FortiADC REST API Error Codes

Error CodeError Message
-11Invalid length of value.
-12Value out of range.
-13Entry not found.
-14Maximum number of entries has been reached.
-15Duplicate entry.
-16Failed to allocate memory.
-17Invalid name.
-18Invalid IP address.
-19Invalid IP netmask.
-20Blank entry.
-21Invalid country name.
-22Get data disk failed
-23Entry is used.
-24Error opening file.
-25Error reading from shared memory.
-26File error.
-27Insufficient memory.
-28File is not an update file.
-29Unmatched partition size. Please enlarge data disk to minimum 2GB and upgrade to 5.1.x again.
-30Invalid username or password.
-31Failed to transfer file
-36Blank or Incorrect email address.
-37Permission denied.
-38Exceed VDOM resource limitation.
-39Configuration file error.
-40Unable to remove an entry from a static table.
-41This entry is reserved by the system. It cannot be edited.
-42This entry is reserved by the system. It cannot be deleted.
-43This interface is used in an aggregate. Please try another port.
-44VDOM resource limitation exceed current value.
-45Invalid IP address range.
-46Port number is duplicated or in use.
-47IP address is duplicated.
-48Failed to change address type.
-49Password does not match policy.
-50Invalid replacement message format.
-51Password is too short.
-52Password must contain at least one uppercase letter.
-53Password must contain at least one lowercase letter.
-54Password must contain at least one number.
-55Password must contain at least one non-alphanumeric character.
-56Empty value is not allowed.
-57New password must have at least four characters different from the old password.
-58User does not belong to this virtual domain.
-59IP address overlap with another interface.
-60Invalid address type.
-61Input is not as expected.
-62The legal characters are A-Z, a-z, 0-9, - and _ .
-63AntiVirus update failed.
-64AntiSpam engine update failed.
-65AntiSpam rules update failed.
-66AV signature already installed.
-67Physical interface cannot be deleted.
-68Duplicate SNMP community name.
-69SNMP community name cannot empty.
-70The port value is reserved for Global DNS
-71The Virtual Domain option cannot be disabled when multiple virtual domains are present.
-72You cannot add a new interface in the virtual domain pages. Go to the global configuration pages.
-73You cannot delete an interface in the virtual domain pages. Go to the global configuration pages.
-74It is not allowed to config this object in slave mode
-75When disable ipv6, host must be IPv4
-76System API error.
-77When enable ipv6, host must be IPv6
-78When enable ipv6, protocol cannot select arp
-79There is not enough memory to perform a geoip region database update
-80Updated failed.
-81The uploaded file is not a valid geoip database
-82The uploaded file is same as current geoip database
-83Only standalone or HA configure master can perform this task
-84IPS update failed.
-87IMAGE CRC error.
-88VS Port should keep consistent with Pool Member Port under Direct Routing mode.
-89Invalid number.
-90This port is uneditable
-130Invalid date.
-131Invalid year.
-132Invalid month.
-133Invalid day.
-134Invalid time.
-135Invalid hour.
-136Invalid minute.
-137Invalid second.
-138Invalid date of the month.
-139Invalid SSL OCSP Stapling Skew Time.
-140Invalid SSL Session Timeout.
-141Invalid SSL Session Cache Size.
-142Either the local cert is not issued by the issuer cert or they do not match the OCSP response
-144The imported OCSP response is invalid.
-145The imported local certificate is invalid.
-146The imported CA certificate is invalid.
-147Cannot delete default certificate.
-148Failed to sign local certificate through SCEP.
-149Failed to download CA certificate through SCEP.
-150Duplicated CA certificate is not allowed in one group.
-151Duplicated intermediate CA certificate is not allowed in one group.
-152Invalid encryption key.
-153Invalid authentication key.
-154Default certificate is not specified in the Local Certificate Group, the first one will be treated as default.
-155Only one default certificate is allowed in the Local Certificate Group.
-156Duplicated local cert is not allowed in one group.
-157Invalid license key
-158The Intermediate CA group is referenced, please dereference it first before you delete its last member
-159Default certificate is not specified in the Intermediate CA Group, the first one will be treated as default.
-160Invalid SSL CRL Update Ahead Time.
-161Invalid SSL CRL Update Interval Time.
-162Invalid SSL OCSP Stapling Update Ahead Time.
-163Invalid SSL OCSP Stapling Update Interval Time.
-164Invalid SSL OCSP Cache Size.
-165Invalid OCSP url
-166Invalid CERT Subject Alternative Name
-167Failed to import the PKCS #12 file.
-168Could not export the PKCS #12 file.
-169Certificate chain is not allowed! Only first certificate in chain is imported.
-170OCSP over secured http is not supported
-171Build-in certificate is not allowed to export.
-172HSM FIPS key size is too small
-173Initialization context failed.
-174Set context failed.
-201Passwords do not match.
-202IP address is blocklisted. Wait a few minutes before trying again.
-203IP address has been blocked.
-204Invalid username or password.
-205Only an admin user with super access profile is allowed when the VM license is invalid.
-206Cannot change the access profile of the predefined super admin account.
-207Cannot assign a higher privilege than your own.
-208Cannot delete current admin user.
-209Old password is invalid.
-210Password cannot be empty.
-211Invalid mode.
-212Invalid server.
-213Cannot config global admin user by normal admin user.
-214Invalid token
-215Invalid entry.
-216Invalid user
-217You need to disable shell access and modify the username or passowrd during next shell access enable config session.
-218Username is already used by system.
-280Command timeout.
-281Failed to add entry.
-282User canceled.
-283Configuration management database API error.
-284CLI parsing error.
-285Configuration condition is not fulfilled.
-286CLI internal error.
-287Configuration management database SQL API error.
-288Configuration file error.
-289Virtual domain not found.
-290Virtual domain is not supported on this platform.
-291Virtual domain number exceeds the maximum.
-292Delete all non-root vdoms first.
-513Invalid domain.
-514Creating entry error.
-515Maximum allocated quota has been reached.
-516Failed to delete a table entry.
-517Failed to append child list.
-602Invalid arguments.
-603The last bit of the MAC address first byte must not be 1.
-801The signature of the new image is invalid or contains invalid data.
-802The new image does not contain a signature.
-803Upgrade to the new image failed.
-804The signature of the new image is invalid or contains invalid data.
-805FIPS: Password too short. Must be at least 8 characters.
-806FIPS: Server mode is not supported when FIPS is enabled.
-807FIPS: Minimum certificate key length of 1024 bits is required.
-808FIPS: Unsupported certificate signature algorithm.
-809FIPS: Telnet/HTTP access are not allowed.
Error CodeError Message
-1002System shutting down.
-1013Invalid device ID.
-1014Device blocked.
-1015Connection ignored.
-1016Device added as unregistered.
-1100Low encryption: Maximum certificate key length of 512 bits is required.
-1101Low encryption: Unsupported certificate signature algorithm.
-1102LDAP profile disabled.
-1103No additional caching configurations can be enabled for LDAP profiles.
-1108Error changing password.
-1110Supported key size: 512, 1024, 1536, 2048, 4096.
-1111Cannot import certificate.
-1200The specified IP address and port are already used by another virtual server.
