Purchasing a New RSA SecurID Appliance to be a Replica
2 years ago
Originally Published: 2014-04-04
Article Number
000051611
Applies To
RSA SecuriD Appliance 130
RSA SecuriD Appliance 250
RSA Authentication Manager 8.1
Issue
Purchasing a new RSA SecurID Appliance to be a replica where a primary instance has already been deployed.
Cause
The primary is a single point of failure.
Resolution

RSA has two types of RSA SecurID Appliance hardware units; RSA SecuID Appliance 250 (Dell PowerEdge R710) and the RSA SecurID Appliance 130 (Dell PowerEdge R210) and information on the latest RSA SecurID Appliance can be obtained from URL http://www.emc.com/security/rsa-securid/rsa-authentication-manager.htm#!hardware.

 

Please contact an RSA Sales Representative with regards to the hardware maintenance called Advance Hardware Replacement (AHR) however AHR is not eligible on R200 or 2950 RSA SecurID Appliance 3.0 hardware models.

 

NOTE: RSA SecurID Appliance 3.0 Service Pack 4 (and RSA Authentication Manager 7.1 Service Pack 4 software) has an End of Primary Support listed for December 2014 at URL http://www.emc.com/support/rsa/eops/servers.htm. RSA no longer ships RSA Authentication Manager 7.1 software on the RSA SecurID Appliance hardware as the RSA Authentication Manager 8.1 software is now shipped on the RSA SecurID Appliance 130 (R210) / 250 (R710).

 

 

Where customers have one RSA SecurID Appliance deployed as a primary instance and would like to implement a replica (or replicas; an Enterprise license is required) you would perform the following checks

 

i)              What is the chassis model of RSA SecurID Appliance currently deployed?

Use the ?
omreport chassis info? command to check the chassis model (instruction provided below).

ii)             Check what software is running on the RSA SecurID Appliance in its deployed state.

RSA Security Console > Home tab > Software Version Information (latest 7.1 version to-date is
am-7.1 SP4 P31)

IMPORTANT NOTE: Replicas must be the same software and build level as the primary to be supported in a production environment.

 

 

Please review the following options for purchasing a new RSA SecurID Appliance to be a replica where only one RSA SecurID Appliance has been deployed running RSA Authentication Manager 7.1 Service Pack 4 software:

 

Chassis Model

(existing primary)

Options

RSA SecurID Appliance 130 (Dell PowerEdge R200)

or

RSA SecurID Appliance 250 (Dell PowerEdge 2950)

Purchasing a new RSA SecurID Appliance 130 (Dell PowerEdge R210) or RSA SecurID Appliance 250 (Dell PowerEdge R710) is shipped with RSA Authentication Manager 8.1 software.

 

It is not possible (or supported) to mix 7.1 with 8.1 deployments as a primary/replica.

 

There is no option to reimage the software on the new RSA SecurID Appliance 130 / 250 to be RSA Authentication Manager 7.1 Service Pack 4 software.

 

Customers will need to contact an RSA Sales Representative to purchase new hardware (RSA SecurID Appliance) for the primary to replace the old R200 / 2950 hardware.

 

?  This leaves the purchased RSA SecurID Appliance to be built as a primary with production data migrated from the old primary. A replica can be configured if it is decided to purchase another RSA SecurID Appliance to replace the aging hardware used by the existing primary.

 

RSA SecurID Appliance 130 (Dell PowerEdge R210)

or

RSA SecurID Appliance 250 (Dell PowerEdge R710)

Purchasing a new RSA SecurID Appliance 130 (Dell PowerEdge R210) or RSA SecurID Appliance 250 (Dell PowerEdge R710) is shipped with RSA Authentication Manager 8.1 software.

 

A possible plan is to use the newer, purchased RSA SecurID Appliance as a primary and migrate the production data into the new 8.1 primary and then decommission the old primary and build the older RSA SecurID Appliance as a 8.1 replica.

 

NOTE: The suggestion to use the new RSA SecurID Appliance as a primary is related to the newer hardware specifications of the RSA SecurID Appliance 130 or RSA SecurID Appliance 250. Primary instances provided administration capabilities and process authentications whereas the replica(s) only process authentications, so deploying the primary on the RSA SecurID Appliance with the better hardware specification ensures for better performance.

 

 

A possible third option

 

Use a third-party product such as PING (at the local console; keyboard and monitor required) to perform a backup of the existing RSA SecurID Appliance 3.0 SP4 (primary instance) and then restore the PING backup to the new RSA SecurID Appliance purchased (making a duplicate primary instance). Next, perform a factory reset on the restored SecurID Appliance where the software will be returned to a factory default of 3.0.4.10. Should this process fail then the RSA Authentication Manager 8.1 ISO is available (via RSA SecurCare Online) to image the RSA SecurID Appliance back to its purchased state, with RSA Authentication Manager 8.1 software.

 

RSA has published a knowledge article at URL https://knowledge.rsasecurity.com/scolcms/knowledge.aspx?solution=a49116 showing a usage of PING however RSA Customer Support does not support the third-party product PING.

 

Chassis Model check

 

Run 'omreport' to Display Your Chassis Model - the chassis model will let us know which type of RSA SecurID Appliance 3.0 you have e.g. PowerEdge R210.

 

 

To run omreport to display your chassis model:

 

1.     Open an SSH connection to your Appliance.

2.     Log on as emcsrv using the operating system password.

3.     Run omreport to display your chassis model. Type: omreport chassis info and press ENTER.

4.     Find the value for "Chassis Model," for example, PowerEdge R210.

 

e.g.

Using username "emcsrv".

emcsrv@homer.csau.ap.rsa.net's password:

Last login: Wed Oct 17 10:23:46 2012 from 152.62.17.76

-bash-3.00$ omreport chassis info

Chassis Information

 

Index                                    : 0

Chassis Name                             : Main System Chassis

Host Name                                : homer.csau.ap.rsa.net

iDRAC6 Version                           : 1.10

Chassis Model                            : PowerEdge R210

Chassis Lock                             : Present

Chassis Service Tag                      : 4950XL1

Chassis Asset Tag                        :

Flash chassis identify LED state         : Off

Flash chassis identify LED timeout value : 300

 

-bash-3.00$

 

 

 

Contact information for RSA Customer Support is located at URL http://www.emc.com/support/rsa/contact/index.htm should you require technical assistance with a purchased RSA product.

 


Workaround
The customer would like to introduce a replica (or replicas) to their deployment for high availability (HA).