Skip to main content

Agent Error Codes

Palo Alto

200000 - Target Firewall Not Connected to Panorama

This error occurs when the Knocknoc agent attempts to refresh an External Dynamic List (EDL) on a...

200050 - Username Mapping Failed

Agent error code #200050 occurs when the Knocknoc agent attempts to map a username to an IP addre...

200100 - Failed to Check if Address Exists

Agent error code #200100 indicates that the Knocknoc agent was unable to verify whether an addres...

200101 - Failed to Create Address Object

Agent error code #200101 indicates that the Knocknoc agent was unable to create an address object...

200102 - Failed to Get Address Group Members

This error indicates that the Knocknoc agent was unable to retrieve the current members of an add...

200103 - Failed to Add Address to Group

Agent error code #200103 indicates that the Knocknoc agent was unable to update an address group ...

200105 - Failed to Remove Address from Address Group

This error indicates that the Knocknoc agent was unable to update an address group on the Palo Al...

200106 - Failed to Delete Address Object

This error indicates that the Knocknoc agent was unable to delete an address object from the Palo...

200107 - Address Group Not Found

Agent error code #200107 means the address group named on the knoc is not on the Palo Alto Networ...

200150 - Failed to Register Tag

Agent error code #200150 occurs when the Knocknoc agent asks a Palo Alto Networks firewall to reg...

200151 - Failed to Unregister Tag

Agent error code #200151 occurs when a Knocknoc grant ends and the agent asks a Palo Alto Network...

200152 - Firewall Busy or Rate Limited

Agent error code #200152 means the Palo Alto Networks firewall turned a User-ID update away becau...

200153 - Target Firewall Not Connected (User-ID)

Agent error code #200153 means Knocknoc sent an IP-tag registration through Panorama for a specif...

200154 - Tag Timeout Out of Range

Agent error code #200154 means the Palo Alto Networks firewall rejected the timeout Knocknoc set ...

200155 - Virtual System Not Found (User-ID)

Agent error code #200155 means the Palo Alto Networks firewall does not have the virtual system t...

200156 - User-ID Authentication Failed

Agent error code #200156 means the Palo Alto Networks firewall or Panorama rejected the API key K...

200157 - User-ID Authorization Failed

Agent error code #200157 means the API key Knocknoc presented is valid, but the administrator it ...

200158 - Registered IP Limit Reached

Agent error code #200158 means the Palo Alto Networks firewall refused a User-ID registration bec...

200200 - Failed to Check HA State

Agent error code #200200 means the Knocknoc agent could not find out which firewall in an HA pair...

200201 - Neither Firewall in the HA Pair Is Active

Agent error code #200201 means both firewalls in the HA pair answered the Knocknoc agent and neit...

Sonicwall

Fortinet

202000 - Failed to Connect to Fortinet Device

Agent error code #202000 indicates that the agent could not establish a connection to the Fortine...

202001 - Fortinet Authentication Failed

Agent error code #202001 indicates that the agent was unable to authenticate with a Fortinet devi...

202002 - Fortinet Authorization Failed

Agent error code #202002 indicates that the agent authenticated successfully with the Fortinet de...

202003 - Fortinet TLS/SSL Certificate Error

Agent error code #202003 indicates that the agent could not establish a secure connection to the ...

202004 - Fortinet Connection Timed Out

Agent error code #202004 indicates that the agent attempted to connect to the Fortinet device but...

202050 - Failed to Update Trusted Host

Agent error code #202050 indicates that the agent could not update the trusted host entry on a Fo...

202051 - Admin User Not Found on FortiManager

Agent error code #202051 indicates that the agent attempted to update a trusted host entry for a ...

202100 - Failed to Push Dynamic Entry to FortiGates

Agent error code #202100 indicates that the agent could not push a dynamic entry (IP address add ...

202101 - Target Device or Group Not Found

Agent error code #202101 indicates that the agent attempted to push a dynamic entry to FortiGates...