-1201The specified IP address/port is the same as the management service (HTTP, HTTPS, SSH, Telnet, SNMP).
-1202Cannot add an identical policy route.
-1203The specified IP address and port is already used by another pool member.
-1204Health check name is invalid.
-1205Cannot modify virtual server ID and multiprocess ID once the virtual server has been created.
-1206Cannot set multiprocess ID when multiprocess mode is not enabled.
-1207The virtual server ID is already used.
-1208The virtual server multiprocess ID is already used.
-1209You must configure persistence for FTP profiles when Direct Routing mode is specified.
-1210The specified type already exists.
-1211The specified persistence type is not supported by Layer 4 virtual servers.
-1212The specified IP address will exist on different interfaces.
-1213The specified virtual server type does not support the Full NAT packet forwarding method.
-1214Source Pool must be set.
-1215The IP address range end address must be greater than or equal to the start address.
-1216IP address range limit is 128.
-1217IP address must not be 0.0.0.0,::, 255.255.255.255, ffff:ffff:ffff:ffff:ffff:ffff:ffff:ffff etc.
-1218Conflicts with virtual server IP address.
-1219Conflicts with real server IP address.
-1220Conflicts with interface IP address.
-1221Source Pool address type error.
-1222Conflicts with gateway IP address.
-1223Virtual server IP address is invalid.
-1224Virtual server port is invalid.
-1225Real Server must be set.
-1226Load balance method must set.
-1227Connection pool is allowed only for Layer 7 virtual servers with source address disabled in the associated profile.
-1228URI regular expression is invalid.
-1229Layer 7 content routing supports only HTTP, HTTPS and TurboHTTP profiles.
-1230Content route type does not match the virtual server type.
-1231Content route list cannot be empty.
-1232The virtual server real server pool has not been set.
-1233Cannot change type when content routing is specified.
-1234Layer 4 content routing supports only TCP, UDP and FTP profiles.
-1235Layer 2 content routing supports only HTTP, HTTPS and TCPS profiles.
-1236The regular expression is invalid in the Condition Table.
-1237The profile is associate with a virtual server. You cannot change its type.
-1238Layer 4 FTP service is not supported for IPv6 traffic.
-1239The virtual server profile does not support the specified persisitence method.
-1240The specified profile and method together can’t be supported by this virtual server type.
-1241Unsupported ciphers list.
-1242Content routing is not supported by this virtual server.
-1243Content rewriting is not supported by this virtual server.
-1244Transactions rate limit is not supported by this virtual server, set it 0 to close.
-1245WAF profile is not supported by this VS
-1246Port Range is not supported, please check supported profile or range number
-1247Auth policy is not supported, only HTTP and HTTPS profile can support this.
-1248Auth policy is not supported with http once only profile.
-1249The content should be set usual IPv4/IPv6 addresses, with or without a netmask appended.
-1250Total subqueue bandwidth is greater than the parent queue bandwidth.
-1251The bandwidth format is invalid, or exceed range.
-1252The selected queue is not the child or grand(grand..) child of the root queue.
-1253Root queue duplicated (same direction and same interface).
-1254If you change parent of this queue, the root’s default queue will be lost.
-1255The specified bandwidth is less than the total sum of its child queues.
-1256The address specified by a QoS filter cannot be a range.
-1257The port specified by a QoS filter cannot be a range.
-1260The IP reputation redirect url must begin with http:// or https://
-1261The geoip redirect url must begin with http:// or https://
-1262The selected content type is already included.
-1263The real server name is already used by another pool member.
-1264Real Server name must be set.
-1265L2 exception list member limit reached!
-1266SSL mirror supports only HTTPS and TCPS profiles.
-1267SSL mirror interface number over limit
-1268Source pool is used as another virtual server with different traffic group.
-1269Port conflict with global load balance
-1270Connection pool is not supported in http keepalive mode.
-1271Can’t configure ippool in content routing if the share ip mode is disabled!
-1272The number of radius attribute list limit reached!
-1273The specified type already exists.
-1274The schedule pool list need to be configured.
-1275The specified shedule pools are conflict.
-1276Pool member number in schedule pool or pool member ID exceeds the maximum(128) when using Layer 7 virtual server.
-1277Invalid HTTP header value.
-1278Invalid HTTP header name.
-1279The max persistence entries is not supported with this profile
-1280The port number must be set to 0 when the profile`s type is IP
-1281The protocol number cannot be set to other than 0 when the profile`s type is not IP
-1282The same real server is assigned to different schedule pools of a virtual server or content routing.
-1283Can`t enable content-routing and schedule-pool at the same time
-1284VS Port should keep consistent with Pool Member Port under Tunnel mode.
-1285You must configure persistence for FTP profiles when tunnel mode is specified.
-1286The IP address types for VS and real server pool do not match.
-1287Can`t assign soft-switch to this virtual server with specified profile or packet forward method
-1288The L2 address is used by other.
-1289The specified IP address and port are used by other.
-1290The geo IP option is not support with the secified type, profile or packet forward method
-1291One Click GSLB Virtual Servers exceed the capacity.
-1292SSL version max is lower than min
-1293The specified interface ip and CoA port are used by other.
-1294The interface ip is required for CoA.
-1295The same HA Node Number is already exist in current NAT Source Pool.
-1296IPV6 pool is not supported on Layer 2 virtual server.
-1297Content routing is referenced by Layer 2 virtual server, IPV6 pool is not supported
-1298The specified Profile is not supported by L2 IPv6.
-1299The port number must be set to 21 when the profile type is FTP.
-1350You must set a heartbeat port.
-1351The license is a trial license.
-1352The specified interface is not under the root virtual domain.
-1353The number of heartbeat ports is out of range. You can select 1-2 ports.
-1354The number of data ports is out of range. You can select 1-3 ports.
-1355The number of monitor ports is out of range. You can select 1-16 ports.
-1356Can not use tftp ha synchronization in standalone mode.
-1357The member port can not be configured as ha heartbeat,data,or monitor port.
-1358The number of gateway monitor is out of range. You can config 1-64 gateways.
-1359The same remote ip entry is exist.
-1360Only master can do this operation.
-1361Only HA VRRP mode can do this operation.
-1362The traffic group is not exist.
-1363The number of traffic group is out of range.
-1364The ethernet type must be 4 hex digit.
-1365The same ethernet type value can’t be used as different ethernet type.
-1366The HA management IP address isn’t set
-1367The HA management interface isn’t set
-1368IP address overlaps with the HA management IP address
-1369HA Unicast Local IP Address must be set!
-1370HA Unicast Peer IP Address must be set!
-1371HA Unicast is only supported by VRRP mode
-1372HA Unicast isn’t support at this platform.
-1373Only HA VRRP mode and HA Unicast are supported on this platform.
-1374HA is not supported on this platform.
-1375HA Unicast Local IP Address must be one of the Heartbeat interfaces.
-1376The IP address is used by HA Unicast Local Address.
-1377Please switch to Standalone firstly.
-1450The prefix is already used.
-1451Egress Interface must be set.
-1452The IP address range end address must be greater than the start address.
-1453The Translate to IP address must be set.
-1454The IP address type for the specified gateway and destination do not match.
