- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Adding the Authentication manager replica cause downtime ?
Hello
we are planning to add first AM replica instance . will it cause any downtime.
- Tags:
- CAS
- Cloud
- Cloud Auth
- Cloud Authentication
- Cloud Authentication Service
- Community Thread
- Discussion
- Forum Thread
- RSA SecurID
- RSA SecurID Access
- SaaS
- SecurID
Accepted Solutions
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Hello Sandip Kandelkar
The short answer is no. Adding a replica doesn't cause or need a downtime. For the detailed steps to add a replica, please check the following documents.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Hello Sandip Kandelkar
The short answer is no. Adding a replica doesn't cause or need a downtime. For the detailed steps to add a replica, please check the following documents.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
True, I've set up radlogin4 for 1 authentication per second to my primary, and then installed a replica...observed zero lost authentications.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Hello Mohamed,
thanks for the confirmation.
I have another question.
we are using SecureID hardware token. Before adding AM replica instance , do i need to set up Load balancer .
we dont have web Tier.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
No, load balancer is not required with Authentication Manager, and in some cases might be more than useless. If you want your users to be able to access either the Self Service Console and/or CTKip URLs for delivery of software tokens and your users are not connected to your internal network (either on your Corp LAN or through VPN) then you could setup a Web Tier or two, and if you wanted to, you could put a load balancer in front of the Web Tier
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Another place you might place a load balancer is between ReST based TCP agents and replicas, because ReST based TCP agent are configured to authenticate against a single AM server (primary or replica) with fail-over to a second AM server, and so on. The legacy UDP based agents e.g. Agent for Windows or Web or PAM ver. 7.x.x or less, do not need a load balancer, as they have a discovery mechanism to test connections to every replica to learn which are online and responding (from UDP port 5500). So putting a load balancer in between UDP based agents and replicas would not just be a waste of time and money, but might actually confuse the keep-alive process.
