"Invalid authentication handle" reported by the Cisco AnyConnect client when using RSA SecurID Access Cloud Authentication Service RADIUS
Originally Published: 2017-09-19
Last Modified: 2022-06-20
Article Number
Applies To
RSA Product/Service Type: Identity Router
Issue
It is essentially a timeout error. It means that the RADIUS authentication response was not received by Cisco ASA before the configured or default authentication timeout set in that product
Cause
- The time taken to authenticate is genuinely longer than the timeout configured for Cisco, or
- The authentication response was not delivered to Cisco for some reason
Resolution
- Cisco AnyConnect - RSA SecurID Access Implementation Guide
- Cisco ASA 9.5.2 - RSA SecurID Access Implementation Guide
<ServerList> <HostEntry> <HostName>label for UI</HostName> <HostAddress>hostname or IP address of the ASA</HostAddress> </HostEntry> </ServerList>
If ServerList HostEntry is not configured, then a 12 second timeout will be used by Cisco no matter what the actual timeout value is set to.
Related Articles
RADIUS shared secret limitations of RADIUS clients configured with RSA Authentication Manager 756Number of Views Radius Client Authentication failed For PIN+Token profile (New PIN Mode) with Cisco Anyconnect VPN 607Number of Views REST Identity collector mixing attributes from SAP SuccessFactors 11Number of Views ORA-01578 ORACLE data block corrupted reported in RSA Identity Governance & Lifecycle 287Number of Views RSA September 2025 Release Announcements 23Number of Views
Trending Articles
How to manipulate imported RSA SecurID Software Token(s) on an iPhone or iPad device How to test RSA Identity Router (IDR) Secure Connector connectivity to the RSA ID Plus Cloud Access Service RSA SecurID Software Token for Microsoft Windows shows blank screen when asked to select a device where the token will be … RSA Governance & Lifecycle Generic Database Collector Guide RSA Authentication Manager 8.7 SP2 Administrator's Guide
Don't see what you're looking for?