Unable to authenticate to Authentication Manager 8.x with a Check Point firewall in a clustered environment where a virtual IP address was implemented
Originally Published: 2016-09-29
Article Number
Applies To
RSA Product/Service Type: Authentication Manager
RSA Version/Condition: 8.1 or later
Issue
In this example,
- There is a Check Point R77 firewall with two clusters.
- Cluster 1 has a physical IP address of x.x.x.101.
- Cluster 2 has a physical IP address of x.x.x.102.
- Cluster 1 and Cluster 2 are a member IPs of the virtual IP address x.x.x.100.
Activity Key: Lookup Authentication agent
Description: Lookup authentication agent by IP address "x.x.x.101"
Reason: Authentication agent not found
Resolution
- In the Security Console, select Access > Authentication Agents > Add New (or Manage Existing, as the case may be).
- Create (or modify) an agent using the virtual IP address in IPv4 format in the Authentication Agent Basics section.
- Click Save when done.
- On the Cluster 1 agent machine, open a text editor and create a file named sdopts.rec.
- In the file add the following entry using the IPv4 virtual IP address, as in the example here:
CLIENT_IP=<virtual IP address>
For example
CLIENT_IP=10.100.100.100
- ave and close the file. A restart of the agent is not required.
- Test authentication against Cluster 1.
- Authentication should be successful and the node secret file named securid will be created in the agent directory (/var/ace/ by default)
- Copy the following files: sdconf.rec, sdopts.rec and securid to standby firewall (Cluster 2)
- This should enable the standby to take authentication requests when it becomes active.
Notes
Related Articles
Verify an IP Address or Hostname 31Number of Views Unable to open any workflow on RSA Identity Governance & Lifecycle 7.0.2 or 7.1.0 when deployed in a clustered environment… 424Number of Views Update the Primary Instance Hostname and IP Address on a Replica Instance 198Number of Views Recover from an Incorrect IP Address Change 146Number of Views Deployment of the aveksa.ear in a clustered environment fails with 305000 ms timeout error in RSA Identity Governance & Li… 228Number of Views
Trending Articles
Download RSA SecurID Access Cloud User Event audit logs using Cloud Administration REST API CLU RSA MFA Agent 2.5 for Microsoft Windows Installation and Administration Guide Quick Setup Guide - Passwordless Authentication in Windows MFA Agent for Active Directory Authentication Manager Security Console and Operations Console Inaccessible After Certificate Update Authentication Manager How to Retrieve the LDAPS Certificate and Configure an External Identity Source to Use LDAPS
Don't see what you're looking for?