- Posts: 1390
- Thank you received: 0
RSA SecurID
17 years 7 months ago #21272
by Smurf
Wayne Murphy
Firewall.cx Team Member
www.firewall.cx
Now working for a Security Company called Sec-1 Ltd in the UK, for any
Penetration Testing work visit www.sec-1.com or PM me for details.
Replied by Smurf on topic Re: RSA SecurID
I am wondering if anyone here has installed RSA Authentication Manager/SecurID with a VPN Concentrator ? Its doin' mi head in and i would really appreciate some assistance.
I have added the SDI Authentication Server into the VPN Concentrator however when i click on test and give it a username/password i keep getting errors which are not making sense. I have searched everywhere but cannot find anything. Arggg.
Can anyone please point me in the right direction. Below are the errors for the VPN Concentrators Log
"1 04/21/2007 15:59:48.630 SEV=5 AUTHDBG/181 RPT=4
Node secret file AC1F5555.sdi not found. Requesting node secret
file from the SDI server ...
3 04/21/2007 15:59:56.600 SEV=5 AUTH/44 RPT=19
Unexpected SDI status value: 23
4 04/21/2007 15:59:56.600 SEV=4 AUTH/15 RPT=39
Server name = 172.*.*.*, type = SDI,
group = none (global server), status = Not-in-service
6 04/21/2007 15:59:56.600 SEV=4 AUTH/9 RPT=19
Authentication failed: Reason = Network error
handle = 240, server = 172.*.*.*, user = murphyw"
I have added the SDI Authentication Server into the VPN Concentrator however when i click on test and give it a username/password i keep getting errors which are not making sense. I have searched everywhere but cannot find anything. Arggg.
Can anyone please point me in the right direction. Below are the errors for the VPN Concentrators Log
"1 04/21/2007 15:59:48.630 SEV=5 AUTHDBG/181 RPT=4
Node secret file AC1F5555.sdi not found. Requesting node secret
file from the SDI server ...
3 04/21/2007 15:59:56.600 SEV=5 AUTH/44 RPT=19
Unexpected SDI status value: 23
4 04/21/2007 15:59:56.600 SEV=4 AUTH/15 RPT=39
Server name = 172.*.*.*, type = SDI,
group = none (global server), status = Not-in-service
6 04/21/2007 15:59:56.600 SEV=4 AUTH/9 RPT=19
Authentication failed: Reason = Network error
handle = 240, server = 172.*.*.*, user = murphyw"
Wayne Murphy
Firewall.cx Team Member
www.firewall.cx
Now working for a Security Company called Sec-1 Ltd in the UK, for any
Penetration Testing work visit www.sec-1.com or PM me for details.
17 years 6 months ago #21326
by sazzy
Replied by sazzy on topic Re: RSA SecurID
Ok I had similar problems with node secrets - you need to reset it. I did this and it sorted out the problem .....
Login as Admin with passcode
Go to Advanced >> Remote Connection
Login as Admin with passcode
Once logged in on RSA,
Go to Start >> Programs >> RSA .. Log
Stay logged into RSA Appliance, but try logging on thru the vpn conc.
On RSA Appliance, check log for unsuccessful authentication error - if it is node verification error ... do this ....
ON RSA App:
Go to Start >> Programs >> RSA Auth. Manager Host Agent
Go to Agent Host >> Edit Agent Host
Select (VPN CONC. AGENT HOST NAME)
UNCHECK Node Secret
Stay logged into RSA Appliance, but try to logon again thru VPN Conc. (or do an authentication test, but not on the rsa appliance itself!)
Enter u/n: Administrator
p/w: passcode (PIN + TOKEN)
Should receive message box: Authetnication Successful
This will automatically upload new node!!!
This might help ... hopefully !! I've just adapated my notes for you ... so if it doesnt make sense let me know!
Login as Admin with passcode
Go to Advanced >> Remote Connection
Login as Admin with passcode
Once logged in on RSA,
Go to Start >> Programs >> RSA .. Log
Stay logged into RSA Appliance, but try logging on thru the vpn conc.
On RSA Appliance, check log for unsuccessful authentication error - if it is node verification error ... do this ....
ON RSA App:
Go to Start >> Programs >> RSA Auth. Manager Host Agent
Go to Agent Host >> Edit Agent Host
Select (VPN CONC. AGENT HOST NAME)
UNCHECK Node Secret
Stay logged into RSA Appliance, but try to logon again thru VPN Conc. (or do an authentication test, but not on the rsa appliance itself!)
Enter u/n: Administrator
p/w: passcode (PIN + TOKEN)
Should receive message box: Authetnication Successful
This will automatically upload new node!!!
This might help ... hopefully !! I've just adapated my notes for you ... so if it doesnt make sense let me know!
17 years 6 months ago #21328
by Smurf
Wayne Murphy
Firewall.cx Team Member
www.firewall.cx
Now working for a Security Company called Sec-1 Ltd in the UK, for any
Penetration Testing work visit www.sec-1.com or PM me for details.
Replied by Smurf on topic Re: RSA SecurID
Thanks for taking the time to post. I will give this a bash tomorrow
Regards
Wayne
Regards
Wayne
Wayne Murphy
Firewall.cx Team Member
www.firewall.cx
Now working for a Security Company called Sec-1 Ltd in the UK, for any
Penetration Testing work visit www.sec-1.com or PM me for details.
17 years 6 months ago #21365
by Smurf
Wayne Murphy
Firewall.cx Team Member
www.firewall.cx
Now working for a Security Company called Sec-1 Ltd in the UK, for any
Penetration Testing work visit www.sec-1.com or PM me for details.
Replied by Smurf on topic Re: RSA SecurID
Still cannot get it to work. For some reason the VPN Concentratory isn't creating the node secret......stupid thing, lol
Wayne Murphy
Firewall.cx Team Member
www.firewall.cx
Now working for a Security Company called Sec-1 Ltd in the UK, for any
Penetration Testing work visit www.sec-1.com or PM me for details.
Time to create page: 0.133 seconds