This section contains instructions on how to integrate Cisco ASA with RSA Authentication Manager using Risk Based Authentication.
Architecture Diagram
RSA Authentication Manager
To configure your RSA Authentication Manager for risk-based authentication with Cisco ASA, you must create an agent host record and enable it for risk-based authentication in the RSA Authentication Manager Security Console. You will need to download the sdconf.rec and the risk-based authentication integration script for the appropriate device type to configure the agent. RSA Authentication Manager can integrate risk-based authentication with UDP-based or RADIUS agents only.
The latest risk-based authentication script template is at the following link.
Download this file and copy it to the following directory in your primary RSA Authentication Manager server.
/opt/rsa/am/utils/rba-agents
Refer to RSA Authentication Manager Administrator's Guide for more information on RBA integration scripts.
Cisco ASA
Follow the steps in this section to integrate Cisco ASA with RSA SecurID Access using risk-based authentication.
Before you begin
Complete RADIUS or Authentication Agent configuration and apply it to Clientless SSL VPN Portal use case.
Procedure
1. Browse to Configuration > Remote Access VPN > Clientless SSL VPN Access > Portal > Web Contents and click Import.
2. Browse to the am_integration.js integration script, select No to not require authentication for access to content and click Import Now.
3. Browse to Configuration > Remote Access VPN > Clientless SSL VPN Access > Portal > Customization and click Add.
4. Enter a Customization Object Name, mark the Use checkbox for your Connection Profile and then open the Logon Page > Informational Panel page.
5. Mark the checkbox to Display informational panel, copy the following text into the Text: field and click OK.
<script src='/+CSCOU+/am_integration.js' type="text/javascript"></script> <script>window.onload=redirectToIdP;</script>
6. Click Apply.
Important: Depending on which versions of AM and ASA you are integrating, you may get the error “Wrong URL” after RBA logon. See the Known Issues section of this guide for more information and a work-around.
Next Step: Head back to the main page for more certification related information.
Related Articles
IBM Security Access Manager 9.0 - Risk-Based Authentication Configuration - RSA Ready SecurID Access Implementation Guide 3Number of Views F5 BIG-IP APM 14.1 - Risk-Based Authentication Configuration - RSA Ready SecurID Access Implementation Guide 24Number of Views maximum open cursors exceeded 63Number of Views Citrix Systems NetScaler Gateway - RSA SecurID Access Implementation Guide 76Number of Views How to include the hostname in the syslog output for RSA Authentication Manager 8.x 503Number of Views
Trending Articles
How to manipulate imported RSA SecurID Software Token(s) on an iPhone or iPad device Reporting on RSA Authentication Manager 8.x users with On-Demand Token, a fixed passcode or a hardware/software token assi… How to Download OTP Token Seed Files from myRSA Anomalix idGenius - SAML Relying Party Configuration - RSA Ready Implementation Guide RSA MFA Agent 2.5 for Microsoft Windows Installation and Administration Guide