-1455The IP address/range is invalid.
-1456The mapped address/range cannot include any interface address.
-1457The external address/range cannot include any interface address when port forwarding is enabled.
-1458The external address/range cannot include the external interface address.
-1459The IP address/range cannot overlap.
-1460The port/range is invalid.
-1461Conflicts with the mapped IP address for 1-to-1 NAT rules.
-1462Conflicts with the external IP address for 1-to-1 NAT rules.
-1463The interface is already set.
-1464The ISP group is already used.
-1465The area id is invalid.
-1466Duplicated area id is not allowed.
-1467The mapped IP address/range is conflict with IP address of virtual server.
-1469The range of id is from 1 to 256
-1550Source IP address must be the address for an interface or a virtual server.
-1551Destination IP address must be set.
-1552Timeout must be less than Interval.
-1553The gateway has not been set.
-1554When health check is enabled, you must specify one health check.
-1555The specified gateway already exists.
-1556Health check is used by a gateway.
-1557The Local Virtual Server must be set correctly.
-1558The Local Virtual Server listening interface must be the same as the LLB gateway egress interface.
-1559IPv4 address must be set.
-1560IPv6 address must be set.
-1561Domain name must be set.
-1562Pool name must be set.
-1563Link policy number exceeds the maximum (4096).
-1564Link group number exceeds the maximum (1024).
-1565Link member number exceeds the maximum (255).
-1566Invalid address range.
-1567The link load balancing policy rule cannot use the default link group.
-1568The link group is already used by a link load balancing policy rule.
-1569LLB gateway is not a valid member of the default link group.
-1570The default link group is being used.
-1571The link member is being used by a DNS host pool.
-1572Gateway conflict with local interface IP address.
-1573Link group must be set.
-1574Virtual tunnel group must be set.
-1575Aging period should not be shorter than retry time.
-1576Duplicate entry is not allowed in proximity static table.
-1577Conflicts with virtual server source pool address.
-1578Invalid link group or link group member.
-1579Conflicts with NAT translate to address.
-1580The virtual server port is already in used
-1650Invalid Maximum Object Size.
-1651Invalid Maximum Cache Size.
-1652Invalid Maximum Certificate Cache Size.
-1701The destination port range end value must be greater than the start value.
-1702The source port range end value must be greater than the start value.
-1703The IP address range end address must be greater than the start address.
-1900Log category is not supported.
Error CodeError Message
-2001PHP invalid arguments.
-2002An error occured while uploading.
-2003Upload failed (not finished).
-2004Upload category not supported.
-2005Download category not supported.
-2006Failed to convert string to data (PHP internal error).
-2007Failed to synchronize the configuration.
-2008Failed to set the system time.
-2009Failed to generate the report.
-2010Failed to connect to the SMTP server.
-2011Failed to set filter for the Event log.
-2012Failed to set filter for the Traffic log.
-2013Log is not ready.
-2014User count has reached the limit.
-2015Log system is busy.
-2016Cannot swap boot partition because there is only one valid boot partition.
-2017Failded to start packet capture
-2018Failded to stop packet capture
-2019Failded to save packet capture file
Error CodeError Message
-3001Zone is used by another DNS policy.
-3002Compatible IPv6 prefixes have lengths of 32 40 48 56 64 and 96 (RFC 6052).
-3003ACL name is reserved by system.
-3004Invalid anchor key format. The key format should like this: “domainname” num1 num2 num3 “content”.
-3005Domain name can’t be changed.
-3006Invalid domain name. Only ‘a’-‘z’, ‘A’-‘Z’, ‘0’-‘9’, ’-.’ are allowed and must end with a ’.’ character.
-3007Invalid primary server name. only ‘a’-‘z’, ‘A’-‘Z’, ‘0’-‘9’ ’-.’ are allowed and must not end with a ’-’ character.
-3008Primary Server IP address must be set.
-3009The DNSSEC related information for a zone cannot be modified. You can unset DNSSEC.
-3010Invalid hostname. Only ‘a’-‘z’, ‘A’-‘Z’, ‘0’-‘9’, ’-.’ are allowed and must not end with ’-.’ character. Or ’@’ as null, ’*’ as wildcard.
-3011IP address must be set.
-3012Invalid alias. Only ‘a’-‘z’, ‘A’-‘Z’, ‘0’-‘9’, ’_-.’ are allowed and must not end with ’-.’ character. Or ’*’ as wildcard.
-3013Invalid target. Only ‘a’-‘z’, ‘A’-‘Z’, ‘0’-‘9’, ’_-.’ are allowed and must not end with ’-’ character. Or ’@’ as null, ’*’ as wildcard.
-3014Duplicated alias name.
-3015Invalid ns domain name. Only ‘a’-‘z’, ‘A’-‘Z’, ‘0’-‘9’, ’-.’ are allowed and must not end with ’-.’ character. Or ’@’ as null.
-3016Duplicated ns record.
-3017Only ‘a’-‘z’ ‘A’-‘Z’ ‘0’-‘9’ ’-’ are allowed for name string.
-3018Dsset list filename must be unique
-3019Create fqdn-generate type zone error
-3020Zone is used by FQDN host
-3021Zone is generated by FQDN host, so you can’t modify the domain name
-3022Zone is used by dns policy, so you can’t modify the domain name
-3023Virtual server port cannot be 0
-3024Invalid txt name. Only ‘a’-‘z’, ‘A’-‘Z’, ‘0’-‘9’, ’_-.’ are allowed and must not end with ’-.‘. Or just ’@’ as null, ’*’ as wildcard.
-3025Invalid txt text. only ‘a’-‘z’, ‘A’-‘Z’, ‘0’-‘9’, ’.*/-:_?=@,&’ are allowed and must not end with a ’.’ character.
-3026Duplicated record.
-3027Invalid anchor key content.
-3028Invalid mx hostname. Only ‘a’-‘z’, ‘A’-‘Z’, ‘0’-‘9’, ’-.’ are allowed and must not end with ’-‘. Or just ’@’ as null.
-3029Invalid responsible mail. Only ‘a’-‘z’, ‘A’-‘Z’, ‘0’-‘9’, ’-.’ are allowed and must not end with ’-‘. Also the ’@’ need be replaced by the ’.’ character.
-3030The name can’t be same as domainname.
-3031Zone is used by FQDN host.
-3032Server and gateway must be set
-3033Link and Link member are in different Datacenter!
-3034Duplicated link member with other link
-3035Port 53 is conflict with server-load-balance
-3036Invalid PTR Address. It should be an IP address or part of IP address in reverse format. Or just ’@’ as null, ’*’ as wildcard.
-3037GEOIPs are duplicated
-3038GEOIPs are conflicted
-3039Topologys’ members are duplicated in the GLB host
-3040Virtual Server pools are duplicated in the GLB host
-3041GLB FQDN hosts are duplicated
-3042Invalid ns hostname. Only ‘a’-‘z’, ‘A’-‘Z’, ‘0’-‘9’, ’-.’ are allowed, and must not end with ’-’ character.
-3043IP address must not be set, while host-name end with ’.’
-3044GEOIP list cannot be NULL
-3045Password length is too long(limitation:0 ~ 60)!
