Setting New Pin when using RADIUS in a LoadBalancer environment usually fails
Originally Published: 2022-06-21
Article Number
Applies To
Issue
Cause
But only when setting up a pin for a token mostly fails when using RADIUS protocol in a Load Balancer environment.
Workaround
As seen the Client and Agent IPs are different in both the transactions showing "New Pin Required" and "Principal Authentication"
When a New Pin is required, an Access-Challenge response is received from the RSA AM. This response contains the State Attribute.
The customer can be advised to create a rule that whenever there is a response from the AM containing the State Attribute to make the connection persisted. The entire transaction/session should be forced to happen via only the first node, where the traffic originated from until an Access-Accept or an Access-Reject is received from the AM server
Related Articles
'No such service afx_server' error when performing afx status/stop/start commands in RSA Identity Governance & Lifecycle 140Number of Views SQL Exception in the RSA Identity Governance and Lifecycle UI while saving the workflow after rollback 84Number of Views Custom URL is not rendering in the Review Instruction field and in the Review Email Body for RSA Via Lifecycle and Governance 37Number of Views AFX Server intermittently shuts down in RSA Identity Governance & Lifecycle 308Number of Views Another Mapping already exists for the target account attribute warning in RSA Identity Governance & Lifecycle when settin… 69Number of Views
Trending Articles
RSA Authentication Manager 8.9 Release Notes (January 2026) RSA MFA Agent 2.3.6 for Microsoft Windows Installation and Administration Guide RSA-2026-07: RSA Authentication Manager Security Update for Third-Party Component Vulnerabilities Downloading RSA Authentication Manager license files or RSA Software token seed records RSA MFA Agent 2.5 for Microsoft Windows Installation and Administration Guide
Don't see what you're looking for?