGENCY Occurs when the data plane process cannot communicate to the management plane proxy.
MGD_VCO_ADDR_RESOLV_FAILED WARNING Occurs when the DNS resolution of the Orchestrator address fails.
MGD_WEBSOCKET_INIT DEBUG Occurs when a WebSocket communication initiates with the Orchestrator.
MGD_WEBSOCKET_CLOSE DEBUG Occurs when a WebSocket communication with the Orchestrator closes.
NSD_MIGRATION_TASKS_QUEUED   Occurs when the Enterprise customers have pending migration tasks for the Gateways that are attached to Non SD-WAN Destinations.
PEER_UNUSABLE ALERT Occurs when overlay connectivity to a peer goes down while transmitting peer stats.
PEER_USABLE INFO Occurs when overlay connectivity to a peer resumes after a period of unusability.
PORT_SCAN_DETECTED INFO Occurs upon detecting a port scan.
QOS_OVERRIDE INFO Occurs to flip traffic path (gateway or direct).
REBALANCE_EDGE_SUCCEEDED   Occurs when the Enterprise customers have successfully rebalanced the required Edges from the quiesced Gateway to the new Gateway.
SLOW_START_CAP_MET NOTICE Occurs when the bandwidth measurement exceeds the slow-start cap limit, forcing a switch to Burst mode.
SWITCH_GATEWAY_COMPLETED   Occurs when the Enterprise customers have successfully switched the traffic from the quiesced Gateways to new Gateways for Non SD-WAN Destinations.
SWITCH_GATEWAY_FAILED   Occurs when the Switch Gateway action for a Non SD-WAN Destination fails during the Gateway migration.
VPN_DATACENTER_STATUS INFO, ERROR Occurs when a VPN Tunnel state changes.
VRRP_FAIL_INFO INFO Occurs when VRRP fails.
VRRP_INTO_MASTER_STATE INFO Occurs when VRRP gets into the Primary state.
VRRP_OUT_OF_MASTER_STATE INFO Occurs when VRRP exits the Primary state.

Arista VeloCloud SD-WAN Edge Configuration Changes that Trigger an Edge Service Restart

This topic covers the VeloCloud SD-WAN™ configuration changes that can cause an Edge dataplane service restart, also known as the Edged process. Edged is one of many services that run on an Edge, and this service handles dataplane tasks, i.e., managing customer traffic. A restart of the Edged service is not the same as a full Edge hardware reboot. Restarting this software process causes a brief interruption in service and customer traffic disruption until the dataplane service resumes. The Orchestrator UI generates the following configuration changes.

Note: For Edges in a High Availability topology, the Edge service restart triggers an HA failover.

Device Settings

The Orchestrator enables the Device Settings changes for either an Edge or a Profile. The Orchestrator generates these changes via the following path:

Enterprise > SD-WAN > Configure > Edge or Profile > Device .

Note: If a Profile configuration changes and an Edge using that Profile already has a configured Edge Override for the Device setting, the Edge is not affected by the Profile level configuration change.
Table 4. Device Settings
Edge Software Version 4.2.x 4.3.x 4.5.x 5.0.x 5.1.x 5.2.x 5.4.x 6.0.x
Configuration Change Type Service

Restart?

Service

Restart?

Service

Restart?

Service

Restart?

Service

Restart?

Service

Restart?

Service

Restart?

Service

Restart?