-3046Invalid mx domain name. Only ‘a’-‘z’, ‘A’-‘Z’, ‘0’-‘9’, ’-.’ are allowed and must not end with ’-.‘. Or just ’@’ as null, ’*’ as wildcard.
-3047Zone type is not allowed to switch.
-3048’fqdn_generate_’ can’t be used as non-fqdn-generate type zone name
-3049Invalid srv hostname. Only ‘a’-‘z’, ‘A’-‘Z’, ‘0’-‘9’, ’_-.’ are allowed and must not end with ’-.‘. Or just ’@’ as null, ’*’ as wildcard.
-3050Invalid srv target name. Only ‘a’-‘z’, ‘A’-‘Z’, ‘0’-‘9’, ’-.’ are allowed and must not end with ’-‘. Or just ’@’ as null.
-3051Invalid PTR fqdn. Only ‘a’-‘z’, ‘A’-‘Z’, ‘0’-‘9’, ’-.’ are allowed and must end with ’.‘.
-3052Policy is not find with the input policy name.
-3053Zone is not find with the input zone name.
-3054Host is not find with the input host name.
-3055Duplicated server name is existed.
-3056Duplicated vsp name is existed.
-3057Duplicated host name is existed.
-3058Wizard server name is too long.
-3059Wizard vsp name is too long.
-3060Server member IP and type cannot be changed when server auto-sync is enabled.
-3061Server member cannot be added when server auto-sync is enabled.
-3062Server member cannot be deleted when server auto-sync is enabled.
-3063Invalid dsset list filename, should start with ‘dsset-’.
-3064The listen port of the IPv4 loopback address is used by other.
-3065The listen port of the IPv6 loopback address is used by other.
-3066The listen port of the IPv4 interface address is used by other.
-3067The listen port of the IPv6 interface address is used by other.
-3068The listen port of the floating address is used by other.
-3069The listen port of the secondary address is used by other.
-3070The listen port of the secondary floating address is used by other.
-3071The listen port of the HA node address is used by other.
-3072The listen port of the HA node secondary address is used by other.
-3073Invalid caa hostname. Only ‘a’-‘z’, ‘A’-‘Z’, ‘0’-‘9’, ’_-.’ are allowed and must not end with ’-.‘. Or just ’@’ as null, ’*’ as wildcard.
-3074Duplicated server IP is existed, please add virtual server members to the existing server.
-3075TXT record text length is exceed 255, please use two quotes ’""’ to paragraph the record.
-3076Alias name is conflict with A/AAAA record host name.
-3077Alias name is conflict with NS record host name.
-3078Alias name is conflict with NS record domain name.
-3079Alias name is conflict with MX record host name.
-3080Alias name is conflict with MX record domain name.
-3081Alias name is conflict with SRV record host name.
-3082Alias name is conflict with TXT record name.
-3083Alias name is conflict with CAA record host name.
-3084Alias name is conflict with host configure.
-3085A/AAAA record host name is conflict with CNAME Alias.
-3086NS record host name is conflict with CNAME Alias.
-3087NS record domain name is conflict with CNAME Alias.
-3088MX record host name is conflict with CNAME Alias.
-3089MX record domain name is conflict with CNAME Alias.
-3090SRV record host name is conflict with CNAME Alias.
-3091TXT record name is conflict with CNAME Alias.
-3092CAA record host name is conflict with CNAME Alias.
-3093Host configure is conflict with CNAME Alias.
-3094Server member address must be set.
-3095NS record is not allow to change domain or remove, should remove the related dsset file and save the zone first.
-3096Dsset file is not allow to add, should add the related ns record first.
-3097TXT record text contains unmatched double quotes.
-3098Port 53 is conflict with GLB Setting Listen on Port
-3099Port 53 is conflict with System Settings Basic
-3100The DNS over TCP/UDP service port is used by other.
-3101The DNS over HTTPS service port is used by other.
-3102The DNS over HTTP service port is used by other.
-3103The DNS over TLS service port is used by other.
-3104The DNS over TCP/UDP service port of the IPv6 interface address is used by other.
-3105The DNS over TCP/UDP service port of the IPv4 interface address is used by other.
-3106The DNS over HTTPS service port of the IPv6 interface address is used by other.
-3107The DNS over HTTPS service port of the IPv4 interface address is used by other.
-3108The DNS over HTTP service port of the IPv6 interface address is used by other.
-3109The DNS over HTTP service port of the IPv4 interface address is used by other.
-3110The DNS over TLS service port of the IPv6 interface address is used by other.
-3111The DNS over TLS service port of the IPv4 interface address is used by other.
-3112The DNS over TCP/UDP service port of the secondary address is used by other.
-3113The DNS over HTTPS service port of the secondary address is used by other.
-3114The DNS over HTTP service port of the secondary address is used by other.
-3115The DNS over TLS service port of the secondary address is used by other.
-3116The DNS over TCP/UDP service port of the secondary floating address is used by other.
-3117The DNS over HTTPS service port of the secondary floating address is used by other.
-3118The DNS over HTTP service port of the secondary floating address is used by other.
-3119The DNS over TLS service port of the secondary floating address is used by other.
-3120The DNS over TCP/UDP service port of the HA node address is used by other.
-3121The DNS over HTTPS service port of the HA node address is used by other.
-3122The DNS over HTTP service port of the HA node address is used by other.
-3123The DNS over TLS service port of the HA node address is used by other.
-3124The DNS over TCP/UDP service port of the HA node secondary address is used by other.
-3125The DNS over HTTPS service port of the HA node secondary address is used by other.
-3126The DNS over HTTP service port of the HA node secondary address is used by other.
-3127The DNS over TLS service port of the HA node secondary address is used by other.
-3128The DoH/DoT certificate is invalid.
-3129The DNSSEC keys are incomplete, please wait while.
-3200Predefine ISP address-book cannot be deleted.
-3201Restored ISP address-book cannot be deleted.
-3202Duplicated subnet is not allowed in the same ISP address-book.
-3203Subnet already exists in another ISP address-book.
-3204Subnet not exists in the ISP address-book.
-3205ISP address-book not exists.
-3206Only the predefined subnet can be added to the exclude-address list
-3210Duplicated address is not allowed in the same address group.
-3211Duplicated service is not allowed in the same service group.
-3212Can not load predefine isp address-book.
-3213Predefine isp is used by isp route.
-3214Predefine isp is used by link-load-balance flow-policy.
-3215Predefine isp is used by link-load-balance proximity entry.
-3216Predefine isp is used by global-load-balance data-center.
-3217Can not unload predefine isp address-book.
-3218Can not add exclude address for user-define ISP address-book.
-3219Predefine isp is used by global-load-balance link.
-3220Predefine isp is used by global-load-balance host.
-3260Health check is used by LLB gateway, can not use port 0.
-3261Health check is used by GLB generic host, can not use port 0.
-3262Health check use port 0, can not used by LLB gateway.
-3263Health check use port 0, can not used by GLB generic host.
-3500URI regular expression is invalid.
-3501File extension regular expression is invalid.
-3502Maximum code should be equal or greater than minimum code.
-3503Request URL should begin with ’/‘.