202102 - External Feed Name Not Found on Target FortiGates

Agent error code #202102 indicates that the agent pushed a dynamic entry update to the target For...

202150 - Invalid or Unexpected Response from Fortinet Device

Agent error code #202150 indicates that the Fortinet device returned a response that the agent co...

202120 - ADOM Not Found on FortiManager

Agent error code #202120 indicates that the ADOM configured on the knoc does not exist on FortiMa...

202121 - Device Not Registered in the ADOM

Agent error code #202121 indicates that the target device is not present in the ADOM the knoc is ...

202122 - Address Group Not Found on FortiGate

Agent error code #202122 indicates that the address group named on the knoc does not exist on the...

202123 - FortiOS Version Does Not Support the Monitor Endpoint

Agent error code #202123 indicates that the FortiOS running on the target device does not provide...

Gcp

Nginx

Pfsense

PFS000 - Failed to Connect to pfSense

Agent error code #PFS000 indicates that the agent could not reach the pfSense REST API at all. Th...

PFS001 - pfSense Authentication Failed

Agent error code #PFS001 indicates that the pfSense REST API rejected the credentials provided by...

PFS002 - pfSense Authorization Failed

Agent error code #PFS002 indicates that the agent authenticated to pfSense successfully but the A...

PFS003 - pfSense TLS/SSL Certificate Error

Agent error code #PFS003 indicates that the agent could not verify the TLS certificate presented ...

PFS004 - pfSense Connection Timed Out

Agent error code #PFS004 indicates that a pfSense API call did not complete within the agent's ti...

PFS005 - pfSense REST API Package Not Installed

Agent error code #PFS005 indicates that the agent connected to pfSense successfully but the pfRes...

PFS100 - Failed to Get pfSense Alias

Agent error code #PFS100 indicates that the request to read the alias from pfSense failed. This l...

PFS101 - Failed to Create pfSense Alias

Agent error code #PFS101 indicates that the agent attempted to create a new alias on pfSense (bec...

PFS102 - Failed to Update pfSense Alias

Agent error code #PFS102 indicates that the agent attempted to update an existing alias on pfSens...

PFS103 - pfSense Alias Not Found

Agent error code #PFS103 indicates that the alias name configured in the Knocknoc ACL does not ex...

PFS200 - Failed to Apply Pending pfSense Firewall Changes

Agent error code #PFS200 indicates that the alias was updated successfully but the subsequent app...

PFS400 - Invalid or Unexpected Response from pfSense

Agent error code #PFS400 indicates that the agent received a response from pfSense that it could ...

Opnsense

OPN000 - OPNsense Authentication Failed

Agent error code #OPN000 indicates that the OPNsense API rejected the credentials provided by the...

OPN001 - OPNsense Authorization Failed

Agent error code #OPN001 indicates that the agent authenticated with OPNsense successfully, but t...

OPN002 - OPNsense Request Timed Out

Agent error code #OPN002 indicates that an OPNsense API call did not complete within the agent's ...

OPN003 - OPNsense TLS Certificate Error

Agent error code #OPN003 indicates that the agent could not verify the TLS certificate presented ...

OPN004 - Connection Refused by OPNsense

Agent error code #OPN004 indicates that the OPNsense host actively refused the connection from th...

OPN005 - Cannot Resolve OPNsense Hostname

Agent error code #OPN005 indicates that the agent host could not resolve the OPNsense hostname to...

OPN006 - OPNsense Request Failed

Agent error code #OPN006 is the fallback code for OPNsense API errors that don't match a more spe...

OPN100 - OPNsense Alias Not Found

Agent error code #OPN100 indicates that the alias name configured in the Knocknoc ACL does not ex...

OPN101 - Failed to Read OPNsense Alias Contents

Agent error code #OPN101 indicates that the agent could reach the alias listing endpoint on OPNse...

OPN102 - Failed to Add Entry to OPNsense Alias

Agent error code #OPN102 indicates that OPNsense rejected an attempt to add an entry to the confi...

