After upgrading RSA Authentication manager to version 8.6, users AnyConnect are not able to authenticate
2 years ago
Originally Published: 2021-09-23
Article Number
000044245
Applies To
RSA Product Set: RSA SecurID
RSA Product/Service Type: Authentication Manager
RSA Version/Condition: 8.6.0
Platform: null
Platform (Other): null
O/S Version: null
Product Name: null
Product Description: null
Issue
After upgrading RSA Authentication manager to version 8.6, users who are using AnyConnect are not able to authenticate
Cause
The root cause of the problem was the AM 8.5 radius client for the Cisco ASA. The Make/Model was set to Cisco PIX FW. This Make/Model does not exist in AM 8.6.
Resolution
The Make/Model "Cisco PIX FW" was called out in the radius log when the radius log level was increase to Verbose.

To Turn on Verbose logging. Go to  the Operations Console->Deployment Configuration->Radius Servers. Select your Primary AM server in the dropdown menu
Select Manage Server Files, edit radiusd.conf.  Increased radius logging from debug_level=0 to debug_level=2 

 
Workaround
In the Radius Client configuration for the Cisco ASA. Change the Make/Model to Standard Radius. 

In the Radius client list., if you see any more Radius clients with Make/Model set to Cisco PIX FW. change them too