-3504Exception rule exceeds maximum dfa graph size.
-3505Exception rule regular expression is invalid.
-3506Another exception already exists in the rule ID
-3507Bot detection URL regular expression is invalid.
-3508Bot detection URL should begin with ’/‘.
-3509Bot detection URL parameter name regular expression is invalid.
-3510Bot detection cookie name regular expression is invalid.
-3511Bot detection user-agent regular expression is invalid.
-3512Bot detection allowlist rule cannot be empty.
-3513Bot detection IP mask should be <1 ~ 32>.
-3514Duplicate signature category is not allowed.
-3515Duplicate signature sub category is not allowed.
-3516Duplicate exception rule is not allowed.
-3517Signature ID not found in this virtual server.
-3518XML schema file does no exist.
-3519JSON schema file does not exist.
-3520Request URL should begin with ’/‘.
-3521Data leak prevention regular expression is invalid.
-3522Sensitive data type regular expression is invalid.
-3523File restrict file type not exist.
-3524File restrict file extension is invalid.
-3525Request URL should begin with ’/‘.
-3526URL regular expression is invalid.
-3527A duplicate entry already exists.
-3528Parameter Value regular expression is invalid.
-3529OpenAPI schema file does not exist.
-3530Invalid file format of OpenAPI Schema.
-3531Secure should be set when using samesite none.
-3532Request URL should begin with ’/‘.
-3533URL regular expression is invalid.
-3534CORS allowed methods is not set.
-3535CORS allowed headers list does not exist.
-3536CORS exposed headers list does not exist.
-3537Profile not found.
-3538Profile rule not found.
-3539This profile does not support add exception.
-3540URL regular expression is invalid.
-3600Scripting file no exist.
-3601Scripting has invalid event.
-3602Scripting event duplicates.
-3603Scripting syntax error.
-3604Scripting doesn’t contain any event.
-3605Scripting doesn’t support non standalone mode
-3606Some content routing(s) in the script does not exist in the VS configuration
-3607Scripting has mismatched { and }
-3608Scripting has invalid class function
-3609Scripting supports only L2 or L7 virtual server with HTTP or HTTPS type of profile
-3610Some script(s) in the script list does not exist
-3999Dual cert has same type.
Error CodeError Message
-4001The location header should not be used in http request.
-4002The ssl proxy mode can’t support strict sni request.
-4003The ssl proxy mode must have a non-empty certificate group and a default certificate in it.
-4004The ssl proxy mode must have intermediate ca group.
-4005The ssl proxy mode requests that intermediate ca group must have default ca.
-4006The ssl proxy mode requests a valid default intermediate ca in group.
-4007The ssl proxy mode requests default intermediate ca must have a private key.
-4008The ssl proxy mode can’t support this method.
-4009The ssl proxy mode can’t support this persistence.
-4010The ssl proxy mode can’t support content routing.
-4011The input SSL cipher suite(s) not supported, please check spelling
-4012The ssl proxy mode can’t support certificate verify.
-4013The l2 exception list can’t support this type of profile.
-4014The ssl proxy mode can’t support connection pool.
-4015Only one default certificate is allowed in the Intermediate CA Group.
-4016Not allowed to change the configured certificate for a remote setup.
-4017Referenced CRL file does not exist
-4018Referenced CA file does not exist
-4019Referenced CA group is empty
-4020Referenced remote is missing certificate and/or OCSP URL
-4021Referenced intermediate CA file does not exist
-4022Referenced local cert file does not exist
-4023Referenced intermediate CA group is empty
-4024Referenced intermediate ca has a mismatched certificate type
-4025Referenced certificate and intermediate ca have mismatched certificate type
-4026The certificate and/or its key file is referenced, please dereference it first
-4027The CA group is referenced, please dereference it first before you delete its last member
-4028The OCSP is referenced, please dereference it first before you clear its URL
-4029Web filter profile has duplicate category or sub category.
-4030Error page file does no exist.
-4031The number of SIP header operator excess
-4032Cannot add an identical SIP header operator
-4033SIP header string only accepts header name for erase operator
-4034SIP header string need ‘header: value’ format for insert operator
-4035The SIP protocol doesn’t support this method
-4036The SIP protocol doesn’t support this persistence
-4037The SIP SLB doesn’t support non standalone mode
-4038The SIP SLB only support L7 mode
-4039The SIP SLB doesn’t support authentication policy
-4040The SIP SLB doesn’t support connection pool
-4041The SIP SLB doesn’t support content routing
-4042The SIP SLB doesn’t support content rewriting
-4043The SIP SLB doesn’t support error page
-4044The SIP SLB doesn’t support WAF
-4045The SIP SLB doesn’t support virtual server scripting
-4046The SIP SLB doesn’t support multi processes
-4047The SIP SLB doesn’t support virtual server warm up
-4048The SIP SLB doesn’t support the number of port more than 5
-4049The RDP profile must be a L7 virtual server type.
-4050The RDP profile doesn’t support content routing.
-4051The RDP profile doesn’t support content rewriting.
-4052The RDP profile doesn’t support transaction limit.
-4053The RDP profile doesn’t support port range.
-4054The RDP profile doesn’t support authentication policy.
-4055The RDP profile doesn’t support scripting.
-4056The RDP profile doesn’t support error page.
-4057The RDP profile doesn’t support waf profile.
-4058The RDP profile doesn’t support this method.
-4059The RDP profile doesn’t support this persistence.
-4060The SIP SLB doesn’t support IPv4-mapped IPv6 address
-4061Bad string, double quotation is not acceptable
-4062The ge number of the prefix list rule is not correct
-4063The le number of the prefix list rule is not correct
-4064The ge number and le number of the prefix list rule is not correct
-4065Conflict with distribute list in and prefix list in
-4066Conflict with distribute list out and prefix list out
-4067bgp as number is out of range
-4068bgp neighbor remote as number is out of range
-4069bgp neighbor keepalive and holdtime timer is not correct
-4070The access list name is not supported
-4071bgp neighbor ebgp multihop only allowed for EBGP peers
-4072bgp neighbor ttl security only allowed for EBGP peers
-4073bgp neighbor ttl security and ebgp multihop cannot be configured together
-4074The match condition’s count limitation has been reached.
-4075The local certificate group mustn’t be empty.
-4076The method type can’t change when it has been referenced.
-4077IP profile only support for L2 load balance.
-4078protocol number setting is not supported for this profile
-4079protocol number setting is conflict with another virtual server
-4080virtual server port is 0, real server health check port should not be 0
-4081virtual server port is 0, real server member health check port should not be 0
-4082virtual server port is 0, real server port should also be 0
-4083This type’s virtual server port count limit reached.
-4084Virtual server only support at most 8 port ranges.
-4085Virtual server port should be 0 or 1-65535, and port start should be no larger than port end.
-4086Virtual server only support at most 8 protocol ranges.
-4087Virtual server protocol number should be between 0-255, and protocol start should be no larger than protocol end.
-4088Virtual server port should be a number or a range with ’-‘.
-4089Virtual server protocol should be a number or a range with ’-‘.
-4090Virtual server port 0 should be not configured with other ports.
-4091Virtual server port 0 is not supported for this profile.
