000029015 - Why an IP address override can fix an initial authentication failures with RSA Authentication Manager when the error Authentication Method Failed displays

Document created by RSA Customer Support Employee on Sep 6, 2017
IssueAuthentication to a specific agent is failing.  On the  agent side, "Error 13002" may display for a WIndows agent.  
In the authentication activity log, the message is> authentication method failed.

DescriptionUser “<user ID>" attempted to authenticate using authenticator “SecurID_Native”. The user belongs to security domain “<security domain>”
Action Result Key:Failure
Result:Authentication method failed

CauseThis is a classic SecurID problem, compounded by RSA terminology that is less than intuitive.  You have not successfully authenticated from this agent yet, which means the node secret (symmetric encryption key) used between the agent and the Authentication Manager server has not yet been created. To correct the issue,
  1. Launch the Security Console.
  2. Navigate to Access >  Authentication Agents > Manage Existing.  
  1. From the context menu for the agent in question, select Manage Node Secret.
Before the node secret is created, the initial encryption algorithm uses the agent's IP address to complete the authentication request.  The agent encrypts the request with its primary IP address, usually its main IP, but never its NATed IP because it has no idea what that is.  However, we have seen plenty of instances where a secondary IP was used, either from a second NIC, or wireless or sometimes the management IP for VPN type devices.  The problem arises when the Authentication Manager server tries to decrypt the authentication request.  It decrypts using the primary IP address as defined in the agent host record.  See below, where is the real IP address of the agent and is the NATted IP address of the agent in all packets arriving at the Authentication Manager server.

The less than clearly named IP address override forces the agent to encrypt with a specific IP address, not allowing the agent to choose its own primary IP for RSA encryption.
  1. Enter the real IP address, in our example it is, as the IP Address Override on the agent in the RSA Control Center, to match the real IP on the agent host entry on the Authentication  Manager server.
  1. Or use an sdopts.rec text file placed in the same directory as the sdconf.rec file, with an entry like this:
NotesThe output of the/opt/rsa/am/server/logs/imsTrace.log with log level set to verbose:
