New PIN Mode and Next Token Mode fail on Cisco VPN 3000 Concentrator with RSA ACE/Server
2 years ago
Originally Published: 2004-08-18
Article Number
000061755
Applies To
RSA ACE/Server 5.1 (no longer supported as of 7-14-2006)
RSA ACE/Server 5.2
Cisco VPN 3000 Concentrator
Issue
New PIN Mode and Next Token Mode fail on Cisco VPN 3000 Concentrator with RSA ACE/Server
Error: "New PIN Deferred"
Error: "Access Denied, Syntax Error"
Error: "No response from SDI Server" in Cisco Logs
Cause
Problem can be caused by an insufficient timeout within Cisco
Firmware version does not support New PIN Mode
Resolution
To correct this issue, update the Cisco Firmware to latest revision available at Cisco Software Center.

Also, review this RSA Implementation Guide for the Firmware Version we used for Certification. For example:

    IOS Version vpn3005-4.0.2-k9.bin had been found to require a minimum upgrade to vpn3005-4.0.5.A-k9.bin to work with New PIN and Next Token Mode