How to test authentication from RSA Authentication Agent 1.0.2 for Microsoft AD FS 3.0 when it fails with a UDP packet creation error.
Originally Published: 2018-06-13
Article Number
Applies To
RSA Product/Service Type: RSA Authentication Agent for AD FS
RSA Version/Condition: 1.0.2
Platform: Microsoft AD FS 3.0
O/S Version: Windows 2016 Server
Issue
UDP Packet Creation Error.
Cause
- The presence of antivirus software on the user's machine,
- User privileges,
- Incorrect DNS name resolution for the machine on which the RSA Authentication Agent 1.0.2 for AD FS is installed,
- A local Windows firewall.
Resolution
- Ensure that the DNS name resolution is successful for the AD FS agent:
- Log on to the Operations Console of the appliance.
- Click Administration > Network > Network Tools.
- From the Select Command drop-down list, choose NSLookup to verify the IP address or hostname.
- Click Run Command.
- Make certain that the IP address override is properly configured for the AD FS agent installed on the AD FS server (see 000029015 - Using an IP address override to fix an initial authentication failures with RSA Authentication Manager when the error Authentication Method Failed displays for information on how to configure an IP override).
- Perform an automatic rebalance from the primary Authentication Manager server's Security Console:
- Select Access > Authentication Agents > Authentication Manager Contact List > Automatic Rebalance.
- Click Rebalance.
-
If the node secret was saved on the agent machine, especially if the server indicates the node secret was sent, verify if read and write permissions is given for C:\Program Files (x86)\RSA Security\RSAWebAgent (where the node secret is written by default):
- Right click on the location folder.
- Select Properties > Security .
- Click Edit.
- Check the Full Control option
- Click Apply then OK.
- Clear any existing node secrets, both on the agent and the server.
- Clearing the node secret on server
- Login to the primary's Security Console.
- Select Access > Authentication Agents > Manage Existing.
- Right click on the agent and select Manage Node Secret from the context menu.
- Check the Clear the node secret option.
- Click Save.
- Clearing the node secret on agent
- On the AD FS server, click Start > Apps > RSA Control Center to launch RSA Control Center.
- Under SecurID Settings, select Advanced Tools.
- Click Clear Node Secret.
- Click Yes.
If Windows Server is installed in Server Core mode, launch Control Center from the command line by running RSAControlCenter.exe from C:\Program Files\Common Files\RSA Shared\RSA .NET\.
- Disable any firewall or installed antivirus software on the AD FS server.
- Run the RSA Authentication Agent 1.0.2 for AD FS application with elevated privileges using the Run as Administrator option and try multiple test authentications.
Related Articles
Visual C++ runtime error intermittenly appears on the OS 14Number of Views 'Unable to process request (possible bad server parameter)' when requesting a certificate with OneStep 10Number of Views Authentication context not added / Context validation failed errors authenticating with RSA Authentication MFA Agent for A… 157Number of Views This request contains no changes. It cannot be submitted error when adding entitlement belonging to a role in RSA Identity… 24Number of Views Add a Custom RADIUS User Attribute Definition 41Number of Views
Trending Articles
Downloading RSA Authentication Manager license files or RSA Software token seed records Unable to login to RSA Authentication Manager Security Console as super admin RSA Authentication Manager 8.9 Release Notes (January 2026) How to manipulate imported RSA SecurID Software Token(s) on an iPhone or iPad device Connection fails to Cloud Authentication Service when connecting through a proxy server from RSA Authentication Manager to…
Don't see what you're looking for?