Setting New Pin when using RADIUS in a LoadBalancer environment usually fails
Originally Published: 2022-06-21
Article Number
Applies To
Issue
Cause
But only when setting up a pin for a token mostly fails when using RADIUS protocol in a Load Balancer environment.
Workaround
As seen the Client and Agent IPs are different in both the transactions showing "New Pin Required" and "Principal Authentication"
When a New Pin is required, an Access-Challenge response is received from the RSA AM. This response contains the State Attribute.
The customer can be advised to create a rule that whenever there is a response from the AM containing the State Attribute to make the connection persisted. The entire transaction/session should be forced to happen via only the first node, where the traffic originated from until an Access-Accept or an Access-Reject is received from the AM server
Related Articles
'No such service afx_server' error when performing afx status/stop/start commands in RSA Identity Governance & Lifecycle 142Number of Views SQL Exception in the RSA Identity Governance and Lifecycle UI while saving the workflow after rollback 85Number of Views 'The request could not be handled' error occurs upon clicking and loading change requests from Requests > Requests in RSA … 100Number of Views Custom URL is not rendering in the Review Instruction field and in the Review Email Body for RSA Via Lifecycle and Governance 37Number of Views AFX Server intermittently shuts down in RSA Identity Governance & Lifecycle 309Number of Views
Trending Articles
RSA Authentication Manager 8.9 Setup and Configuration Guide How to 'Trust' the RSA Authentication Manager Security Console Self-Signed Root CA certificate and prevent Cert warnings. RSA Authentication Manager 8.9 Release Notes (January 2026) Configure RSA Authentication Manager as a Secure Proxy Server for Cloud Access Service RSA Authentication Manager Upgrade Process
Don't see what you're looking for?