"Invalid authentication handle" reported by the Cisco AnyConnect client when using RSA SecurID Access Cloud Authentication Service RADIUS
Originally Published: 2017-09-19
Article Number
Applies To
RSA Product/Service Type: Identity Router
Issue
It is essentially a timeout error. It means that the RADIUS authentication response was not received by Cisco ASA before the configured or default authentication timeout set in that product
Cause
- The time taken to authenticate is genuinely longer than the timeout configured for Cisco, or
- The authentication response was not delivered to Cisco for some reason
Resolution
- Cisco AnyConnect - RSA SecurID Access Implementation Guide
- Cisco ASA 9.5.2 - RSA SecurID Access Implementation Guide
<ServerList> <HostEntry> <HostName>label for UI</HostName> <HostAddress>hostname or IP address of the ASA</HostAddress> </HostEntry> </ServerList>
If ServerList HostEntry is not configured, then a 12 second timeout will be used by Cisco no matter what the actual timeout value is set to.
Related Articles
Cisco ASA - RADIUS Configuration with Cloud Authentication Service - RSA Ready Implementation Guide 71Number of Views Cisco ASA - RSASecurID Access Implementation Guide 191Number of Views Clear the node secret file on Cisco ASA in RSA Authentication Manager 8.x 233Number of Views Cisco AnyConnect sends multiple authentication requests to RSA Authentication Manager 8.4 188Number of Views How to configure RADIUS profiles to segment user permissions in Cisco devices for RSA Authentication Manager 8.x 444Number of Views
Trending Articles
RSA Authentication Manager 8.9 Setup and Configuration Guide How to 'Trust' the RSA Authentication Manager Security Console Self-Signed Root CA certificate and prevent Cert warnings. RSA Authentication Manager 8.9 Release Notes (January 2026) Configure RSA Authentication Manager as a Secure Proxy Server for Cloud Access Service RSA Authentication Manager Upgrade Process
Don't see what you're looking for?