User name included in RADIUS response packet in RSA ACE/Server; 'Passcode Accepted' message followed 'Access Denied' and 'auth lock' errors
Originally Published: 2002-05-09
Last Modified: 2023-09-25
Article Number
Applies To
Sun Solaris 2.8
Microsoft Windows 2000
UNIX (AIX, HP-UX, Solaris)
All supported platforms
All UNIX platforms
RADIUS
3rd-party access server, Jtec frame switch module, FSM-16
Issue
Response delay time is set to 1 second but RADIUS authentications still fail
Error: "ACCESS DENIED, auth lock error"; users locked out for 10 minutes after the error
Dial-up through access server doesn't work after upgrade to ACE/Server 5.0.x
Error: "auth lock error" in the ACE/Server logs
In the ACE/Server logs, "Passcode Accepted" message is immediately followed by "Access Denied" and auth lock errors
RADIUS authentications were working before upgrade
RADIUS authentications fail
Other RADIUS devices are working fine
A packet sniffer shows that successful response packet from ACE/Server includes attribute 1, User NAME in response packet
ACE/Server LOG show:
04/24/2002 01:33:42U jsilk/Jtec_server 000072629150
04/24/2002 11:33:42L Passcode accepted cyclone
04/24/2002 11:33:42L Johan Silkenas
04/24/2002 01:33:46U jsilk/Jtec_server 000072629150
04/24/2002 11:33:46L ACCESS DENIED, passcode incorrect cyclone
04/24/2002 11:33:46L Johan Silkenas
04/24/2002 01:33:46U ------/Jtec_server 000072629150
04/24/2002 11:33:46L ACCESS DENIED, auth lock error cyclone
04/24/2002 11:33:46L -----
04/24/2002 01:33:50U jsilk/Jtec_server 000072629150
04/24/2002 11:33:50L ACCESS DENIED, passcode incorrect cyclone
04/24/2002 11:33:50L Johan Silkenas
04/24/2002 01:33:50U ------/Jtec_server 000072629150
04/24/2002 11:33:50L ACCESS DENIED, auth lock error cyclone
04/24/2002 11:33:50L -----
04/24/2002 01:33:54U jsilk/Jtec_server 000072629150
04/24/2002 11:33:54L ACCESS DENIED, passcode incorrect cyclone
04/24/2002 11:33:54L Johan Silkenas
04/24/2002 01:33:54U ------/Jtec-server 000072629150
04/24/2002 11:33:54L ACCESS DENIED, auth lock error cyclone
04/24/2002 11:33:54L -----
Cause
Resolution
Workaround
Related Articles
Errors 'Server Timeout' and 'User TIME's access is denied' with RSA Access Manager and RSA SecurID 182Number of Views Access denied error while running the RSA Authentication Manager 8.x Administration SDK 96Number of Views Error message "Access denied - User not a member of any identity source in access policy" in RSA SecurID Access 81Number of Views RSA Via Lifecycle & Governance administrators do not see Privileges tab for users 28Number of Views RSA Via Lifecycle & Governance administrators do not see administrative tabs in the Console 131Number of Views
Trending Articles
Artifacts to gather in RSA Identity Governance & Lifecycle How to Update the Root (Server) and Client Certificates in RSA Identity Governance & Lifecycle How to manipulate imported RSA SecurID Software Token(s) on an iPhone or iPad device Troubleshooting AFX Connector issues in RSA Identity Governance & Lifecycle How to Download and Reinstall the AFX Server Archive in RSA Governance & Lifecycle
Don't see what you're looking for?