How to Configure Two Network Interface Cards for RSA Authentication Manager 8.x
9 days ago
Originally Published: 2016-05-11
Article Number
000052981
Applies To

RSA Product Set: SecurID
RSA Product/Service Type: Authentication Manager
RSA Version/Condition: 8.x

Issue

There is a requirement to have two Network Interface Cards (NICs) on an Authentication Manager instance.

Tasks

Refer to the RSA Authentication Manager 8.x Setup and Configuration Guide found at URL https://community.rsa.com/s/rsa-securid-documentation/authentication-manager to determine if two Network Interface Cards (NICs) are supported by an Authentication Manager appliance. Ensure you use the supported network adapter(s) for virtual appliances. 

Follow the correct procedure to configure the NICs, where two NICs are supported.

Usually, the Authentication Manager virtual appliance is deployed with one NIC and the second NIC is added after the deployment of a primary or replica instance. In some cases, add the second NIC (eth1) after deploying the Authentication Manager template ( e.g. OVA template ) and before starting the Authentication Manager virtual appliance for the first time.

 

    Notes

    Supported Use Cases

    • All services are available on both NICs.
    • Customers can configure their networks to use NIC1 (eth0) or NIC2 (eth1) for particular type of traffic. For example, use NIC1 for authentications and NIC2 for management tasks, such as Authentication Manager backups to a Windows/NFS share.
    • For requests received on NIC2 responses will be sent out on NIC2. If destination becomes unreachable over NIC2 there will be no attempt to failover to NIC1.

    Unsupported Use Cases

    • Assignment of multiple IP addresses to the same NIC.
    • Assignment of the same IP address to both NICs.
    • Automatic fail over for traffic other than agent authentications.
    • Assignment of services to a specific NIC (supported only for SSH).
    • Configuration of more than 2 NICs.

    Multi-NIC Configuration

    • During initial installation of an Authentication Manager instance only one NIC can be configured.
    • Use the Operations Console to enable and configure second NIC (eth1). A restart of Authentication Manager occurs to complete the configuration.
    • Use the Operations Console to check the local hosts files has been updated correctly.
    • Only second NIC can be disabled via the Operations Console.

    Appliance Fully Qualified Doman Name (FQDN) with Multi-NIC Configuration

    • The appliance only has one FQDN.
    • Do not attempt to configure a separate FQDNs for each IP address.
    • Default appliance certificates have the FQDN as the Common Name (CN).

    Not Recommended

    • NIC1 and NIC2 configured to use different IP addresses from the same subnet.

    Online Reference