Any BGP Configuration Change IPv4 No No No No No No No No
Any OSPFv2 or OSPFv3 configuration Change No No No No No No No No
Any Static Route Configuration Change No No No No No No No No
Any Multicast Configuration Change No No No No No No No No
Authentication Settings in Global Segment Yes Yes Yes Yes No No No No
DNS Settings No No No No No No No No
NetFlow Enable/Disable/Port Change in Global Segment No No No No No No No No
NetFlow Collector IP Change No No No No No No No No
ICMP Probes/Responder No No No No No No No No
VRRP Settings No No No No No No No No
Cloud Security Service No No No No No No No No
Gateway Handoff Assignment No No No No No No No No
Configure VLAN No No No No No No No No
Interface Enable/Disable Yes Yes Yes Yes Yes Yes Yes Yes
Change the High Availability Interface N/A N/A N/A N/A N/A Yes Yes Yes
Activate High Availability with a Non-GE1 Interface N/A N/A N/A N/A N/A Yes Yes Yes
Activate GRE/BGP Support on a LAN Interface N/A N/A N/A N/A N/A No No No
DHCPv6 Relay N/A N/A N/A N/A N/A No No No
Activate Loss of Signal (LoS) for an Interface N/A No No No No No No No
Route Summarization N/A N/A N/A N/A N/A No No No
Management IP ChangeMGT IP is deprecated from 4.3.x and later Yes N/A N/A N/A N/A N/A N/A N/A
Multi-Source QoS No No No No No No No No
SNMP Settings No No No No No No No No
NTP Servers No No No No No No No No
Visibility Mode No No No No No No No No
WAN Settings Changes No No No No No No No No
Enable/Disable WAN Overlay on an Enabled Interface No No No No No No No No
Renaming an Overlay for a GE Interface No No No No No No No No
Renaming an Overlay for a USB Interface Yes Yes Yes Yes Yes Yes Yes Yes
Wi-Fi Radio Settings at the Profile Level No No No No No No No No
Wi-Fi Radio Settings at the Edge Level Yes Yes Yes Yes Yes Yes Yes Yes
Advertise Enable/Disable on a GE Interface No No No No No No No No
High Availability Type Change Yes Yes Yes Yes Yes Yes Yes Yes
Change the IP Address, Mask or Default Gateway on an Enabled Interface Yes Yes Yes Yes Yes Yes Yes Yes
Add/Remove/Modify a Subinterface Yes Yes Yes Yes Yes Yes Yes Yes
Add/Remove/Modify a Secondary IP Address No No No No No No No No
Add/Remove/Modify VLAN on a GE Interface Yes Yes Yes Yes Yes Yes Yes Yes
Change the Interface Mode from ‘Access Port’ to ‘Trunk Mode’ or vice versa (Only with Corporate VLAN in the Trunk) No No No No No No No No
Add/Remove a VLAN on Switched Interface with ‘Trunk Mode’ Yes Yes Yes Yes Yes Yes Yes Yes
Enable Cloud VPN for the first time Yes Yes Yes Yes No No No No
Disable/Enable Cloud VPN on a Profile No No No No No No No No
IPv6: Enable Support on the Routed Interface (Static) N/A N/A Yes Yes Yes Yes Yes Yes
IPv6: Enable Support on the Routed Interface (DHCPv6 Stateless) N/A N/A Yes Yes Yes Yes Yes Yes
IPv6: Enable Support on the Route Interface (DHCPv6 Stateful) N/A N/A Yes Yes Yes Yes Yes Yes
IPv6: Any BGP Configuration Change N/A N/A No No No No No No
IPv6: Any BFD Configuration Change N/A N/A No No No No No No
IPv6: Any Static Route Change Configuration Change N/A N/A No No No No No No
IPv6: Reverse Path Forwarding (Turn On: Strict) N/A N/A No No No No No No
IPv6: Reverse Path Forwarding (Turn On: Loose) N/A N/A No No No No No No
IPv6: Reverse Path Forwarding (Turn Off) N/A N/A No No No No No No
IPv6 Only: Change WAN Overlay Configuration N/A N/A N/A No No No No No
IPv6 Dual Stack: Change WAN Overlay Configuration N/A N/A N/A No No No No No
Enable/Disable Branch-to-Hub and Add/Remove a Hub Edge No No No No No No No No
Enable Branch-to-Hub, add a Hub Edge, and Enable Branch-to-Branch VPN with Cloud Gateway No No No No No No No No
Enable Branch-to-Hub, add a Hub Edge, and Enable/Disable Branch-to Branch Enable Cloud VPN with Dynamic Branch-to-Branch No No No No No No No No
Enable Branch-to-Hub, Enable/Disable Branch-to-Branch VPN with Dynamic Branch-to-Branch and Autoselect VPN Hub No No No No No No No No
Enable Branch-to-Hub, Enable/Disable Branch-to-Branch VPN with Dynamic Branch-to-Branch and Branch-to-Hub No No No No No No No No
Enable Branch-to-Hub, Enable/Disable Branch-to-Branch VPN with Dynamic Branch-to-Branch, Branch-to-Hub and Autoselect VPN Hub No No No No No No No No
Enable Branch-to-Hub, Enable/Disable Branch-to-Branch VPN with Dynamic Branch-to-Branch, Branch-to-Hub, and Enable/Disable Dynamic Branch-to-Branch No No No No No No No No
Enable Branch-to-Hub, Branch-to-Branch, execute a Hub Order change No No No No No No No No
Enable/Disable Branch-to-Hub, add/remove Hub-Cluster No No No No No No No No
Enable Branch-to-Hub with Hub-Cluster and Enable Branch-to-Branch VPN with Cloud Gateway No No No No No No No No
Enable Branch-to-Hub with Hub-Cluster and Enable/Disable Branch-to Branch VPN with Dynamic Branch-to-Branch No No No No No No No No
Enable Branch-to-Hub with Hub-Cluster, Enable/Disable Branch-to Branch VPN with Dynamic Branch-to-Branch, Autoselect VPN Hub No No No No No No No No
Enable Branch-to-Hub with Hub-Cluster, Enable/Disable Branch-to Branch VPN with Dynamic Branch-to-Branch and Branch-to-Hub No No No No No No No No
Enable Branch-to-Hub with Hub-Cluster, Enable/Disable Branch-to Branch VPN with Dynamic Branch-to-Branch, Branch-to-Hub and Autoselect VPN Hub No No No No No No No No
Enable Branch-to-Hub with Hub-Cluster, Enable/Disable Branch-to Branch VPN with Dynamic Branch-to-Branch, Branch-to-Hub, and Enable/Disable Dynamic Branch-to-Branch No No No No No No No No
Enable Branch-to-Hub, Branch-to-Branch with Hub-Cluster and execute a Hub order change No No No No No No No No
Enable Branch-to-Non SD-WAN Destination via Edge using Edge Override No No No No No No No No
Activate Intrusion Detection System/Intrusion Prevention System (IDS/IPS) as part of the Enhanced Firewall Service N/A N/A N/A N/A N/A Yes Yes Yes

