Launch the Identity Router for Amazon Web Services
Use the identity router Amazon Machine Image (AMI) provided by RSA to launch the identity router as a virtual instance in your Amazon Web Services (AWS) cloud environment. You configure your Amazon environment and deploy AMIs using the Elastic Compute Cloud (EC2) web-based interface.
Before you begin
- You must be a Super Admin in the Cloud Administration Console.
- Your Amazon environment must meet the Amazon Web Services Identity Router Deployment Requirements.
- Obtain the Identity Router Image.
Procedure
- Sign into Amazon EC2.
- Follow the AWS documentation provided by Amazon to install the virtual instance using the AMI.
When prompted, specify the following:
Setting Description AMI template The AMI template image provided by RSA. Instance type Determines presets for the virtual instance. The identity router requires a t2.large instance or greater. Virtual Private Cloud (VPC) The section of your Amazon environment where you will deploy the identity router. Subnet A subnetwork within your VPC where you will deploy the identity router. The subnet can be public or private, depending on how resources and users will connect to the identity router. Auto-assign Public IP Determines whether Amazon issues dynamic public IP addresses for the identity router, or the IP address is determined by the subnet settings.
If your organization manages its own DNS service and the AWS IDR's Single Sign-On Portal needs to be publicly accessible, it is recommended to allocate a persistent Elastic IP address through AWS. This is crucial if the IDR is not behind Network Address Translation (NAT) or an AWS-based load balancer. Once the instance launch process is complete, assign the Elastic IP address to the identity router instance.
Storage Virtual storage space. The identity router requires 54 GB General Purpose SSD (GP2) storage. Tags Optional labels that describe this identity router. RSA recommends adding a tag specifying the Fully Qualified Domain Name, which acts as a unique identifier to differentiate this identity router from others in your deployment. Security groups Firewall rules that control traffic to and from the identity router. Add security groups that allow necessary traffic from other network resources according to your deployment model. See Identity Router Network Interfaces and Default Ports. Advanced details Advanced settings that control metadata access for IDR. RSA strongly recommends enabling the Metadata Accessible option and selecting V2 Only from Metadata Version dropdown list. - Review the configuration and launch the instance.
- If prompted to select a key pair, select Proceed without a keypair.
- Use the Get instance screenshot feature to monitor instance deployment status. When deployment is complete, the screenshot displays the URL for the Identity Router Setup Console.
After you finish
Configure Network Settings Using the Identity Router Setup Console.
Related Articles
Provisioning Form fails with 'An error occurred loading the fields for the form' error while running in RSA Governance & L… 62Number of Views Unexpected MFA Challenge for Unchallenged Users when machines are in WORKGROUP environment 75Number of Views Understanding RSA Authentication Manager logging fields when they are forwarded to syslog 606Number of Views Cloud Access Service - Planning Access Policies 13Number of Views RSA SecurID Software Token 2.4.2 for iOS requires a reboot of the device when launched a second time 99Number of Views
Trending Articles
RSA Authentication Manager Upgrade Process How to Update the Root (Server) and Client Certificates in RSA Identity Governance & Lifecycle RSA Authenticator 6.2.2 for Windows Administrator Guide RSA SecurID software token .sdtid file fails to import into RSA SecurID Software Token 5.0 for Windows RSA MFA Agent 2.3.6 for Microsoft Windows Installation and Administration Guide