Authentication fails to RSA Authentication Manager 8.x with Cisco Adaptive Security Appliance 9.8 (2) using native SecurID protocol
Originally Published: 2018-06-15
Article Number
Applies To
RSA Product: Authentication Manager
RSA Version/Condition: 8.x
Platform (Other): Cisco Adaptive Security Appliance 9.8 (2)
Issue
- Unable to authenticate to RSA Authentication Manager 8.x servers from Cisco Adaptive Security Appliance using native SecurID protocol.
- The software version running on the Cisco Adaptive Security Appliance is 9.8 (2).
- Error seen as authentication failed on the Cisco Adaptive Security Appliance command line prompt.
- Communication packets between the Cisco agent and Authentication Manager server was verified by performing a tcpdump on the primary Authentication Manager appliance.
- No error log entries were seen on the Authentication Manager server real time activity monitor after performing a couple of authentications from the Cisco Adaptive Security Appliance over UDP port 5500.
Cause
-
The exact cause for the Native SecurID authentications to fail over the port UDP 5500 when authenticating from the Cisco Adaptive Security Appliance 9.8 (2) is yet to be identified.
-
However, this looks like an incompatibility issue with RSA Authentication Manager 8.x and Cisco ASA running version 9.8 (2) specifically
- Below is the snippet.of the version information from theCisco ASA:
Cisco Adaptive Security Appliance Software Version 9.8(2) Firepower Extensible Operating System Version 2.2(2.52) Device Manager Version 7.8(2)
Workaround
Use RADIUS protocol as an alternative protocol to native SecurID protocol by creating the Cisco Adaptive Security Appliance as a RADIUS client on the Authentication Manager server.
Review the article on how to Add a RADIUS Client Agent for the ASA.
Notes
Related Articles
Export of reports to a .csv file are blank in RSA Via Lifecycle & Governance 6.9.1 P12 31Number of Views Artifacts to gather in RSA Access Manager 43Number of Views Cisco ASA - RSASecurID Access Implementation Guide 186Number of Views RSA ACE/Server RADIUS authentication fails when coming from Cisco Router 26Number of Views How to configure RADIUS profiles to segment user permissions in Cisco devices for RSA Authentication Manager 8.x 434Number of Views
Trending Articles
RSA Authentication Manager Upgrade Process RSA Release Notes for RSA Authentication Manager 8.8 RSA RADIUS Server service failed to start in the RSA Authentication Manager 8.1 Operations Console Microsoft Entra ID External MFA - Relying Party Configuration Using OIDC - RSA Ready Implementation Guide RSA Release Notes: Cloud Access Service and RSA Authenticators
Don't see what you're looking for?