Authentication fails to RSA Authentication Manager 8.x with Cisco Adaptive Security Appliance 9.8 (2) using native SecurID protocol
Originally Published: 2018-06-15
Last Modified: 2026-05-13
Article Number
Applies To
RSA Product: Authentication Manager
RSA Version/Condition: 8.x
Platform (Other): Cisco Adaptive Security Appliance 9.8 (2)
Issue
- Unable to authenticate to RSA Authentication Manager 8.x servers from Cisco Adaptive Security Appliance using native SecurID protocol.
- The software version running on the Cisco Adaptive Security Appliance is 9.8 (2).
- Error seen as authentication failed on the Cisco Adaptive Security Appliance command line prompt.
- Communication packets between the Cisco agent and Authentication Manager server was verified by performing a tcpdump on the primary Authentication Manager appliance.
- No error log entries were seen on the Authentication Manager server real time activity monitor after performing a couple of authentications from the Cisco Adaptive Security Appliance over UDP port 5500.
Cause
-
The exact cause for the Native SecurID authentications to fail over the port UDP 5500 when authenticating from the Cisco Adaptive Security Appliance 9.8 (2) is yet to be identified.
-
However, this looks like an incompatibility issue with RSA Authentication Manager 8.x and Cisco ASA running version 9.8 (2) specifically
- Below is the snippet.of the version information from theCisco ASA:
Cisco Adaptive Security Appliance Software Version 9.8(2) Firepower Extensible Operating System Version 2.2(2.52) Device Manager Version 7.8(2)
Workaround
Use RADIUS protocol as an alternative protocol to native SecurID protocol by creating the Cisco Adaptive Security Appliance as a RADIUS client on the Authentication Manager server.
Review the article on how to Add a RADIUS Client Agent for the ASA.
Notes
Related Articles
The importDescriptions Web Service requires System Administration privilege in RSA Identity Governance & Lifecycle 7.0.2 a… 10Number of Views Support the use of OAuth 2.0 tokens for the RSA Identity Governance & Lifecycle Web Service API 73Number of Views How to determine if RSA Access Manager IIS agent is deployed as an ISAPI filter or a MODULE? 24Number of Views How to set user RADIUS profile to include Cisco vendor-specific DNS servers (primary and secondary) 44Number of Views Determining if the RSA Authentication Manager 8.x install platform is hardware or virtual 56Number of Views
Trending Articles
How to manipulate imported RSA SecurID Software Token(s) on an iPhone or iPad device Reporting on RSA Authentication Manager 8.x users with On-Demand Token, a fixed passcode or a hardware/software token assi… How to Download OTP Token Seed Files from myRSA Anomalix idGenius - SAML Relying Party Configuration - RSA Ready Implementation Guide RSA MFA Agent 2.5 for Microsoft Windows Installation and Administration Guide
Don't see what you're looking for?