-4092bgp neighbor passowrd length should less than 80
-4162Please select a CA for this verify member
-4163The selected CRL file is not issued by this CA
-4164This CA certificate is already included in the verify.
-4165CA group is missing in a referenced remote
-4166No remote selected for the referenced OCSP in the verify
-4167The remote certificate file does not exist for the selected remote in the referenced OCSP in the verify
-4168Referenced OCSP is missing URL
-4169The DNS profile must be a L7 virtual server type.
-4170The DNS profile doesn’t support content routing.
-4171The DNS profile doesn’t support content rewriting.
-4172The DNS SLB doesn’t support connection pool
-4173The DNS profile doesn’t support port range.
-4174The DNS profile doesn’t support authentication policy.
-4175The DNS profile doesn’t support scripting.
-4176The DNS profile doesn’t support error page.
-4177The DNS profile doesn’t support waf profile.
-4178The DNS profile doesn’t support this method.
-4179The DNS profile doesn’t support persistence.
-4180The DNS SLB doesn’t support non standalone mode
-4181The DNS SLB doesn’t support multi processes
-4182The DNS SLB doesn’t support virtual server warm up
-4183The DNS SLB doesn’t support connection limit
-4184Caching policy is not supported with profile other than server-close.
-4185Invalid SSO Domain format: XXX.[Domain]
-4186Top level domain is not allowed
-4187Maximum of 2 components are used
-4188Valid principal format: Name[/instance]@REALM
-4189Cross realm is not supported
-4190Duplicated SPN within Realm
-4191At most 1 auth-relay server can be configured in a user group
-4192Member type should be either auth-relay server or other authentication server
-4193There should be at least one member for SSO type user-group
-4194Domain prefix should be a valid NetBIOS domain name
-4195The metric instance name does not match metric object type
-4196The metric member does not match metric object type
-4197The virtual path is used
-4198The memeber type with NTLM only support Normal Group Type
-4199Only allow one NTLM server when client auth. method is NTLM
-4200SAML SSO can’t support the ECDSA certificate.
-4201SAML SSO export assertion ACL list is full.
-4202The auth policy can only contain one SAML SSO profile.
-4203The SAML SSO can’t support the non standalone VS.
-4204The SMTP profile must be a L7 virtual server type.
-4205The SMTP profile doesn’t support content routing.
-4206The SMTP profile doesn’t support content rewriting.
-4207The SMTP profile doesn’t support port range.
-4208The SMTP SLB doesn’t support virtual server warm up.
-4209The SMTP profile doesn’t support authentication policy.
-4210The SMTP profile doesn’t support scripting.
-4211The SMTP profile doesn’t support error page.
-4212The SMTP profile doesn’t support waf profile.
-4213The SMTP profile doesn’t support this method.
-4214The SMTP profile doesn’t support this persistence.
-4215The SMTP profile must be set domain name.
-4216attribute ‘local-cert-group’ must be set.
-4217Doesn’t support interface with type loopback
-4218hardware-ssl-status can’t enable because global HSM enable and client-ssl-profile is used at the same time.
-4219the number of enabled hardware-ssl process is exceed the limit.
-4220the size of RSA key of client-ssl-profile is not support by hardware-ssl-status all and ae-only.
-4221the size of RSA key of rs-profile is not support by hardware-ssl-status all and ae-only.
-4222client ssl versions are not continuous.
-4223client backend ssl versions are not continuous.
-4224Only TCPS and HTTPS profile need client ssl profile
-4225TCPS and HTTPS profile require client ssl profile
-4226The ssl proxy mode can’t support L4-VS.
-4227The selected local-ca in the ssl proxy mode is not a CA.
-4228Referenced local signing ca cert file or key file does not exist
-4229There is a conflict between SSL proxy mode and the profile type, SSL proxy supports only HTTPS profile
-4230The Verify group is referenced, please dereference it first before you delete its last member
-4231Client SSL Supported Groups have no FFDHExxx
-4232Client SSL enabled RFC7919 Comply but no DHE ciphers
-4233Client SSL Supported Groups have no EC curve
-4234Client SSL add EC curve in Supported Groups but no ECDHE ciphers
-4235Client SSL RFC7919 Comply can not support TLS 1.3
-4236Client SSL RFC7919 Comply can not support SSLv3
-4240The specified load-balance-profile of virtual server does not support the specified type
-4241The specified load-balance-profile of virtual server does not support the specified load-balance-persistence
-4242The specified type of virtual server does not support traffic log
-4270Only HTTP Form is support 2FA authentication
-4298DIAMETER profile with client_ssl require client ssl profile.
-4299The profile is associate with a virtual server. You cannot change its client_ssl.
-4300The Real Server that uses the ip/ip6 has existed.
-4301The specified Real Server and port is already used by another pool member.
-4302The Source IP Pool not support this packet forward method.
-4303The Source IP Pool not support this type of profile.
-4304The SAML SSO can’t support the multi-port VS.
-4305The table in mysql-sharding is duplicate.
-4306There is not IPv4 address in the real-server.
-4307There is not IPv6 address in the real-server.
-4308Can not unset IPv4, it used by a pool member.
-4309Can not unset IPv6, it used by a pool member.
-4310The MySQL virtual-server don’t support traffic-log.
-4311The MySQL virtual-server don’t support load-balance-persistence.
-4312SMTP profile with StartTLS require client ssl profile.
-4313There is a conflict between client ssl profile and the profile type, SMTP profile with StartTLS require local-certificate-group.
-4314SMTP profile with StartTLS doesn’t support client-certificate-verify.
-4315SMTP profile with StartTLS doesn’t support client-sni-required.
-4316The profile is associate with a virtual server. You cannot change its starttls-active-mode.
-4317Pagespeed is not supported by this VS.
-4318Page control regular expression is invalid.
-4319Resource control regular expression is invalid.
-4320HSM register failed.
-4321The imported HSM server certificate is invalid.
-4322Can’t assign application id on partition, please check HSM.
-4323HSM Partition is required.
-4324HSM is disabled. Enable it first.
-4325A management port can’t be HSM outgoing interface and vice versa.
-4326RSA only if HSM is using.
-4327Interface primary ip must be set.
-432860F doesn’t support HSM now.
-4329Diagnosis HSM partition failed.
-4330Maximum partition number is reached
-4331HSM is registered with this interface, please unregisetr it before making change
-4332Server ip is required
-4333Interface with LOOPBACK/DHCP type or PPPOE mode is not supported
-4334No client certificate! Use execute command to generate it.
-4335Fail to create HSM client certificate
-4336HSM unregister failed.
-4350The origin-host must be a valid FQDN.
-4351The origin-realm must be a valid domain name.
-4352The origin-host in profile can not equal the one in health check.
-4360This SSL parameter isn’t allowed by HTTP/2, see RFC7540 Appendix A for more detail.
-4361This virtual server type not support by HTTP/2.
-4362The specified IP is conflict with IP address/range of static NAT.
-4370The RDP profile doesn’t support pagespeed.
-4371The DNS profile doesn’t support paegspeed.
-4372The SMTP profile doesn’t support paegspeed.
-4373The pagespeed doesn’t support the non standalone VS.
-4374The pagespeed doesn’t support http once only profile.
-4375The profile is associating with a virtual server. You can not change its MySQL mode.
-4381Cannot delete default intermediate ca group.
-4382Invalid intermediate ca group.
-4383IP address must not be 0.0.0.0,::, 255.255.255.255, ffff:ffff:ffff:ffff:ffff:ffff:ffff:ffff etc.
-4384Proxy server port must not be 0.
-4390IDP file format is not correct.
-4395A challenge token is required.
-4396Input token is invalid.
-4399Only local and NTLM member is allowed if authentication method is NTLM
-4400Disable wildcard before changing authentication type to local
-4401Remote server is currently used by wildcard authentication
-4402Non-wildcard admin is referenced to this remote server
-4410restore of entire configuration required because the origianl configuration has scripts, error pages, …
-4412The Source IP Pool is conflict from other virtual server.
-4413AV profile is not supported.
-4414The name of overlay tunnel conflict with a interface name
-4415HealthCheck List cannot be empty
-4416only IPv4 unicast address can be set as destination IPs
-4417Can’t change settting before empty remote-host table
-4418only one IPv4 multicast address can be set as destination IP
-4419Renegotiation interval value is not valid.
-4420the vtep of host can’t be multicast
-4421multicast is not support by nvgre
-4422duplicate vni with other overlay-tunnel
-4423Renegotiation period value is not valid.
-4424the outgoing interface is used by others
-4425Cannot change the vdom of the interface
-4426Invalid OCI key
-4427The virtual servers can not have real servers with same address and port
-4430The maximum of clone pool member has been reached
-4432The clone pool is not supported with IPv6 address
-4433The clone pool is not supported with specified profile
-4434The clone pool is not supported with specified packet forward method and clone traffic type
-4440The addr type of the server pool is not IPv4
-4441The number of wvs task is out of range
-4442This pool is referenced by wvs profile. The addr type of this pool should be IPv4
-4443The report is not found
-4444The spaces is not enough to preview the report
-4445The regex is not valid
-4446The url pattern match our scanner signature, sfi9876
-4450Read certificate file failed
-4451Certificate type not recognized
-4452Chained cert contained in the file
-4453Certificate key type not recognized
-4454Input value empty
-4455Create tmp file failed
-4456Invalid OCSP response
-4457OCSP response does not match local and issuer
-4458Invalid certificate
-4459Not a CA certificate
-4460Failed to store the private key
-4461Invalid key
-4462Invalid CRL
-4463Duplicate cert or key file
-4464Key file exists, need delete first
-4465Cert forming file path failed
-4466Cert file in the new path doesnot exist
-4480client-address of SIP profile only works on UDP protocol at server side
-4481The profile is associate with a virtual server. You cannot change its protocol.
-4500Failed to create temporary file
-4501Failed to backup to temporary file
-4502Failed to read backup file
-4503File already exist
-4504Failed to set Virtual domain
-4505TFTP sending failed
-4506Name is over length limit
-4507File number is over limit
-4508File is over size limit
-4509Init ssh2 library failed
-4510Create socket failed
-4511Failed to connect
-4512Session init failed
-4513Failure establishing SSH session
-4514Unable to open file with SFTP
-4515Scp transaction failed
-4516Unable to init SFTP session
-4530The uploaded file can not contain any .php file!
-4531File must contain a html file named index.html!
-4535Disable CM Agent before making any change
-4540Invalid password or file error
-4560Secret length is no more than 64
-4570Can’t use multi-pipes
-4571Pipe cannot be used here
-4600FortiCloud internal error
-4601Please log in using the email address you used to create the FortiCloud account
-4602Invalid user name or password
-4603Account already exists
-4604Username too long
-4605Password too long
-4606The report could not be retrieved from FortiCloud
-4607Error retrieving FortiCloud license agreement
-4608Error connecting to FortiCloud
-4609Error activating FortiCloud certificate
-4610Certificate already activated
-4611Certificate has been disabled
-4612Certificate has expired
-4613Invalid certificate number
-4614Please register with FortiCare before activating your FortiCloud certificate
-4615FortiCare runtime error
-4616Tunneling server is unreachable
-4617Login tunneling server failed
-4640rs profile is used by AD FS proxy, ssl must be enable
-4641Invalid adfs pool
-4642SSL of this pool should be on
-4643AD FS need real server SSL certificate
-4644AD FS proxy is disabled
-4645AD FS Proxy not found
-4646AD FS published external URL is not valid(example:https://aaa/bbb/)
-4647AD FS published backend URL is not valid(example:https://aaa/bbb/)
-4648AD FS proxy has at least one published service
-4649SSL sni forward flag is not enabled
-4650AD FS pool and real server pool are same
-4651AD FS relying party is invalid
-4652AD FS publish is being used
-4653AD FS only used for HTTPS
-4654AD FS only used for layer7
-4655AD FS publish service is disabled
-4656AD FS need sni forward
-4657AD FS virtual server must use port 443
-4658AD FS publish external URL duplicate
-4659AD FS publish backend server URL duplicate
-4661AD FS relying party proxy name not found
-4662AD FS relying party has been deleted
-4663AD FS relying party can not be editted
-4664config sync bind port error
-4670Invalid IPS value
-4800traffic sort type unmatch
-4801slb submodule unmatch
-4802NEED SET FILTER
-4810snmp custom health-check is empty
-4811Can’t remove all members of snmp custom health-check, when it is used
-4812One click GSLB server url should begin with ‘https://‘.
-4813’ ’ space is not allowed in one click GSLB server email address.
-4814’@’ is only allowed appears once in one click GSLB server email address.
-4815’ ’ space is not allowed in one click GSLB server url.
-4820Min memory size exceeds maximum memory size or not
-4840local cert format invalid
-4841issuer cert format invalid
-4842issuer and local cert are not match
-4843config file size is out of range
-4860SNI value invalid
-4861real sever pool ssl versions are not continuous.
-4862client ssl no shared cipher for SSL versoin and cipher suite.
-4863backend ssl no shared cipher for SSL versoin and cipher suite.
-4864real server ssl no shared cipher for SSL versoin and cipher suite.
-4865server ssl no shared cipher for SSL versoin.
-4866client ssl no shared cipher for SSL versoin, cipher suite and cert type(RSA|ECDSA).
-4867client verify group no member
-4868Real Server SSL Supported Groups have no FFDHExxx
-4869Real Server SSL enabled RFC7919 Comply but no DHE ciphers
-4870Real Server SSL Supported Groups have no EC curve
-4871Real Server SSL add EC curve in Supported Groups but no ECDHE ciphers
-4872Real Server SSL RFC7919 Comply can not support TLS 1.3
-4873Real Server SSL RFC7919 Comply can not support SSLv3
-4880Cannot enable Source Address and Dynamic Auth at the same time
-4890not a valid hex string, should be characters among 0-9a-fA-F and not end with 00
-4891The number of iso8583 bitmap list reach limitation
-4892The header length should equal or larger than the sum of length-indicator-shift and length-indicator-size
-4900Invalid Input
-4901Server is offline
-4902Failed to revert file
-4903The two versions are identical in content
-4904Base DN is empty
-4905Bind DN is empty
-4910No report-uri directive in policy when report-only is enabled
-4911No duplicated header name allowed in Add-Replace or Add-If-Absent mode
-4912URL regular expression is invalid.