Business Policy

This section applies to both Edge and Profile level changes to Business Policies on the Configure > Business Policy page of the Orchestrator.

Note: If a Profile business policy changes and an Edge using that Profile already has a configured, matching Edge-specific business policy, the Edge is not affected by the Profile-level business policy change, as the Edge business policy overrides a matching Policy business policy.
Table 5. Business Policy: IPv4 Only
Configuration Type Profile Level Only / Edge Level Only / Both Profile & Edge Override Global Segment / Non-Global Segment Edge Service Restart?
New/Modify/Delete Rule with Source ‘Any’ Both Profile & Edge Override Global Segment & Non-Global Segment No
New/Modify/Delete Rule with Source None Both Profile & Edge Override Global Segment & Non-Global Segment No
New/Modify/Delete Rule with Source VLAN Both Profile & Edge Override Global Segment & Non-Global Segment No
New/Modify/Delete Rule with Source IP Address Both Profile & Edge Override Global Segment & Non-Global Segment No
New/Modify/Delete Rule with Source Ports & Operating System Both Profile & Edge Override Global Segment & Non-Global Segment No
New/Modify/Delete Rule with Destination ‘Any’ Both Profile & Edge Override Global Segment & Non-Global Segment No
New/Modify/Delete Rule with Destination Internet Both Profile & Edge Override Global Segment & Non-Global Segment No
New/Modify/Delete Rule with Destination SD-WAN Edge Both Profile & Edge Override Global Segment & Non-Global Segment No
New/Modify/Delete Rule with Destination Non SD-WAN Destination Both Profile & Edge Override Global Segment & Non-Global Segment No
Newly Created User-Defined Application Map and Respective Application used as Match Criteria Both Profile & Edge Override Global Segment & Non-Global Segment No
Add 1000 Rules and then Delete All Rules Both Profile & Edge Override Global Segment & Non-Global Segment No
New/Modify/Delete Rule with Application ‘Any’ Both Profile & Edge Override Global Segment & Non-Global Segment No
New/Modify/Delete Rule with Defined Application Both Profile & Edge Override Global Segment & Non-Global Segment No
New/Modify/Delete Rule with Priority High/Normal/Low Both Profile & Edge Override Global Segment & Non-Global Segment No
New/Modify/Delete Rule with Network Service Direct/Multi-Path/Internet Backhaul Both Profile & Edge Override Global Segment & Non-Global Segment No
New/Modify/Delete Rule with Link Steering Auto/Transport Group/Interface/WAN Link Both Profile & Edge Override Global Segment & Non-Global Segment No
New/Modify/Delete Rule with NAT Enabled/Disabled Both Profile & Edge Override Global Segment & Non-Global Segment No
New/Modify/Delete Rule with Service Class Real Time/Transactional/Bulk Both Profile & Edge Override Global Segment & Non-Global Segment No
Enable/Disable SD-WAN Traffic Class and Weight Mapping Both Profile & Edge Override Global Segment & Non-Global Segment No
Enable/Disable SD-WAN Overlay Rate Limit Both Profile & Edge Override Global Segment & Non-Global Segment No