OPN103 - Failed to Remove Entry from OPNsense Alias

Agent error code #OPN103 indicates that OPNsense rejected an attempt to remove an entry from the ...

OPN200 - Failed to Apply OPNsense Alias Changes

Agent error code #OPN200 indicates that the alias entry was added or removed successfully, but th...

Generic External Object Refresh Errors

Generic Agent Errors

MikroTik

Okta

OKTA000 - Failed to Connect to Okta

Agent error code #OKTA000 indicates that the agent could not reach the Okta REST API at the confi...

OKTA001 - Okta Authentication Failed

Agent error code #OKTA001 indicates that the Okta API rejected the API token in the agent's Auth...

OKTA002 - Okta Authorization Failed

Agent error code #OKTA002 indicates that the Okta API authenticated the agent's token but rejecte...

OKTA003 - Okta TLS/SSL Certificate Error

Agent error code #OKTA003 indicates that the agent's TLS handshake with the configured Okta domai...

OKTA004 - Okta Connection Timed Out

Agent error code #OKTA004 indicates that a request to the configured Okta domain did not complete...

OKTA005 - Okta API Rate Limit Exceeded

Agent error code #OKTA005 indicates that Okta rejected the request with HTTP 429 Too Many Request...

OKTA050 - Failed to Get Okta Network Zone

Agent error code #OKTA050 indicates that the agent could not retrieve the configured network zone...

OKTA051 - Failed to Update Okta Network Zone

Agent error code #OKTA051 indicates that the agent retrieved the network zone successfully but th...

OKTA052 - Okta Network Zone Not Found

Agent error code #OKTA052 indicates that Okta returned HTTP 404 for the configured Network Zone I...

OKTA053 - Okta Network Zone Is Not an IP Zone

Agent error code #OKTA053 indicates that the configured network zone exists, but its type is not...

OKTA054 - Invalid or Unexpected Response from Okta

Agent error code #OKTA054 indicates that Okta returned a 2xx status, but the response body did no...

Entra

ENTRA000 - Failed to Connect to Microsoft Graph

Agent error code #ENTRA000 indicates that the agent could not reach Microsoft Graph at https://g...

ENTRA001 - Microsoft Entra Authentication Failed

Agent error code #ENTRA001 indicates that the Microsoft identity platform rejected the credential...

ENTRA002 - Microsoft Entra Authorization Failed

Agent error code #ENTRA002 indicates that the agent authenticated to Entra ID successfully but Mi...

ENTRA003 - Microsoft Graph TLS/SSL Certificate Error

Agent error code #ENTRA003 indicates that the agent's TLS handshake with login.microsoftonline.c...

ENTRA004 - Microsoft Graph Connection Timed Out

Agent error code #ENTRA004 indicates that a request to login.microsoftonline.com or graph.micro...

ENTRA005 - Microsoft Graph API Throttled

Agent error code #ENTRA005 indicates that Microsoft Graph rejected the request with HTTP 429 Too ...

ENTRA050 - Failed to Get Entra Named Location

Agent error code #ENTRA050 indicates that the agent could not retrieve the configured Named Locat...

ENTRA051 - Failed to Update Entra Named Location

Agent error code #ENTRA051 indicates that the agent retrieved the Named Location successfully but...

ENTRA052 - Entra Named Location Not Found

Agent error code #ENTRA052 indicates that Microsoft Graph returned HTTP 404 for the configured Na...

ENTRA053 - Entra Named Location Is Not an IP-Based Location

Agent error code #ENTRA053 indicates that the configured Named Location exists, but its @odata.t...

ENTRA054 - Invalid or Unexpected Response from Microsoft Graph

Agent error code #ENTRA054 indicates that Microsoft Graph returned a 2xx status, but the response...

Checkpoint

CHKP000 - Failed to Connect to Check Point Gateway

Agent error code #CHKP000 indicates that the Knocknoc agent could not open a network connection t...

