Test Access to Cloud Access Service
RSA maintains two Cloud Access Service (CAS) environments. When one environment becomes unavailable for any reason, your deployment automatically switches to the other environment. RSA recommends that you test access to both environments before it is needed to ensure a smooth transition during unexpected downtime.
You need to use your tenant-specific authentication and access domain names when performing connectivity tests. Each tenant-specific domain resolves to a service IP address within your assigned region. Although your tenant will typically resolve to a consistent IP address, the service may use any IP address allocated to that region. If you enforce outbound firewall rules by using IP allowlisting, you need to allow all published IP addresses for your deployment region, not only the IP address currently returned by DNS.
Note: Additional IP addresses may be introduced as the service expands. You need to ensure your firewall policies are updated accordingly.
After your deployment is switched to another environment, the following events occur:
Authentication services and the Cloud Administration Console are restored as quickly as possible.
Domain Name Services (DNS) redirects the Cloud Administration Console and your identity routers to the new URLs for your deployment (for example, US). Make sure to whitelist the base authentication and access domain names if you are using DNS firewall rules so that identity routers can connect to the Cloud using the region-specific domain names.
A message is posted to the RSA SecurID Access status page with details about the event.
Before you begin
Confirm that your firewall rules allow access to both IP addresses for your deployment.
If your company uses URL filtering, be sure that both IP addresses for your deployment are whitelisted.
Procedure
To test access for your identity routers, on an identity router, do the following:
Enable SSH on an identity router. For instructions, see Access SSH for Identity Router Troubleshooting.
To test connectivity for both auth and access domains, you can use the following example with your tenant name:
openssl s_client -connect tenantName.auth.securid.com
openssl s_client -connect tenantName.access.securid.com
To test the connectivity with region-specific domain names, you can use the following example authentication domain name:
openssl s_client -connect tenantName-idr-useast.auth.securid.com:443
This domain name is for the useast region of the US deployment. Enter the domain name for your deployment.
Note: You can obtain the tenantName from the Cloud Administration Console.
You receive information back about the certificate chain and other details. If you are unable to reach the environment, the command eventually times out and you see SSL-related error messages.
- Repeat this for one identity router in each data center (or different firewall settings) in your deployment.
To test access for your internal users, on an internal machine, do the following:
Enter the following URL in your browser: https://tenantName.auth.securid.com.
The domain tenantName.auth.securid.com is the US deployment domain dedicated to your tenant. Replace tenantName with the actual tenant name for your deployment.
View details about the connection and confirm that *auth.securid.com is included in the certification path.
For example, on Google Chrome, click the Not secure warning in the address bar. Then click the certificate and confirm that it is issued to *auth.securid.com.
- Repeat this for one internal machine in each data center (or different firewall settings) in your deployment.
If you are unable to access one of the environments, confirm that you have the correct firewall and whitelist settings. For more information, see the "Connectivity Requirements" section in your Quick Setup Guide. To download a Quick Setup Guide that is appropriate for your deployment, see Cloud Access Service Planning and Configuration.
Related Articles
Edit an Authentication Agent 35Number of Views Session Lifetime Limits 49Number of Views Update System Date and Time Settings 74Number of Views Cloud Administration Delete User Now API 164Number of Views Configure Critical System Event Notification 162Number of Views
Trending Articles
RSA Authentication Manager Upgrade Process How to Update the Root (Server) and Client Certificates in RSA Identity Governance & Lifecycle RSA Authenticator 6.2.2 for Windows Administrator Guide RSA SecurID software token .sdtid file fails to import into RSA SecurID Software Token 5.0 for Windows RSA MFA Agent 2.3.6 for Microsoft Windows Installation and Administration Guide