Error CodeError Message
-5001The attack log size is not between 0~10 percent total hard disk size
-5002Exception rule IP mask should be <1 ~ 32>.
-5003Host is invalid.
-5004URL is invalid.
-5005Name is invalid.
-5006Value is invalid.
-5010Duplicate rule
-5011Duplicate user
-5012Can’t change API Key for the user
-5013Can’t change UUID for the user
-5030The virtual path is conflict with other configure’s vpath, please check the related VS’s error page, custom auth form base, captcha profile and SAML configure.
-5031This virtual server has conflict virtual path, please check error page, custom auth form base, captcha profile and SAML configure.
-5050The captcha profile mustn’t be NULL, please select a captcha profile.
-5100Insufficient FortiToken Cloud service points.
-5101Invalid email.
-5102Require mobile number.
-5103Invalid mobile number.
-5104FortiADC connect to cloud server error.
-5105Server error.
-5106Unknown error.
-5107Need token.
-5108Invalid token.
-5109FTM check timeout
-5110Not support ftm push
-5111Local user two-factor is enabled. Disable it first
-5200The listen port(http, https, ssh or telnet) of the IPv4 interface address is used by other.
-5201The listen port(http, https, ssh or telnet) of the IPv6 interface address is used by other.
-5202The listen port(http, https, ssh or telnet) of the floating address is used by other.
-5203The listen port(http, https, ssh or telnet) of the secondary address is used by other.
-5204The listen port(http, https, ssh or telnet) of the secondary floating address is used by other.
-5205The listen port(http, https, ssh or telnet) of the HA node address is used by other.
-5206The listen port(http, https, ssh or telnet) of the HA node secondary address is used by other.
-5207The listen port(http, https, ssh or telnet) of the HA mgmt address is used by other.
-5220SNMP listen port of the IPv4 interface address is used by other.
-5221SNMP listen port of the IPv6 interface address is used by other.
-5222SNMP listen port of the floating address is used by other.
-5223SNMP listen port of the secondary address is used by other.
-5224SNMP listen port of the secondary floating address is used by other.
-5225SNMP listen port of the HA node address is used by other.
-5226SNMP listen port of the HA node secondary address is used by other.
-5227SNMP listen port of the HA mgmt address is used by other.
-5230Explicit HTTP VS must a L7 type VS.
-5240The direct route ip of pool is not consistent with related virtual server ip
-5241The health check type is not supported in direct-route mode.
-5242The direct-route pool is referenced by a non direct-route virtual server.
-5300oauth redirect url must start with ’/‘
-5301oauth logout url must start with ’/‘
-5302oauth path can’t be ’/‘
-5303oauth auth url must start with ‘https://‘
-5304oauth token url must start with ‘https://‘
-5305auth path conflict with oauth redirect url
-5331Must configure password when username is set.
-5332Must configure username when password is set.
-5333Can’t change status. The external resource is in use.
-5999SSLi re-encryption ssl profile used by L2/L3 should not set SNI
Error CodeError Message
-6001SSLi re-encryption real server ssl should enable
-6002SSLi decryption real server pool member is more than 1
-6003SSLi re-encryption real server pool member is more than 1
-6004SSLi instance only support at most 8 port ranges.
-6005SSLi instance port should be a number or a range with ’-‘.
-6006SSLi instance port should be 0 or 1-65535, and port start should be no larger than port end.
-6007The specified decryption ip|port is already used by another SSLi instance decryption.
-6008The specified decryption ip|port is already used by another SSLi instance re-encryption.
-6009The specified re-encryption ip|port is already used by another SSLi instance decryption.
-6010The specified re-encryption ip|port is already used by another SSLi instance re-encryption.
-6011L2 bind interface conflict.
-6012SSLi mode already enabled
-6013SSLi mode enable failed
-6014SSLi mode already disabled
-6015SSLi mode disable failed
-6016SSLi inbound interface is not soft switch for L2 topology
-6017SSLi outbound interface is not the member of decryption soft-switch
-6018SSLi L7 should not enable forward proxy
-6019The specified decryption and re-encryption ip|port is conflict.
-6020The decryption pool of L2/L3 SSLi instance can’t support ipv6.
-6021The encryption pool of L2/L3 SSLi instance can’t support ipv6.
-6022The addr type of decryption pool and of SSLi instance are not match.
-6023The addr type of encryption pool and of SSLi instance are not match.
-6024The alert and policy type are not match.
-6025policy only need one alert member.
-6026alert member has duplicated events.
-6027alert policy has not alert member.
-6028Input a domain name without a ’.’ at the beginning.
-6029Vdom-link entry can’t be deleted, move the interface to root vdom firstly.
-6030The device memory is too low to support RAM disk.
-6031Ramdisk size has been changed, the specified space will be occupied by anti-virus scanning, please reboot the device to take effect.
-6032It is enabled.
-6033Disable private key encription first.
-6034FTP profile requires security when setting client ssl profile.
-6035FTP profile with secutiy doesn’t support forward-proxy
-6036FTP profile with secutiy doesn’t support TLSv1.3
-6037There is a conflict between client ssl profile and the profile type, FTP profile with security require local-certificate-group.
-6038FTP profile with security doesn’t support client-certificate-verify.
-6039FTP profile with security doesn’t support client-sni-required.
-6040FTP profile with security doesn’t support reject-ocsp-stapling-with-missing-nextupdate.
-6041FTP profile with security doesn’t support renegotiation.
-6042FTP profile with security doesn’t support ssl-dynamic-record-sizing.
-6043FTP profile with security should set persistence.
-6044FTP profile with security should set client ssl profile.
-6045The NF SNAT range is conflict with VS ippool.
-6046L4 FTP VS doesn’t support client ssl profile.
-6047The alert and policy filter scope are not match.
-6048L4 FTP VS doesn’t support FTP SSL.
-6049Once SameSite is set to None, Secure attribute must also be enabled.
-6050The custom attribute value does not seem to be formatted correctly.
-6051The cookie keyword shall be a valid cookie name.
-6052The custom attribute value is missing while the option is enabled.
-6053The cookie domain does not seem to be formatted correctly.
-6054The license is a trial license.
-6055The FortiADC license does not support EMS related feature.
-6056Invalid IP address or vs name filter for the WAF blocked IP.
-6057Failed to release WAF blocked IP with provided contitions.
-6058Can’t change vdom mode, please disable vdom first.
-6059Please delete all VS configuration in this vdom.
-6070Only port1 is allowed in current design
-6071FortiADC is not in any cloud autoscaling group
-6072Life cycle state of FortiADC is not InService
-6073HA is enabled. Please disable it first.
-6074Auto-scale is enabled or the FAD is currently in ASG. Please disable auto-scale or detach the FAD from ASG.
-6075The keyword shall be a valid header name.
-6076The keyword shall be a valid URL parameter name.
-6077Oversize Limit is too big. Without AV RAM disk setting, the range is 1-1200.
-6078Oversize Limit is too big. This size cannot exceed the size of AV RAM disk size.