000033103 - How to configure 2 NICs for RSA Authentication Manager 8.1

Document created by RSA Customer Support Employee on Jun 14, 2016Last modified by RSA Customer Support on Dec 23, 2017
Version 3Show Document
  • View in full screen mode

Article Content

Article Number000033103
Applies ToRSA Product Set: SecurID
RSA Product/Service Type: Authentication Manager
RSA Version/Condition: 8.1
Issue
  • How to access AM authentication services from two different subnets.
  • How to configure Failover for Agent Authentications.
  • How to configure networks to use NIC1 or NIC2 for particular type of traffic.
Tasks
  1. Build AM server with single NIC, eth0, as normal.
  2. The eth0 interface will be the primary NIC, for authentication, administration, and replication.
  3. Backup to a network drive (NFS or Windows share) will go out this interface.
  4. After system works with single NIC, which is fully supported, you can optionally add 2nd NIC, eth1, which can handle authentication requests, might allow backups (not supported) and should not work for either replication or administration.
ResolutionTask 4 - After system is working with single NIC, add second NIC for Authentication failover.
  1. Log into the Operations console and navigate to Administration > Network > Appliance Network Settings.
  2. In the Network Interface Card (NIC) Settings, enable eth1 and do the following:
    1. In the IPv4 Address field, configure the IP address.
    2. In the IPv4 Subnet Mask field, configure the subnet mask.
    3. In the IPv4 Default Gateway field, configure the IP address.
  3. Click Next.
  4. Review the changes you made and Apply Network Settings to accept these changes.
  5. After the services are restarted, log into the Operations console and navigate to Administration > Network > Hosts File.
  6. Update the hosts file with the two IP addresses.
 
    Notes
    • SSH can be enabled on NIC1 (eth0) or NIC2(eth1).
    • Don’t attempt to configure separate FQDN for each IP address.  You will break Administration.
    • If DNS is configured to return both IP addresses AM code doesn’t expect it and won’t take advantage of it and probably will break Administration to Security Console and Self Service Console.
    • RSA recommends using a different subnet for each NIC. If two NICs share the same subnet and one NIC becomes unavailable, then Authentication Manager services will not be available on either NIC.
    • Offline Days, Windows Agent Auto-registration, Replication and Security & Self Service Console Administration are not QE tested on a second NIC, therefore are not supported, only UDP authentication requests are supported.

    Attachments

      Outcomes