CHKP001 - Check Point Connection Timed Out

Agent error code #CHKP001 indicates that the Knocknoc agent reached the network path to the Check...

CHKP002 - Check Point TLS/SSL Certificate Error

Agent error code #CHKP002 indicates that the Knocknoc agent opened a connection to the Check Poin...

CHKP003 - Check Point Authentication Failed

Agent error code #CHKP003 indicates that the Check Point gateway rejected the shared secret the K...

CHKP004 - Check Point Source IP Not Authorized

Agent error code #CHKP004 indicates that the Check Point gateway recognized the shared secret but...

CHKP005 - Check Point Request Refused

Agent error code #CHKP005 indicates that the Check Point gateway refused the request with a bare ...

CHKP050 - Failed to Push Identity to Check Point Gateway

Agent error code #CHKP050 indicates that the Knocknoc agent's request to register a user's identi...

CHKP051 - Failed to Remove Identity from Check Point Gateway

Agent error code #CHKP051 indicates that the Knocknoc agent's request to remove a user's identity...

CHKP052 - Check Point Access Role Not Found

Agent error code #CHKP052 indicates that the Access Role configured on the Knoc does not correspo...

CHKP053 - Identity Awareness Blade Not Enabled

Agent error code #CHKP053 indicates that the Check Point gateway's response showed the Identity A...

CHKP054 - Session Timeout Below Gateway Minimum

Agent error code #CHKP054 indicates that the per-identity session timeout Knocknoc sent with the ...

CHKP400 - Invalid Response from Check Point Gateway

Agent error code #CHKP400 indicates that the Knocknoc agent received a response from the configur...

CHKP401 - Check Point Gateway Server Error

Agent error code #CHKP401 indicates that the Check Point gateway returned a server error (HTTP 5x...

Proxmox

Agent error codes for the Proxmox VE backend.

PROX000 - Proxmox Authentication Failed

Agent error code #PROX000 indicates that Proxmox VE rejected the API token provided by the agent....

PROX001 - Proxmox Authorization Failed

Agent error code #PROX001 indicates that the Proxmox API authenticated the token successfully but...

PROX002 - Proxmox Did Not Respond In Time

Agent error code #PROX002 indicates that the agent connected to Proxmox VE but the cluster did no...

PROX003 - Proxmox TLS Certificate Error

Agent error code #PROX003 indicates that the agent could not establish a trusted TLS connection t...

PROX004 - Connection Refused By Proxmox

Agent error code #PROX004 indicates that the agent reached the Proxmox host but the connection to...

PROX005 - Failed To Resolve Proxmox Hostname

Agent error code #PROX005 indicates that the agent could not resolve the Proxmox hostname in the ...

PROX006 - Proxmox Request Failed

Agent error code #PROX006 indicates that a request to the Proxmox VE API failed at the network la...

PROX100 - Proxmox Ipset Not Found

Agent error code #PROX100 indicates that the ipset configured in the Knocknoc ACL does not exist ...

PROX101 - Failed To Read Proxmox Ipset Contents

Agent error code #PROX101 indicates that the agent reached Proxmox VE and the ipset lookup did no...

PROX102 - Failed To Add Entry To Proxmox Ipset

Agent error code #PROX102 indicates that the agent tried to add an IP address to the configured P...

PROX103 - Failed To Remove Entry From Proxmox Ipset

Agent error code #PROX103 indicates that the agent tried to remove an IP address from the configu...

PROX104 - Proxmox Node Or VM Not Found

Agent error code #PROX104 indicates that, for a per-VM (qemu) scoped Knoc, Proxmox VE could not f...

PROX400 - Invalid Response From Proxmox

Agent error code #PROX400 indicates that the agent received a response from Proxmox VE that it co...

Kemp

Agent error codes for the Kemp LoadMaster backend.

KEMP000 - Failed to Connect to Kemp LoadMaster

Agent error code #KEMP000 indicates that Knocknoc could not reach the Kemp LoadMaster API. The co...

