Error messages

Prev Next

If the appliance is not configured correctly, it tries to identify the problem and sends a temporary or permanent failure message.

The text in parentheses in the error message provides additional information about the problem.

Some error messages relay the response from the Smart Host so the Trellix DLP Network Prevent – SaaS response contains the IP address, which is indicated by x.x.x.x.

For example, 442 192.168.0.1 : Connection refused indicates that the Smart Host with the address 192.168.0.1 did not accept the SMTP connection.

Temporary failure messages

Text

Cause

Recommended action

451 (The system has not been registered with a server)

The initial setup was not completed.

Register the appliance with a ePO - SaaS server using the Graphical Configuration Wizard option in the appliance console.

451 (No DNS servers have been configured)

The configuration applied from ePO - SaaS did not specify any DNS servers.

Configure at least one DNS server in the General category of the Common Appliance policy.

451 (No Smart Host has been configured)

The configuration applied from ePO - SaaS did not specify a Smart Host.

Configure a Smart Host in the Trellix DLP Network Prevent Email Settings policy category.

451 (Policy OPG file not found in configured location)

The policy configuration applied from ePO - SaaS was incomplete.

  • Configure a Data Loss Prevention policy.

  • Contact Technical Support. The configuration OPG file must be applied with the policy OPG file.

451 (Configuration OPG file not found in configured location)

The configuration applied from ePO - SaaS was incomplete.

  • Make sure that the Data Loss Prevention extension is installed.

  • Configure a Data Loss Prevention policy.

  • Contact Technical Support. The configuration OPG file must be applied with the policy OPG file.

451 ( Active Directory server configuration missing)

This error occurs when both these conditions are met:

  • Trellix DLP Network Prevent – SaaS contains a rule that specifies a sender as a member of an LDAP user group.

  • Trellix DLP Network Prevent – SaaS is not configured to receive group information from the Active Directory server that contains that user group.

Check that the Active Directory server is selected in the Users and Groups policy category.

451 (Error resolving sender based policy)

A policy contains LDAP sender conditions, but can't get the information from the Active Directory server because:

  • Trellix DLP Network Prevent – SaaS and the server have not synchronized.

  • The Active Directory server is not responding.

Check that the Active Directory server is available.

451 (FIPS test failed)

The cryptographic self-tests required for FIPS compliance failed

Contact technical support.

451 (Unable to verify data against the registered document server)

The registered documents server is unavailable.

Check your configuration to confirm that the server is available, and the details you entered are correct.

442 x.x.x.x: Connection refused

Trellix DLP Network Prevent – SaaS could not connect to the Smart Host to send the message, or the connection to Smart Host was dropped during a conversation.

Check that the Smart Host can receive email.



Permanent failure messages

Error

Cause

Action

530 Authentication required

MTA doesn't send AUTH credentials.

Configure MTA to send AUTH LOGIN credentials.

530 Authentication required - AUTH conversation is required for onward delivery

The Smart Host doesn't present AUTH as part of its response to the Trellix DLP Network Prevent – SaaS appliance's EHLO request.

Configure the Smart Host to send AUTH LOGIN credentials.

504 Error: Supported authentication mechanism unavailable for onward delivery

The Smart Host doesn't support the LOGIN mechanism for authentication.

The Smart Host must support the LOGIN mechanism for authentication.

550 Host / domain is not permitted

Trellix DLP Network Prevent – SaaS refused the connection from the source MTA.

Check that the MTA is in the list of permitted hosts in the Trellix DLP Network Prevent Email Settings policy category.

550 x.x.x.x: Denied by policy. TLS conversation required

The Smart Host did not accept a STARTTLS command but Trellix DLP Network Prevent – SaaS is configured to always send email over a TLS connection.

Check the TLS configuration on the host.



ICAP error messages

Error

Cause

Action

500 (Unable to verify data against the registered document server)

The registered documents server is unavailable.

Check your configuration to confirm that the server is available, and the details you entered are correct.

500 ( Active Directory server configuration missing)

This error occurs when both these conditions are met:

  • Trellix DLP Network Prevent – SaaS contains a rule that specifies an end-user as a member of an LDAP user group.

  • Trellix DLP Network Prevent – SaaS is not configured to receive group information from the Active Directory server that contains that user group.

Check that the Active Directory server is selected in the Users and Groups policy category.

500 (Error resolving end-user based policy)

A policy contains LDAP sender conditions, but can't get the information from the Active Directory server because:

  • Trellix DLP Network Prevent – SaaS and the Active Directory server have not synchronized.

  • The Active Directory server is not responding.

Check that the Active Directory server is available.