> Source: [sk108279](https://support.checkpoint.com/results/sk/sk108279)

# sk108279 - "analyze_ras_urq: failed, couldn't find prior registration" and "analyze_ras_ucf: failed, UCF is out of state" errors in /var/log/messages file

| Property | Value |
|----------|-------|
| Solution ID | sk108279 |
| Date Created | 2015-10-20 |
| Last Modified | 2021-08-20 |
| Technical Level | Advanced |
| Products | Security Gateway |
| Versions | R82.10, R82, R81.20 |

## Symptoms

- */var/log/messages* file on Security Gateway shows the following error messages:

* `analyze_ras_urq: failed, couldn't find prior registration`
* `analyze_ras_ucf: failed, UCF is out of state`

## Cause

These messages are related to H323 traffic and will be displayed if kernel debug of "H323" module is enabled (due to debug flag "error"):

* URQ (Unregister_Request) is sent from endpoint or gatekeeper to cancel registration.
* UCF (Unregister_Confirm) is sent from endpoint or gatekeeper to confirm an unregistration.

The "*analyze_ras_urq: failed, couldn't find prior registration*" is printed if:

* Registration was not found

The "*analyze_ras_ucf: failed, UCF is out of state*" is printed if:

* Either registration was not found,
* Or registration was found, but there is no previous URQ

## Solution

This solution requires authentication. Please log in to view the full solution.

---

# Agent Instructions

This content is from the Check Point Support Center (https://support.checkpoint.com), the official knowledge base for Check Point cybersecurity products.

## Navigating This Knowledge Base

- **Complete index**: [llms.txt](https://support.checkpoint.com/llms.txt)
- **All SK articles**: [SecureKnowledge Sitemap](https://support.checkpoint.com/sitemaps/secureknowledge-sitemap-index.xml)
- **SK article URL pattern**: `https://support.checkpoint.com/results/sk/{skId}`
- **Markdown responses**: AI bot User-Agents automatically receive `text/markdown` content
