Error: Unable to perform pre-login process when trying to login to RSA Authentication Manager 8.x Web Tier Self Service Console
Originally Published: 2019-11-18
Article Number
Applies To
RSA Product/Service Type: Authentication Manager, Webtier
RSA Version/Condition: 8.x
Issue
The Authentication Manager server was unable to identify the incoming requests though the the backend instance IP addresses of the Azure App Gateway added under the Virtual Host load balancer page in the Operations Console.
- On the side of the end user who is trying to access the web tier console from the internet to login, the following error is seen:
Sorry, your request cannot be processed at this time

- In the /opt./rsa/am/server/ImsTrace.log collected from the Authentication Manager server the following errors are registered:
ERROR 16042 Execute command Administrator “SYSTEM” attempted to execute command “com.rsa.ims.sso.service.CheckAccessCommand” Failure Unexpected exception caught SYSTEM
UNEXPECTED_EXCEPTION Webtier.selfservice.com XX.XX,XX.XX system.com.rsa.command.CommandServerEngine com.rsa.ims.sso.service.CheckAccessCommand
com.rsa.common.SystemException: Access denied. The authentication request was routed through a load balancer/Proxy server that is not recognized by the system.
- On the Authentication Manager server System Activity Report (Reporting > Reports > Add New or Manage Existing), the following errors are shown:
com.rsa.command.AuditedLocalizableSystemException: COMMAND_EXECUTION_UNEXPECTED_ERRORcom.rsa.command.AuditedLocalizableSystemException: COMMAND_EXECUTION_UNEXPECTED_ERROR Caused by:
com.rsa.common.SystemException: Unable to perform pre-Login process... Caused by: java.net.UnknownHostException: XX.XX.XX.XX:XXXX: invalid IPv6 address at
java.net.InetAddress.getAllByName(InetAddress.java:1170) at java.net.InetAddress.getAllByName(InetAddress.java:1127) at java.net.InetAddress.getByName(InetAddress.java:1077) at
com.rsa.ims.sso.service.SSOPreLoginCommand.performExecute(SSOPreLoginCommand.java:160) at com.rsa.ims.sso.service.SSOPreLoginCommand.performExecute(SSOPreLoginCommand.java:280)Cause
The RSA Authentication Manager Server does not expect that the request from the firewall will be sent in the format <IP Address>:<Port> in the header; rather it expects the request contain only the IP address, that is <IP Address>
Resolution
For more information please refer to the section entitled "Modifications to the request" in the article from Microsoft on How an Azure application gateway works.
Notes
Related Articles
Passcode format error when trying to set a PIN thru a Cisco ASA 375Number of Views Unable to login to Self-Service Console after moving web tier to Internet in RSA Authentication Manager 8.4 patch 6 676Number of Views Error Unable to resolve user by login ID and/or alias, or authenticator not assigned to user when attempting to authentica… 2.09KNumber of Views Couldn't get lock for /opt/rsa/am/server/logs/rsaserv.log error when trying to list services on RSA Authentication Manager… 423Number of Views Error Facts are not available when trying to authenticate using the RSA Authentication Agent 2.0 for AD FS 141Number of Views
Trending Articles
RSA Authentication Manager Upgrade Process RSA Release Notes for RSA Authentication Manager 8.8 RSA RADIUS Server service failed to start in the RSA Authentication Manager 8.1 Operations Console Microsoft Entra ID External MFA - Relying Party Configuration Using OIDC - RSA Ready Implementation Guide RSA Release Notes: Cloud Access Service and RSA Authenticators
Don't see what you're looking for?