 

Table 6. Business Policy: IPv6 Only
Configuration Type Edge Service Restart?
Business Policy (IPv6 only) No
New/Modify/Delete Rule with Source Any IPv6 No
New/Modify/Delete Rule with Source None IPv6 No
New/Modify/Delete Rule with Source VLAN IPv6 No
New/Modify/Delete Rule with Source IP Address IPv6 No
New/Modify/Delete Rule with Source Ports & Operating System IPv6 No
New/Modify/Delete Rule with Destination Any IPv6 No
New/Modify/Delete Rule with Destination Internet IPv6 No
New/Modify/Delete Rule with Destination SD-WAN Edge IPv6 No
New/Modify/Delete Rule with Destination Non SD-WAN Destination IPv6 No
Newly created user defied app map and respective application used as match criteria IPv6 No
Add 1000 Rules and then Delete All Rules IPv6 No
New/Modify/Delete Rule with Application Any IPv6 No
New/Modify/Delete Rule with Defined Application IPv6 No
New/Modify/Delete Rule with Priority High/Normal/Low IPv6 No
New/Modify/Delete Rule with Network Service Direct/Multi-Path/Internet Backhaul IPv6 No
New/Modify/Delete Rule with Link Steering Auto/Transport Group/Interface/WAN Link IPv6 No
New/Modify/Delete Rule with NAT Enabled/Disabled IPv6 No
New/Modify/Delete Rule with Service Class Real Time/Transactional/Bulk IPv6 No

 

Table 7. Business Policy: IPv4/IPv6 Dual Stack (Mixed Mode)
Configuration Type Edge Service Restart?
New/Modify/Delete Rule with Source Any ‘Mixed Mode’ No
New/Modify/Delete Rule with Source None ‘Mixed Mode’ No
New/Modify/Delete Rule with Source VLAN ‘Mixed Mode’ No
New/Modify/Delete Rule with Source IP Address ‘Mixed Mode’ No
New/Modify/Delete Rule with Source Ports & Operating System ‘Mixed Mode’ No
New/Modify/Delete Rule with Destination Any ‘Mixed Mode’ No
New/Modify/Delete Rule with Destination Internet ‘Mixed Mode’ No
New/Modify/Delete Rule with Destination SD-WAN Edge ‘Mixed Mode’ No
New/Modify/Delete Rule with Destination Non SD-WAN Destination ‘Mixed Mode’ No
Newly Created User-Defined Application Map and Respective Application used as Match Criteria ‘Mixed Mode’ No
Add 1000 Rules and then Delete All Rules ‘Mixed Mode’ No
New/Modify/Delete Rule with Application Any ‘Mixed Mode’ No
New/Modify/Delete Rule with Defined Application ‘Mixed Mode’ No
New/Modify/Delete Rule with Priority High/Normal/Low ‘Mixed Mode’ No
New/Modify/Delete Rule with Network Service Direct/Multi-Path/Internet Backhaul No ‘Mixed Mode’ No
New/Modify/Delete Rule with Link Steering Auto/Transport Group/Interface/WAN Link ‘Mixed Mode’ No
New/Modify/Delete Rule with NAT Enabled/Disabled ‘Mixed Mode’ NAT is allowed when IP version is either IPv4 or IPv6 only. Mixed Mode is not supported.
New/Modify/Delete Rule with Service Class Real Time/Transactional/Bulk ‘Mixed Mode’ No

Firewall

This section applies to both Edge and Profile level changes to setting found on the Configure > Firewall page. Changes include Firewall rules, 1:1 NAT rules, and Port-Forwarding rules.