KEMP001 - Kemp LoadMaster Authentication Failed

Agent error code #KEMP001 indicates that Knocknoc reached the Kemp LoadMaster but the username or...

KEMP002 - Kemp LoadMaster Authorization Failed

Agent error code #KEMP002 indicates that the credentials authenticated successfully but the user ...

KEMP003 - Kemp LoadMaster TLS/SSL Certificate Error

Agent error code #KEMP003 indicates that Knocknoc could not establish a trusted TLS connection to...

KEMP004 - Kemp LoadMaster Connection Timed Out

Agent error code #KEMP004 indicates that Knocknoc opened or attempted a connection to the Kemp Lo...

KEMP005 - Kemp LoadMaster API Interface Not Enabled

Agent error code #KEMP005 indicates that Knocknoc reached the LoadMaster but the API endpoint was...

KEMP100 - Failed to List Kemp LoadMaster Allowlist

Agent error code #KEMP100 indicates that Knocknoc could not read the global ACL allowlist it is s...

KEMP101 - Failed to Add Kemp LoadMaster Allowlist Entry

Agent error code #KEMP101 indicates that Knocknoc could read the global ACL but the call to add a...

KEMP102 - Failed to Remove Kemp LoadMaster Allowlist Entry

Agent error code #KEMP102 indicates that Knocknoc could read the global ACL but the call to remov...

KEMP400 - Invalid Response From Kemp LoadMaster

Agent error code #KEMP400 indicates that Knocknoc reached the Kemp LoadMaster and received a resp...

F5

F5000 - Failed to Connect to F5 BIG-IP

Agent error code #F5000 indicates that the Knocknoc agent could not establish a network connectio...

F5001 - F5 BIG-IP Authentication Failed

Agent error code #F5001 indicates that the F5 BIG-IP rejected the username and password supplied ...

F5002 - F5 BIG-IP Authorization Failed

Agent error code #F5002 indicates that the F5 BIG-IP accepted the credentials but the user's role...

F5003 - F5 BIG-IP TLS/SSL Certificate Error

Agent error code #F5003 indicates that the TLS handshake with the F5 BIG-IP management endpoint f...

F5004 - F5 BIG-IP Connection Timed Out

Agent error code #F5004 indicates that a request to the F5 BIG-IP management endpoint did not com...

F5005 - Failed to Obtain an F5 BIG-IP Authentication Token

Agent error code #F5005 indicates that the login request to /mgmt/shared/authn/login did not ret...

F5050 - Failed to Read the F5 Data-Group

Agent error code #F5050 indicates that the agent authenticated successfully but the GET request f...

F5051 - F5 Data-Group Not Found

Agent error code #F5051 indicates that the internal data-group named in the Knocknoc backend does...

F5052 - F5 Data-Group Is Not an Address (ip) Type

Agent error code #F5052 indicates that the configured data-group exists, but it is not an Address...

F5053 - Failed to Update the F5 Data-Group

Agent error code #F5053 indicates that the PATCH request to update the data-group's records faile...

F5400 - Invalid or Unexpected Response from F5 BIG-IP

Agent error code #F5400 indicates that the F5 BIG-IP returned a response the agent could not inte...

Cloudflare IP Lists

Meraki

MERA000 - Failed to Connect to the Meraki Dashboard

Agent error code #MERA000 indicates the agent could not establish a connection to the Meraki Dash...

MERA001 - Meraki Authentication Failed

Agent error code #MERA001 indicates the Meraki Dashboard rejected the API key in the agent's Aut...

MERA002 - Meraki Authorization Failed

Agent error code #MERA002 indicates the API key authenticated successfully but is not authorized ...

MERA003 - Meraki Dashboard TLS/SSL Certificate Error

Agent error code #MERA003 indicates a TLS/SSL certificate error while connecting to the Meraki Da...

