Setting New Pin when using RADIUS in a LoadBalancer environment usually fails
Originally Published: 2022-06-21
Article Number
Applies To
Issue
Cause
But only when setting up a pin for a token mostly fails when using RADIUS protocol in a Load Balancer environment.
Workaround
As seen the Client and Agent IPs are different in both the transactions showing "New Pin Required" and "Principal Authentication"
When a New Pin is required, an Access-Challenge response is received from the RSA AM. This response contains the State Attribute.
The customer can be advised to create a rule that whenever there is a response from the AM containing the State Attribute to make the connection persisted. The entire transaction/session should be forced to happen via only the first node, where the traffic originated from until an Access-Accept or an Access-Reject is received from the AM server
Related Articles
'No such service afx_server' error when performing afx status/stop/start commands in RSA Identity Governance & Lifecycle 142Number of Views What method does RCM/KCA use to calculate the certificate SKI value? 2Number of Views How to use Link Gopher to determine additional proxy web servers to set up for a SecurID Access HFED Application 33Number of Views "Request Error" when editing a Global Role or viewing a Global Role in a Review in RSA Identity Governance & Lifecycle 124Number of Views Error message on RSA Identity Management and Governance workflow: requires at least one valid outbound transition path but… 165Number of Views
Don't see what you're looking for?