Note: If a Profile rule changes and an Edge using that Profile already has a configured, matching Edge-specific rule, the Edge is not affected by the Profile level rule change as the Edge rule overrides a matching Policy rule.
Table 8. Firewall Rules: IPv4 Only
Configuration Type Profile Level Only / Edge Level Only / Both Profile & Edge Override Global Segment / Non-Global Segment Edge Service Restart?
Enable/Disable Firewall Status Both Profile & Edge Override Global Segment & Non-Global Segment No
Enable/Disable Firewall Logging Both Profile & Edge Override Global Segment & Non-Global Segment No
New/Modify/Delete Rule with Source ‘Any’ and an ‘Allow’ Action Both Profile & Edge Override Global Segment & Non-Global Segment No
New/Modify/Delete Rule with Source ‘None’ with ‘Allow’ Action Both Profile & Edge Override Global Segment & Non-Global Segment No
New/Modify/Delete Rule with Source IP Address with ‘Allow’ Action Both Profile & Edge Override Global Segment & Non-Global Segment No
New/Modify/Delete Rule with Source MAC Address with ‘Deny’ Action Both Profile & Edge Override Global Segment & Non-Global Segment No
New/Modify/Delete Rule with Ports with ‘Deny’ Action Both Profile & Edge Override Global Segment & Non-Global Segment No
New/Modify/Delete Rule with Destination Any with ‘Deny’ Action Both Profile & Edge Override Global Segment & Non-Global Segment No
New/Modify/Delete Rule with Destination None with ‘Allow’ and ‘Log’ Action Both Profile & Edge Override Global Segment & Non-Global Segment No
New/Modify/Delete Rule with Destination IP Address with ‘Allow’ and ‘Log’ Action Both Profile & Edge Override Global Segment & Non-Global Segment No
New/Modify/Delete Rule with Destination MAC Address with ‘Allow’ and ‘Log’ Action Both Profile & Edge Override Global Segment & Non-Global Segment No
New/Modify/Delete Rule with Destination Protocol with ‘Deny’ and ‘Log’ Action Both Profile & Edge Override Global Segment & Non-Global Segment No
New/Modify/Delete Rule with Destination Ports with ‘Deny’ and ‘Log’ Action Both Profile & Edge Override Global Segment & Non-Global Segment No
Newly Created User-Defined Application Map and a Respective Application Used as a Match Criteria Both Profile & Edge Override Global Segment & Non-Global Segment No
Add or Delete a Large Number of Rules (>1000) Both Profile & Edge Override Global Segment & Non-Global Segment No
New/Modify/Delete Rule with Application ‘Any’ with ‘Deny’ and ‘Log’ Action Both Profile & Edge Override Global Segment & Non-Global Segment No
New/Modify/Delete Rule with Defined Application with DSCP tag with ‘Allow’ and ‘Log’ Both Profile & Edge Override Global Segment & Non-Global Segment No
New/Modify/Delete a Port Forwarding Rule Both Profile & Edge Override Global Segment & Non-Global Segment No
New/Modify/Delete a 1:1 NAT Rule Both Profile & Edge Override Global Segment & Non-Global Segment No
Edge Access with Support Access set to ‘Deny All’ Both Profile & Edge Override Global Segment & Non-Global Segment No
Edge Access with Support Access with IP Addresses Configured Both Profile & Edge Override Global Segment & Non-Global Segment No
Edge Access with SNMP Access with Deny/Allow All LAN/IP Addresses Both Profile & Edge Override Global Segment & Non-Global Segment No
Edge Access with Local UI Web Access with Deny All/Allow All LAN/IP Address Both Profile & Edge Override Global Segment & Non-Global Segment No
Enable and Disable Firewall several times, having Firewall Logs Enabled in the Background and confirm that Edge Access is Still Working Both Profile & Edge Override Global Segment & Non-Global Segment No
Enable and Disable Firewall several times, having Firewall Logs Disabled in the Background and confirm that Edge Access is Still Working Both Profile & Edge Override Global Segment & Non-Global Segment No
Turn Firewall Logs ON and OFF several times, having ‘Action’ already set with the Firewall Logs Both Profile & Edge Override Global Segment & Non-Global Segment No

 