MERA004 - Meraki Dashboard Connection Timed Out

Agent error code #MERA004 indicates a request to the Meraki Dashboard did not complete within the...

MERA005 - Meraki Dashboard API Rate Limit Exceeded

Agent error code #MERA005 indicates the Meraki Dashboard API rate-limited the agent (HTTP 429). T...

MERA050 - Failed to Read the Meraki Organization

Agent error code #MERA050 indicates the agent could not read the configured Meraki organization. ...

MERA100 - Failed to Read the Meraki Policy Object Group

Agent error code #MERA100 indicates the agent could not read the configured policy object group. ...

MERA101 - Failed to Update the Meraki Policy Object Group

Agent error code #MERA101 indicates the agent could not update the membership of the configured p...

MERA102 - Meraki Policy Object Group Not Found

Agent error code #MERA102 indicates the configured policy object group could not be found (HTTP 4...

MERA150 - Failed to Create a Meraki Policy Object

Agent error code #MERA150 indicates the agent could not create the CIDR policy object for a grant...

MERA151 - Failed to Delete a Meraki Policy Object

Agent error code #MERA151 indicates the agent removed an object from the group but could not dele...

MERA152 - Failed to Read a Meraki Policy Object

Agent error code #MERA152 indicates the agent could not read a policy object referenced by the co...

MERA400 - Invalid Response from the Meraki Dashboard

Agent error code #MERA400 indicates the Meraki Dashboard returned a response the agent could not ...

IPSet

Agent error codes raised by the IPSet backend.

Fastly

Agent error codes for the Fastly ACL backend (FSTL000-FSTL999).

FSTL001 - Fastly Authentication Failed

Agent error code #FSTL001 indicates Fastly rejected the API token in the agent's Fastly-Key head...

FSTL002 - Fastly Authorization Failed

Agent error code #FSTL002 indicates the API token authenticated but is not allowed to act on the ...

FSTL003 - Fastly API TLS Error

Agent error code #FSTL003 indicates the TLS handshake with the Fastly API failed: the certificate...

FSTL005 - Fastly API Rate Limit Exceeded

Agent error code #FSTL005 indicates Fastly answered with HTTP 429: the API token has made too man...

FSTL050 - Failed to Read the Fastly Service

Agent error code #FSTL050 indicates the agent could not read the configured Fastly service. It re...

FSTL051 - Fastly Service Not Found

Agent error code #FSTL051 indicates Fastly answered HTTP 404 for the configured service. Common c...

FSTL052 - The Fastly Service Has No Active Version

Agent error code #FSTL052 indicates the configured service has no active version, so its ACLs are...

FSTL100 - Failed to Read the Fastly ACL

Agent error code #FSTL100 indicates the agent could not list the ACLs on the service's active ver...

FSTL101 - Fastly ACL Not Found

Agent error code #FSTL101 indicates no ACL with the configured name exists on the service's activ...

FSTL150 - Failed to Create the Fastly ACL Entry

Agent error code #FSTL150 indicates Fastly refused to add the entry for a granted address, so the...

FSTL151 - Failed to Delete the Fastly ACL Entry

Agent error code #FSTL151 indicates Fastly refused to remove an entry, so an address may still be...

FSTL152 - Failed to List the Fastly ACL Entries

Agent error code #FSTL152 indicates the agent could not read the ACL's entries. It reads them to ...

FSTL153 - The Fastly ACL Has Reached Its Entry Limit

Agent error code #FSTL153 indicates the ACL is full, so the grant could not be added. Fastly caps...

FSTL000 - Failed to Connect to the Fastly API

Agent error code #FSTL000 indicates the agent could not reach the Fastly API. The connection was ...

FSTL004 - Fastly API Connection Timed Out

Agent error code #FSTL004 indicates the Fastly API did not answer within the agent's timeout. Com...

FSTL400 - Invalid Response From the Fastly API

Agent error code #FSTL400 indicates the API answered successfully but the body was not the JSON t...

AWS

Azure

nftables

Script