Table 9. Firewall Rules: IPv6 Only
Configuration Type Edge Service Restart?
New/Modify/Delete Rule with Source ‘Any’ and ‘Allow’ Action No
New/Modify/Delete Rule with Source ‘None’ and ‘Allow’ Action No
New/Modify/Delete Rule with Source ‘IP Address’ and ‘Allow’ Action No
New/Modify/Delete Rule with Source ‘MAC Address’ and ‘Deny’ Action No
New/Modify/Delete Rule with Source ‘Ports’ and ‘Deny’ Action No
New/Modify/Delete Rule with Destination ‘Any’ with ‘Deny’ Action No
New/Modify/Delete Rule with Destination ‘None’ with ‘Allow’ and ‘Log’ Actions No
New/Modify/Delete Rule with Destination ‘IP Address’ with ‘Allow’ and ‘Log’ Actions No
New/Modify/Delete Rule with Destination ‘MAC Address’ with ‘Allow’ and ‘Log’ Actions IPv6 does not support Destination MAC address
New/Modify/Delete Rule with Destination ‘Protocol’ with ‘Deny’ and ‘Log’ Actions No
New/Modify/Delete Rule with Destination ‘Ports’ with ‘Deny’ and ‘Log’ Actions No
Newly Created User-Defined Application Map and a Respective Application Used as a Match Criteria No
Add or Delete a Large Number of Rules (>1000) No
New/Modify/Delete Rule with Application ‘Any’ and ‘Deny’ and ‘Log’ Actions No
New/Modify/Delete Rule with Defined Application with DSCP Tag and ‘Allow and ‘Log’ Actions No
Stateful Firewall Rules Created for IPv6 No
New/Modify/Delete a 1:1 NAT Rule No
New/Modify/Delete a Port Forwarding Rule No

 

Table 10. Firewall Rules: IPv4/IPv6 Dual Stack (Mixed Use)
Configuration Type Edge Service Restart?
New/Modify/Delete Rule with Source ‘Any’ and ‘Allow’ Action No
New/Modify/Delete Rule with Source ‘None’ and ‘Allow’ Action No
New/Modify/Delete Rule with Source ‘IP Address’ and ‘Allow’ Action No
New/Modify/Delete Rule with Source ‘MAC Address’ and ‘Deny’ Action No
New/Modify/Delete Rule with Source ‘Ports’ and ‘Deny’ Action No
New/Modify/Delete Rule with Destination ‘Any’ with ‘Deny’ Action No
New/Modify/Delete Rule with Destination ‘None’ with ‘Allow’ and ‘Log’ Actions No
New/Modify/Delete Rule with Destination ‘IP Address’ with ‘Allow’ and ‘Log’ Actions Destination with IP Address Not Supported
New/Modify/Delete Rule with Destination ‘MAC Address’ with ‘Allow’ and ‘Log’ Actions Destination with MAC Address Not Supported
New/Modify/Delete Rule with Destination ‘Ports’ with ‘Deny’ and ‘Log’ Actions No
Newly Created User-Defined Application Map and a Respective Application Used as a Match Criteria No
Add or Delete a Large Number of Rules (>1000) No
New/Modify/Delete Rule with Application ‘Any’ and ‘Deny’ and ‘Log’ Actions No
New/Modify/Delete Rule with Defined Application with DSCP Tag and ‘Allow and ‘Log’ Actions No
Stateful Firewall Rules Created for IPv6 No
New/Modify/Delete a 1:1 NAT Rule No
New/Modify/Delete a Port Forwarding Rule No

Segments

This section covers changes to the Segments page of the Orchestrator.

Table 11. Segments
Configuration Type Edge Service Restart?
New/Modify/Delete a New Segment No
Per Customer, Per Segment Partner Gateway Handoff Change No
Add a New Interface to a Segment Yes
Modify Segment Detail Per Interface No
Add/Remove Authentication Settings in a Non-Global Segment No
Add/Remove NetFlow settings in a Non-Global Segment No
Increase the Maximum Number of Segments through the Orchestrator System Settings No

Overlay Flow Control (OFC)

This section covers configuration changes to the Overlay Flow Control (OFC) page of the Orchestrator.

Table 12. Overlay Flow Control
Configuration Type Edge Service Restart?
Change Route Order for specific route No
Move Edge from a Preferred VPN Exit to an Eligible VPN Exit and vice-versa No
Toggle Global Advertise option for Edge/Hub/Partner Gateway No

Network Services

This section covers changes to the Network Services page of the Orchestrator.

Table 13. Network Services
Configuration Type Edge Service Restart?
Create/Delete Edge Cluster No
Non SD-WAN Destinations No
IPv6 Non SD-WAN Destination via Edge No
Cloud Security Service No
Create/Delete DNS Services No
Private Network Names No
Create/Delete Authentication Services No
..